I suspect the ease (or otherwise) of this transition is heavily dependent on the hardware manufacturer and firmware quality rather than the Windows side of things.
We're an almost exclusively Lenovo estate and our experience has been much more mixed than some of the "turn on the Intune policy and forget about it" reports above. The Windows updates themselves have generally behaved as expected, but we've found BIOS/UEFI support to be quite patchy across different Lenovo generations and models.
On some devices the Secure Boot certificate updates went through automatically with no intervention. On others, even with the latest available BIOS installed, the certificates either refused to update or remained stuck in an incomplete state. In quite a few cases the limiting factor wasn't Windows, Intune or policy configuration - it was simply that the firmware wasn't correctly handling the Secure Boot variable updates.
Looking at the new Intune Secure Boot Status report and Microsoft's detection scripts, most of our remaining non-compliant devices correlate strongly with specific Lenovo models rather than any particular Windows build or management method.
Reading through the replies here, it sounds like HP and some other vendors may have had a smoother path, whereas older Lenovo hardware seems to be a bit more hit-and-miss. I'd be interested to know whether others are seeing the same pattern, or whether we've just been unlucky with our device mix.
The good news is that Microsoft now appears to be continuing to deploy the new certificates through Windows Update, so the situation feels much less urgent than it did a few months ago. We've gone from worrying about a hard deadline to mostly monitoring the stragglers and identifying the handful of devices that are genuinely limited by firmware support.