Most of them use group-policies and other software to install root-certs onto company devices. HTTPS won't help you with MITM in that case.
Fun times getting blocked by the public/corporate firewall for something, hovering the mouse in the right place and pressing “s” and going, ahhh, “fixed it!”
With mobile devices (iOS/Android), web browsers also trust custom root certificates, but apps have the ability to reject them.
However mobile platforms are more finicky now. For example in Android 7 and above you can no longer add certs to the system store in most management modes. Only to the user store. And apps can choose whether to obey the user store or not. So many apps then refuse to work.
There's a few management modes that do allow it but they require a full wipe to start the enrollment process which starts from the setup wizard.