Earlier quoted context omitted.
But it's very much a part of boot verification to unlock a TPM with your encryption keys on it.
You're conflating secure boot with measured/verified boot.
Or is this just some technical detail that in practice is under the same tools and settings?