For Intel 13th Gen, secure boot is enabled by default. (Thanks Microsoft.) To disable it, access the Administer Secure Boot panel from the BIOS root screen before attempting to boot an unsigned image. Otherwise, the content of the Administer Secure Boot panel is blocked when a secure boot fails.
If you get the message blocking Administer Secure Boot, then power off and try again. When powering on, either press F2 before the BIOS attempts to load an image, or power on with no OS image attached.
Unfortunately the BIOS is configured for no delay before attempting to load an OS image.
See pictures in EFI USB Device has been blocked by the current security policy - #6 by Vortico.