The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.
Another manager told users to just bypass the certificate errors on a new web service.
Multiple times I've had people tell me over teams to do all kinds of weird things to work around security errors.
It's a weird thing where people in IT think the security rules are for everyone else and not for them. And it's just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company's domain] and the cert is valid and if it's an internal service, use kerberos to validate the user so they don't even enter a password.
The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what's needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.