Platforms like Windows and Chrome can also use it for remote attestation, i.e., verifying you haven’t bypassed security controls and locking you out if they think you have.
I keep mine enabled because it’s good for secure boot and secrets handling.