Before making any changes in BIOS, please ensure you have a safe backup of your files, and if you log into Windows with a PIN, be sure you know your password, in case the PIN does not work after making the changes in BIOS.
In BIOS have you already reset TPM keys and Secure Boot keys to factory and that still does not allow you to boot into Windows with Secure Boot enabled?
If so, the best option would be to go to the support page for your device on the Lenovo website to check for any BIOS update that may be available and not yet installed.