They reworked the connection dialogue in SSMS 20, and SSMS (like all client APIs), now defaults to requiring an encrypted connection. The regular connection dialogue exposes the encryption options on the front page, but there a couple of places they still have to address.
And one such place is when you use the command line to start SSMS. I have noticed this myself, but I don't think I have come around to bring it up with Microsoft. But they may still have it on their radar.