This is the correct answer. Having your users run multiple browsers by default (instead of with whitelisted exceptions) is now multiple attack surfaces the org has to manage.
And if your company has any web presence or apps, you usually can't cherry pick which browsers your customers can use. That means some portion of your company will need access to other browsers for QA purposes.
You can do additional device management to lock down the rest of the machine. You can force Chrome and restrict Safari/Firefox/etc on Mac just fine. Same for Windows.