It’s about on par with these tools no? Running a closed source configurator that heavily alters the core OS isn’t really something I would expect a responsible IT team to do. Doubly so if you are in any sort of regulated industry.
Many IT teams are irresponsible though. I have a client now that has revenue of $1B and has no legal review process and doesn’t require IT vendors to submit SOC 2 certifications or any other security attestations.
They could still switch to using a Linux machine for most things (that don't belong to the employer), segregating the Windows machine off as much as possible and never letting Microsoft near any of their own data.