Yeah I want #3 but not as a temporary stage, but permanent, max compatibility. If that is only temporary staging process then I will try to keep #2.
I think I understand the options now, so I let it update boot manager, and then pick the one to use when making an ISO (probably 2011).
If I was to let it revoke/ban the 2011 cert, microsoft would make it so much easier if they wasnt doing that, then I can imagine things like my macrium reflect recovery failing to boot. I dont really want to have to keep going in the bios to toggle secure boot for different boot devices.
Also its good ntlite reports on the host status, I guess I need to put ntlite on every device to see what certs they have installed?