Some things break by design and require user interaction to resolve when using Secure Boot:
- tirdad (requires enrolling a MOK to resolve)
- Fonts on the GRUB boot menu (no solution)
- Memtest86+ (no solution)
- Possibly more (anything kernel lockdown mode breaks)
The last two may not matter that much, the first two are more important, the first one especially.