We also just ran into this issue. We are on MP11. it seriously trashed the machine, a Surface 4. I could get into the BIOS, but could not manipulate TPM or SecureBoot settings. THe machine would boot, screen flashed erratically and then a message about SecureBoot.
Through some miracle I was able to get the machine to respond to PXE so I could re-image it. I enabled ipv6 for PXE and then was able to disable SecureBoot, which was an odd fix, but it worked.
Hope this gets resolved.