The issue is:
1) Embedded devices that run Windows run the same Windows as your regular PC, possibly without any services being turned off even. So if base Windows is modified, those will be too.
2) Airgapped devices can't go online to verify every time you log in, and if it's built into the...