Especially if they have valid concerns of degraded performance from past updates. That’s a recipe for an adversarial user-IT relationship and inevitably drives users to attempt their own, sometimes risky, work arounds.
Like developer experience roles, maybe security departments need specialist 'user experience', teams or ICs. I think there's fertile middle ground here between anarchy and the received wisdom on 'best practices'.