I know all the reasons why this isn't a good idea, but everywhere I've worked, people do it to prevent ad-hoc requests from people who don't have access.
My feeling is that this is a "open secret" that most SMBs do it, but I'm keen to hear:
1. Whether you / your company does it
2. If you avoided it, how did you do that
reply