It might depend on how much your IT departements cares about customizing your setups. The efforts described in TFA for instance don't cover auto install scripts which are still free to create whatever local account is needed, provided it's done through the fleet management mechanisms.
Much of the scripts to "debloat" windows also rely on MDM entry points and overriding user preferences with higher privilege.
As you point out it's still a cat and mouse game but I assume they work OK. I tend to go the painful way and do most of it myself following instructions, as I'm not comfortable having these tools run as admin on a system. It's not that bad either.
Much of the scripts to "debloat" windows also rely on MDM entry points and overriding user preferences with higher privilege.