- Machines get verifiably "slow" for no apparent reason. This is sometimes fixed by a reinstall, sometimes isn't.
- Even on supposedly "locked down" machines, you'll come around for a support call and find 15 IE toolbars sometimes. It apparently requires a genuine domain expert (which some $100/hour enterprise network consulting firms in the Midwest don't have) to accomplish a seemingly common goal on a Windows domain with Group Policy: only run the software we preinstall for you.
- The infrastructure to automate installation of your Windows image via netboot technically exists, but is expensive (requiring salespeople and resellers) and difficult. Large corporations tend to have it, small-medium ones tend not to. I spent most summers of my adolescence clicking through Windows installers.
- People install (and are exploited by) malware pretty regularly.
- Windows Server and particularly Exchange are dominated by quirky, undocumented behavior on the sysadmin side. You cannot do what seems natural or what it says in the manual - you need a subject matter expert who is experienced in all the ways common admin tasks will break things and how to fix them. Not 1/1000th of the time, more like 1/5th of the time. It also generally requires a business partnership with Microsoft so you have access to real support people. Even they aren't always helpful.
Managing a healthy Windows domain is certainly possible, and lots of big companies do it more or less, but it requires a whole lot of effort, highly experienced people who can "eat" the quirkiness and complexity, and a special relationship with Microsoft.
This might be reasonable for a very large, complex deployment, but it's also required for the simple case of "deliver an office suite and web browser to ~35 computer-illiterate people." I think any modern SaaS company would be appalled to deliver something with UX as poor as Windows for small-medium companies.