Question BIOS Secure State, opinions needed.

Yes. It's required for Windows 11 because the TPM feature isn't usable otherwise. My laptops have it on by default, and one of them is running Linux. All Apple computers from like the mid 2010s on have a similar feature.
I have Windows 11 installed on a Gigabyte z690 Master with onboard TPM but msinfo32 advises that Secure Boot is off.