

It’s been attempted in two ways.
First is secure boot. There were a handful of computers sold that did not allow disabling of secure boot, or changing the loaded keys. So it was basically essentially a Windows only computer.
More recently is there was Microsoft Windows S. This was a cheap version of Windows Home that ran on low end computers and was locked to only allow installing apps from the Microsoft store. It was possible to unlock it but as I recall it required an additional fee.
Enterprises almost all run Windows anyway so they DGAF.
I was talking about secure boot. If the computer only runs Windows, enterprise doesn’t care. If the computer only runs Windows S, it’s an absolute nonstarter in enterprise tons of apps aren’t on the app store. But Windows S is never targeted to enterprise, only low end home users.
Anything can support secure boot, the question is, are the keys included in the BIOS so it can run that particular OS without loading extra keys?
I’ve also not personally encountered a computer where secure boot couldn’t be disabled or the list of keys modified, but I’ve definitely heard about them existing.