I usually am replacing the hard drive anyways for performance and size. I never even boot up windows on a refurb, pulling that drive and setting aside before hand.
Visually inspect the motherboard for any obvious shenanigans. Then install Linux.
Simply put, you cant have 100% certainty that a used or even new system hasnt been tampered with. And its actually far easier for a state actor to target a user via a new system vs a used one, particularly if theres supply chain impact (buying apple, dell, hp, lenovo, system76 etc from factory)