From own experience this is 99% corporate shenanigans.
You should have a serious talk with your IT department. Sometimes they are not aware how much garbage they are throwing at people through Active Directory.
In my experience, the best way around such issues is to force IT to dogfood their own system instead of having special laptops for IT employees.
For the IT department it's a tradeoff though; they'd rather have everyone be inconvenienced or their hardware not working at 100% than to risk a virus wreaking havoc on their networks, or ransomware crippling their whole organization. Even without the restricted Windows machines they struggle with enough shit already, because people can't behave on company hardware on the one hand, and every employee is a target.
You should have a serious talk with your IT department. Sometimes they are not aware how much garbage they are throwing at people through Active Directory.
In my experience, the best way around such issues is to force IT to dogfood their own system instead of having special laptops for IT employees.