Isn't the whole drive towards zero-trust network configurations to allow BYO device to work, i.e. to assume that every device will be compromised and plan accordingly? Seems much better (to me) than crippling the desktop environment of your employees and hobbling their productivity.