I'm just wondering: if I'd make a bootable clone (on an ext disk) would the T2 security have to be set at 'no security' (or whaterver the lowest settings is called) to actually allow a boot from clone? If so, I'd have to have this as default T2 settings as one doesn't know in advance when one needs to start up from an external clone (in the future), no?