Because it's not very useful, very replacable, requires them to keep email addresses, and it's costing them extra resources for the free service they provide.
They manually create certs at my job then manually move them other to a network drive and then a gpo? policy installs those certs to AD users.
I found a way to automate this process (but company didn't care)
But I'm not an IT person, what's the best approach for doing this on promises?
edit: I like the responses but I was hoping for something that wouldn't use 3rd party products. What if hypothetically the certificates were self signed and you wouldn't need a 3rd party CA?
Another thing is: is using 3rd party CAs really the most common way ?
Luckily Let's Encrypt made automation more popular. Every new domain of mine gets a cert that is renewed automatically. I don't have to worry at all about it.