Or they can provide default VMs which have a company certificate as a trusted root, either locally or in the Active Directory. Then it's simply a intercept and dump without the browser complaining. (I cannot confirm the active directory problem in other browsers apart from IE)