>HMM ... there are hardening settings only available through Configurator or MDM profiles. Will those be defaulted on as well?
Yes, that one leapt out at me as well as kind of an awkward one with more compromises, painting with a very broad brush. It's obvious that some of the very powerful config profiles/MDM capabilities could be used for a lot of mischief, but some of them are also exactly what I'd want to be running myself if I was at a lot of risk, and some are both. Ie., continuing to have one's own offline based CA with proper Name Constraints could be handy for a group of people who want to try to better secure and keep private their own internal network services from anything short of a government physical assault, but if an attacker can slip on a profile with an unlimited CA your goose is cooked.
Perhaps Apple simply doesn't have the capability for fine grained control of those capabilities yet, which wouldn't be surprising given their path up until now. I'll be interested to see if over time Apple leaves this mostly untouched or invests in seriously improving it. Like it'd be interesting if you could boot into a special mode ala DFU though requiring password and with graphics up and have a bunch of toggles for various capabilities that would then be enforced in normal usage. Analogous to the Recovery Mode on Macs.