> In a company with controlled workstations, have your own CA and push the trust of that through GP or in your standard OS build
I'd be surprised if this did not cost when done properly. Securing a (even internal) CA is a whole thing that is not trivial.