My workstation at home got flagged as incompatible anyway. It does meet the hardware requirements but I use bios to boot. There are workarounds, but I don't want to bother honestly. I wonder how many people will throw away their systems because they have wrongly configured software. I don't want to support secure boot because I hate seeing remote attestation gain any significant ground. It is just a bundle of bad incentives. If have no maids either.
Sadly I probably have to use Windows for work, since a lot of tools in my industry rely on Windows. At work the PCs still run Windows 10, but that is still the usual update cycle. It would probably be distributed by WSUS, but I haven't heard about any ambitions to update. Windows PCs for offices have secure boot enabled by default, so at least that would be less hassle.