With this change, I have to choose between configuring systems to leave these users unprotected or waiting until the OS actually drops and then walking them through the rejection process. The former is a bad idea, the latter is a potential minefield, particularly with people who have a tendency to click first and only call for help once something goes wrong.