2 points
Especially when there’s a chance that the bios update resets the tpm and if the user has enabled bitlocker (automatically done in background without user consent on windows 11 if using a Microsoft account) then they need to type the decryption key to boot again.
Happened twice on my laptop