Absolutely right
The only reason to have a "proper" root cert is if you want to be sneaky an pull in people who are not using corporate systems. That's a bit of a hail mary due to the proliferation of personal 3g links which bypass the whole lot.
Either that, or its a very large organisation without the ability to manage its devices' certs. I suppose that isn't too unlikely.
