I agree in general. And I do not get the BYOD thing. As another commenter said, an employer should provide the tools necessary. Or live with the constraints.
I am in another camp. Until recently my employer had a policy of treating our devices somewhat like private devices. We are provided with the device, are allowed to use them at home at will, are full admins. We are only requested to encrypt the harddrive. My employee never had access to my data if I did not provide it to them.
So now two situations changed. Clients of ours force us to use endpoint management to ensure different "security" standards (some not as secure as I had before). Also we got bought by a bigger company and they have rules and regulations for their ~470k employees. These mean we will get some hefty spyware on our devices while still being officially allowed to take the devices home with us, use them privately and so on.
Well. I am not so sure, I will do this in the future. I am not willing to introduce spyware that also scans all devices within the network to my home network. I do not want some admin on the other side of the world to be able to download any file from my device. Or to upload any file onto my device.
So I will probably buy another computer (not having owned a private laptop for quite some time) to use at home. Same with my mobile phone.
On the other hand - I hate to carry two devices with me. For me separating out private/freelance stuff onto one machine and corporate stuff onto another makes things more complicated. And I know convenience kills security.
Sorry for my rant, without providing much to the discussion. I mean - it is my work device and my employer is within their full right to install whatever they wish - once the works council agrees.