Thats literally just a really shitty IT department poorly managing their MDM. And on Android at least the "work profile" is generally completely separate from your usual stuff and (if enrolled properly) the company cannot control major aspects of your phone (just the work profile). The company can remote wipe the work related sections, for example, but not your entire device.
There are settings though for passcode enforcement and whatnot