Just installed Z16 Lite on my wife's desktop. The option to disable Secure Boot involves deleting some Secure Boot keys - I hadn't done that with Z15 so I chose not to and left Secure Boot and UEFI on. In the past, on Z15 install I had disabled UEFI, had Secure Boot on, but I couldn't replicate my success so I had to resort to leaving them both on.
During installation I was asked to setup a Secure Boot password (haven't encountered this with Z15) and it stated that I would be asked for that password during reboots. Like in all other Z installs, there was only one reboot and I wasn't asked the password. I don't think I have to hang on to the password given the installation has already completed and it has been rebooted at least once after the full installation's own reboot, correct?