So like... literally on boot when Windows Security starts? Or actually during setup when disk encryption is turned on and the setup gives you the option to backup your recovery key?
Are you somehow not aware that Windows 11 is perfectly happy to allow you to turn any or all of its security features on post-installation? If you can get the system installed without any of those things, you can turn any or all of them on piecemeal (aside from dependencies) after the fact. You can even start with fdisk partitioning and no TPM in the system, and wind up all of the security stuff turned on without reinstalling Windows. I've done all of this in a virtual machine, but you can also put a TPM on some motherboards, so you can do all of these things with a real machine as well.
the common person these days expects online accounts, cloud integration, etc.
Microsoft is not forcing accounts on people for their good. Making it a prominent default is very reasonable. Making it this difficult to go around is unacceptable. But then, I haven't accepted Windows on the metal (except for some veritable antiques I've got here... single-and dual core Atoms) in years, and these days I don't even allow it to access the internet except via filtering proxy. Windows cannot be trusted. No corporation should be trusted, but Microsoft more than most.