And a quick follow up - our security team does not allow rogue * .company.com wildcards - they hunt down those sites and boot them off the network.
They do, however, allow *.<service>.company.com.
They do, however, allow *.<service>.company.com.
> I work at a large Fortune 150 [...] we have [an] internal CA
(This was a lot clearer when there weren't so many other comments in between.)
I work for a large Fortune 150, one that you've heard of, and we have a security team that is constantly scanning our network for weaknesses and potential exploit vectors. They will kill (firewall off) any sites that might compromise the network and tell the application owner to fix the issue before they allow it back on the public net.