The problem is not that they exist or that Windows 11 supports them. It's that Microsoft pretends they are required, when they are not.
The problem is not that they exist or that Windows 11 supports them. It's that Microsoft pretends they are required, when they are not.
I think that's what "artificial limitations" mean. Microsoft pretending they are required when they are not.
They can also often be used as a (slow) source of hardware randomness.
Most modern intel (seris 8 onwards) and AMD Zen onwards have fTPM too. Often these can be enabled in the bios during upgrade then disabled again.
Personally I upgraded to Win11 the moment it became available, but that's because I want to continue my run of free MS windows forever and I only ever boot into it to play games, with even that becoming less common.
But it's kind of MSFT's choice whether TPM and secure boot are requirements for their software. If their software makes security assumptions that the OS has access to trusted hardware then it's a requirement. One could argue that they should create secure and less secure versions of Windows, but I don't think anyone is really going to take that seriously beyond rhetoric.
There are a lot of advantages to assuming the hardware is mildly trustworthy. The downside is you may not want Microsoft to be controlling what counts as trusted on your machine. If so, then you probably don't want MSFT to have root in your machine either and you're better off with a different OS.
In an IT security context, "trusted" (example: "trusted computing") means distrusting the users.
If you want to add better security to a computer make it opt-in and not expect people to use it who don't need it.
TPM also enables things that average users care less about like DRM, but Passkeys are a good idea and having them more-secure-by-default is good for the average user (even with accidental vendor lock-in implications).
There are security boons, sure, but these are a side effects. They are not what TPM is for.
Stated primary intent by Microsoft for TPM is Passkeys (because Microsoft has key incentives to kill Passwords and reduce Phishing) and Netflix-class DRM (because people want to still be able to watch Netflix on their PCs).
Sure, Microsoft has also tried locked down "Store-only" versions of Windows (partly to appease Educators who moved to Chrome OS for that need/compliance requirement), but also has heard loud and clear that isn't the version of Windows that will drive sales from the market at every one of those attempts. At this point there should be no way that Microsoft still thinks they can lock down Windows as much as Apple and Google lock down their phones. If anything Android moving even more locked down seems to be a marketing opportunity for Windows to point out that they generally won't.
Microsoft isn't perfect, and isn't a monolith (I'm sure there are executives that wish Microsoft was in the position of Apple or Google right now), but the flip side, Microsoft is a company with products to sell and the market tells it doesn't want locked down Windows and for the most part Microsoft is incentivized still to not lock down Windows. Basic greed is an easier explanation for their past and future behavior than imagining some conspiracy where Apple, Google, and Microsoft are all in it together to kill the unlocked computer.
Microsoft has tried, and failed, before but there is a culture shift here. All platforms are becoming locked down and consumers are being accustomed to being treated like cattle. Some even prefer it, beg for it.
One day, the time will come, and Microsoft will have all the tools. Because you gave them the tools.