I'd be willing to bet dollars to donuts that the desktops/laptops are leased instead of the purchases that the tablets/phones are. Most large companies do that.
If they are leased any hardware issues are not addressed. The machine is removed, imaged, wiped, and returned for a replacement. A properly implemented AD helps alleviate the imaging.
If your IT guys aren't addressing hardware issues due to leasing, but rather software issues, your company isn't getting their money's worth out of them. There should be a simple, streamlined, and stable image. Administrative privileges should be restricted. Yada, yada, yada.
Your post mentions Bluetooth being disabled; what other security precautions are being undertaken? Are mass storage devices not mounted (removable storage access in gpedit)? Are non-white listed programs allowed execution (Application Control)?