Quite the opposite: M$ rules for "secure" boot are:
* on x86 (or "non-ARM" in their wording) devices, it MUST be possible for 
users to disable "secure" boot,
* on ARM devices, it MUST NOT be possible for users to disable "secure" 
i.e. all ARM devices shipping Window$ will have restricted boot forced on 
with no option to disable it.

