I'd be really curious to know the frequency of IT departments reaching the conclusion that nope, FireFox x.y should NOT be installed. I have a suspicion that this is some ridiculously lengthy process that always gets a thumbs up at the end. However, I have zero experience in this so I am more than willing to believe that that's not the case.
Some years ago I asked one of the IT guys at a company I worked at about this. They had a laborious checklist to go through to make sure that no internal or external web apps broke.
This sounds like a small job, but the number of things to check when dealing with apps built internally and externally over the course of a decade or more is not insignificant. Factor in the failure case being potentially hundreds of staff answering phone calls with "Sorry, our system is broken" and you can understand the conservatism towards upgrades.
In the time he'd been at the company (18 months) two upgrades had been held back, one due to a bad stylesheet in an internal app and a second due to an incompatibility with a third-party site that used client SSL certificates.
It took a long time for Firefox to get the thumbs up as a supported browser for internal apps where I work. Like FF 3.5 maybe? Before that, if you reported issues, they told you to use the standard shipped IE on our laptop images. I imagine that the result of this kind of thing will be that FF goes back to the unsupported list.
(This is especially a bummer for those using Linux desktops.)
The basic idea is that if you do something lengthy and laborious and generate documentation that no-one will ever read then if/when it all goes wrong, you cannot be blamed, no matter how spurious your work is. It's like making sure you do all the right steps in a raindance, or ceremony for warding-off evil demons.
Basically when one of their low level "packaging" people screws up the install script. It took me 3 months for an IT department to give me an updated Java VM, as they had marked it "incompatible."