posting an update that it worked in the end. (somehow the VM i created as test used another SCSI adaptor and it didn’t play well)
The settings that are default for a Win10 x64 still needed secure boot to be turned off.
For those who might venture, here’s my settings for my clients.
Time for some NAC + Jumpcloud + Chocolatey fun