Later I found if I turned off Secure Boot and enabled CSM (corporate stable mode) then I could boot as before.

Frankly I find UEFI to be over-reaching. Here's an article about it.
http://www.fsf.org/campaigns/secure-boot-vs-restricted-boot

This effectively can remove the Personal from the PC and move it out of our control. You may want to rethink your choices here.
Bob