“… there’s only one OIK for any given M1/M2 Mac, and by default only the primary admin user has access to it”

Link. The Mac is drifting towards being a single user device like the iPhone.

“There are two good ways to discover which users are owners, and have Secure Token…”