Earlier quoted context omitted.
They don't MITM, they record sessions and later decrypt out-of-band as needed. With TLS 1.3, they would need to MITM, which require infrastructure changes and potentially affects the performance. They are complaining TLS 1.3 forces them to do work they otherwise wouldn't have to do.
But how doe they get access to the keys for the session without modifying the end hosts or MITM'ing the traffic?
They have full control of the end hosts. That's why the group policy forces you to use Internet Explorer instead of letting you use Firefox.