Not aware of any technical reason, but I assume that these are CAs managed by different teams and integrating the Windows build process into the third-party signing chain would probably be a lot of work. Also, Windows would then stop booting on these machines that have already been deployed.
no subject