I've recently got a laptop with secure boot enabled by default (an Asus Zenbook), and man that was a pain. I wanted to install Linux on a second partition, and it wouldn't let me boot anything from a removable medium until I turned off secure boot.
But of course the option to disable secure boot was grayed out, and it took me some searching on the Internet to find a solution: first you have to go to the key management window, and delete all the keys there. Then you're allowed to turn off secure boot.
If they wanted it to be usable, they'd just offer me an option 'boot once without secure boot' (and ask for the BIOS/EFI administrator password if set).
After this experience, my hypothesis is that the main purpose of "secure boot" is to discourage the user from installing anything non-default (aka Linux).