A big part of sudo is that you should be running individual commands using sudo to increase auditability rather than simply running sudo bash or whatever.
I honestly thought they’d be using ssh that way (single command at a time), though I’m still not sure to what security end.
Also, may I introduce you to the ‘sudo -i’ option.
Keep in mind that this is borderline impossible to enforce unless your goal is just to stop the most common ways of accidentally breaking the policy. A list of commands that allows breaking out into a full shell includes: less, apt, man, nano, wget & many more.
This made me chuckle. Apple influencing the way Emacs is capitalized (pun intended) versus RMS's stance on Free Software couldn't be further apart I think.