Sadly this is often due to regulations and industry expectations.
I work in finance and we get all these audits and questionnaires from regulators, insurers, intermediaries, clients, etc. and many of them are straight out of the 90s.
For example, when we replaced the VPN with a zero trust system, we got a ton of pushback. It didn't matter that the ZT implementation provided stronger guarantees than the VPN ever did as well as doing everything the VPN did. What mattered is that it wasn't called a VPN and they were expecting me to write "Cisco VPN" or similar.
Unfortunately, developers having admin access on their machines triggers so many red flags in these processes. Doesn't matter if you install a load of auditing and remote attestation stuff, admin access is instant ticket to bureaucratic hell.