It's likely that the assumption is that in 'enterprise' or large organizations software installation and configuration is managed or that they fall back if they can't (but as the blog post says; DNS over HTTPS is hard to block).
With BYOD that is less and less likely to be true..
And Android P is already gearing up to DNS over HTTPS as well with Android itself going with DNS over TLS.
Don't know what the iOS stance on this is.
I've not seen many orgs manage FF settings. Typically AD policies apply to MSIE/Edge. Has this changed?
As a single data point, my current and quite large company manages firefox settings. I discovered this when they turned off the search in address bar feature...
Cool. I hope this is becoming more prevalent. A coworker gave me a link to the policy (for windows) [1]
If anyone wonders why anyone would do that it might be because the autocomplete in search bar leaks metadata not only about what you search but also about what sites you visit.
It seems many orgs manage to shoot themselves in the foot quite badly with centrally managed browser. In all the environments I've seen, IT have managed to disable auto-update on Chrome or Firefox and break the centrally managed updates for a long time, creating an easy avenue for malware or worse to get in.
best response I've had to that is 1) they'll retry queries internally if they don't work externally (leaking everything first) 2) people should not have internal only domains, everything to the cloud!
That seems very leaky to me. It would be a shame if we had to block CF's DNS IP's.
I would rather CF (or any other company) not get a list of all our internal domain names.