Oh that is troubling. Perhaps I will have to stick with the Azure VM/VPN solution after all, as Trusted Launch and Secure Boot is definitely possible there, as well as Encryption at Host and Bitlocker..
Unfortunately, AAD Join is not yet enabled in my instance for Windows 365 enterprise. I don't know when it will be enabled, but if indeed secure boot and trusted launch are not supported right now, I guess it doesn't matter. Additionally, as i mentioned above, on MacOS and iOS it is currently not possible to connect to more than one Windows 365 workspace unless all the licenses are under the same UPN in the tenant.
When I did have the windows 365 business license, not only could I not enable secure boot or trusted launch, even with windows 11, but the windows security dashboard in settings clearly said the hardware i was using did not support this. Also, I was unable to enable bitlocker on the windows 365 instance. Do you have bitlocker enabled on your windows 365 enterprise instances? Also, I know at one point not all regions supported trusted launch for vms, this may no longer be the case, I am not sure, however, it is my understanding you can select which region you have your windows 365 enterprise vm, which is not the case with windows 365 business. Have you checked that maybe your instances are in a region that don't support trust launch/secure boot for VMs? Thats the only other thing I can think of.