It is, Secure boot and the TPM must both be enabled.
If you check Msinfo32 / “System Information” with admin rights, there is a “device encryption” listing that maybhave additional information.
There are rare instances where a device won’t support automatic encryption due to “Un-allowed DMA capable bus/device(s) detected” which requires a registry tweak to work around
I’m pretty sure those ads also have to meet certain criteria though.
Using ABP, I’ve never had a popup ad, full page ad, auto-playing video, or other intrusive form of advertisement. The “acceptable ads” have been quiet and out of the way in what would otherwise be empty space.
With the understanding that some websites and content creators are entirely reliant on ad revenue, I prefer to have those filtered down to those that don’t provide a burdensome experience.
I will say that having a new tab open with a solicitation for a donation / “premium” every single update (so almost daily) is irritating and they better knock that shit off if they don’t want to alienate users.