Yeah, one command - on every machine... Meanwhile on Linux, I don't need to do any special configuration to run scripts.
I think Microsoft envisions centrally-managed environments, rather than those with lots of Windows machines that aren't centrally managed.
Or through one group policy pushed to every machine.
So the company can push their CA and new PS policy in a single GPO, and then all internal PS scripts are signed using an internal CA generated code signing certificate.
This sounds complex but it is actually as simple as running Set-AuthenticodeSignature on each script using the code signing certificate.