ASUS releases BIOS 2102 with AGESA 1.3.0.0a to fix BitLocker recovery loop issues on AM5 600 and 800 series motherboards.
So... my Asus mobo (ROG Strix Z390-E Gaming) is from 2018, and while the code Andrew provided for PowerShell shows I'm OK for the new cert, I get "False" for Default ...