They will whitelist super old known insecure java versions / windows versions etc that can NEVER change. I remember having to downgrade to windows 7 to access one VPN setup (yes - to get through the security firewalls you had to downgrade the entire stack to something the "security" firewall handled). I think this all was in part because they don't patch / update, so some stuff (flash / activeX etc) just doesn't work well on a modern machine
Ironically, they also would let their key domains expire but thankfully folks just would call a helpdesk and get an IP address to use (but these domain endpoints were 100% being hit by downgraded / unpatched machines so if someone had purchased the domain it would have been bad news).
For some places that were not inside an agency we had had to keep the "secure" machine separate from the actual network because it was the most vulnerable.
Thankfully, the help desk was so overwhelmed with calls about this horribly fragile system that they would reset anyone's password over the phone, so user lockouts were easy to handle, call up, ask that so and so's password be reset to XXXX and done (virtually no authentication other than knowing what number to dial). This was critical because the passwords had to be changed every 30 days and were insanely complex - we had lockouts even though folks thought they'd written them down properly right next to the machine (cap / lower / number / letter confusion issues?).
Meanwhile, my google account has proper two factor authentication, can be accessed from most any modern device, rate limits and screens login attempts in a smart way, and I haven't had to change my password in 15 years (so I could pick a hard one I don't use elsewhere).
Fun times!