Currently there are a broad set of tools to manage thousands of PCs from a core infrastructure, think Puppet or Chef for Windows Desktops. And you can set broad policies about software and access.
That sort of deployment, where you have say a call center with 1,500 people sitting in front of a PC to look up orders and such on their desk. You can update all of them, make sure none of them can surf outside to random web sites, etc.
It is also useful in a large technology enterprise where you have many developers. (Say a large C# shop of contract coders) because the tools help manage workstation build environments etc. When you are a mixed shop it is less useful.
Basically if all of your IT needs can be met by Microsoft products, they have a good story about how you can deploy them, manage them, and maintain them. There isn't a solid open source equivalent. Part of Google's strategy there is 'Chromebook' since if you're running a bunch of terminals that makes things easier to centrally manage.
If you were going to build something in the FOSS space here it would probably impose some strong limits on customizations in order to work. It would also need a way of disabling 'smart' employees from subverting the system (remember the kids who broke through the restrictions in their school issued ipads?) You have to think in the mindset that your employees are not your friends and may be trying to subvert the system :-) The "ideal" (and I put it in scare quotes because most employees hate it) is a workstation that can only run the tools to do your job, and only browse to sites that help you do your job.
I expect we'll get back to that and there will be a 'soft' network for personal devices which is monitored.