The user has to have some level of technical knowledge and personal responsibility in keeping their machines clean. Downloading random VPN software that is free seems like such a dangerous thing to do. If the user doesn't understand this, they haven't really learnt how to computer properly.
Meanwhile Mac will go so far as to completely deny you the right to run code it can't identify the developer of, until you go into the settings and temporarily grant yourself the permission to do so.
It is fundamentally impossible to prevent a user from doing bad things to their systems unless you are willing to 100% prevent the running of code that you can't identify with 100% certainty.
The problem with the desktop security model is the controls are ridiculously course-grained.
it'd be really nice if it was more efficient to run an OS like https://www.qubes-os.org/. I think only true security model that works is the sandbox isolation model of virtual machines.
It will also warn you that you are installing unsigned software in scary language.