Earlier quoted context omitted.
"Typical users only care about the abstraction of web security so that's what Windows surfaces." Typical users do not open certmgr.msc
People that understand what certmgr.msc does (or should do) would immediately realize that it's not telling the full story.
Perhaps that could be written off as my failing in not knowing what certmgr.msc "should do", but Windows certainly does not make it very clear and I think it's reasonable for an average power user to assume that it shows all the trusted certs on the system, and not part.