Basically, when MS started requiring Secure Boot on Windows computers, there were a few anti-trust actions against then that looked at this action. So they back-pedaled and required that people should be able to disable Secure Boot on x86 and amd64 computers. They also created a 3rd party certification program, that those distros one buys could pay for and get signed.
But make no mistake, MS completely control the specs of any PC available to you, and will not miss a chance to remove the support for 3rd party OSes.