How do those changes interact poorly? A difficult password format requires a change to /etc/login.defs. Software pushes (if I understand what you mean by them) can be handled by the package manager (this would require the most work as you need to set up your own repository, but I imagine that is nessasary on windows as well). Configuring a browser proxy is done in the browser (or system wide). Encrypted /home directorys are the default on Ubuntu, and using TrueCrypt (or similar) fuel HD encryption is possible. Personal firewall is handled by ip tables.
GNU/Linux, by the nature of its userbase, has been forced to tolerate far more severe changes. The same software is used in countless configurations, on countless operating systems, some of which are neither GNU nor Linux. And once you have it set up, you could just make a master image and clone that to your target machines. Or, you could make a corporate linux distro with all of these requirements built in by default.