Peripherals like a keyboard and mouse connected using USB to a Thunderbolt Dock may work in BIOS, do not work at the login screen, but work after login.
Thunderbolt interface architecture up to Thunderbolt 3.
The new Kernel DMA Protection that is active in Windows does not let Thunderbolt docking stations initialize before booting into the Operating System (OS). This is working as designed.
Companies or individuals using a Domain login to push group policies may see this issue. This is due to group policies not being pushed to the computer before the User logs in.
To fix this behavior, the group policy must be changed to allow the docking station to initialize at the login screen.
Additional Information:
An example of the settings in Intune: