Microsoft sell locked down PCs today. Secure Boot cannot be disabled, nor new keys enrolled, on Windows PCs that ship with an ARM processor (yes they exist). It's as if Apple decided to lock down Macbooks when they switched to M-series. The only thing keeping PCs "free" is that ARM processors suck at the high end if you're not Apple, so it's seen as acceptable market segmentation. It's purely arbitrary though, just like it's purely arbitrary that you can put Linux on a Macbook but not an iPad despite having the same SoC.
They do, and 20 years ago a move like that would have also drawn widespread condemnation.
It's not as big a problem as it is with phones though because the vast majority of PCs on the market are not locked down in this way, and only a handful of PC applications (a few competitive games) use remote attestation to check for an unmodified Microsoft OS.