If Windows, it requires a VM and currently infosec is not keen on virtualization in the hands of users.
3 points
I’m no expert, but isn’t running in a VM strictly better than running on raw metal from a security perspective? It’s generally more locked down, and breaking out of the virtualization layer requires a separate security breach from gaining access to the running container.