You said, "Internet Explorer hasn't been part of the operating system itself since roughly Windows 7"
"Windows 7 includes Internet Explorer 8 as part of the operating system."
"Windows 7 includes Internet Explorer 8 as part of the operating system."
https://www.quora.com/Which-IE-version-does-Windows-7-come-with-by-default
"..any 3rd-party apps simply adds to the vulnerabilities as I stated earlier, so there's never a more secure operating system possible than the original installation."
Naturally, all apps have their vulnerabilities. However, stating there's never a more secure OS possible than the original installation.. is just plain false. I know for a fact that most, if not all, experts in the security industry will strongly disagree. Windows has always been an insecure OS. I could write a book on all the tweaks and hacks I applied to XP to make it more secure! Firewall wasn't enabled by default. Services that shouldn't have been included or enabled by default, etc. After it's release multitudes of systems became infected by that internet worm. (I don't recall the name offhand.)
I realize there's been much improvement in 7 and 10. However, there are still out-of-the-box security issues with both OS's. I consider privacy invasion a security issue, as well. I'm sure you're aware of all the ways MS is spying on users in Win10, and I just read somewhere they're also ways they're spying on Win7 users, but I haven't looked into it.
As as admin, you're applied many restrictions on the systems you maintain. I wouldn't call that out-of-the-box security. Generally speaking, though, that's just not true and never has been.
Carol, I realize now that you are talking about the superficial point of Internet Explorer (IE) being "bundled" with Windows as if this means that IE is part of the operating system, when in reality this is nothing more than including an application with the operating system, as with any other app such as media player or notepad.
What I was talking about is the direct integration of Internet Explorer into the operating system itself as a portion of the Windows Shell and other critical system components. This is how earlier versions including Windows XP with IE6 were designed, which led to technical issues, especially as Microsoft worked to create the earliest version of Protected Mode within Internet Explorer 7. This "Separation of Internet Explorer 7 from the Windows shell" article describes some of the motivations behind that separation.
If you brief that article, you'll find a partial explanation of the groundwork that provides the highly improved security when Enhanced Protected Mode is enabled in IE11. That's because this separation of the browser from the shell allows for the increased isolation and so enhanced security that later versions of Internet Explorer have improved upon and to a great extent carried back into the earlier version of Windows 7 that these support.
Obviously you recognized that the various configuration items I'd discussed earlier made significant changes to the security of the operating system, so I'd assumed that either you or Christine would also understand that I was referring to the initial installation of Windows operating system files and applications, but not the default configuration of these in order to provide the best security possible. Of course this requires additional configuration, but nothing like most of the hacks typically seen in various 3rd-party articles, often turning off services and other settings these people typically have no understanding of.
Note that I've never turned off or changed the default services configuration of any system nor changed any other core system configurations other then those I've mentioned above, except of course a handful within Internet Explorer itself, none of which I felt worth mentioning since their effect on true security is minimal or obvious. For example Enable SmartScreen Filter which is prompted [and enabled] at first use of IE or Empty Temporary Internet Files folder when browser is closed.
Despite these apparently limited changes to settings, note that it's primarily these few configuration items that provide the enhancements to security, since in truth they were early releases of changes which were often made the default configuration in later versions of Windows. For example, the DEP capabilities within Windows 7 are now the default configuration in Windows 10.
So today we are many generations beyond the ancient history of Windows XP, but many consumers are still operating under the same delusions they held when that version was current. The reality is far more complex, but the user base generally knows nothing more technically then they did back then, still operating within a mythology that they use to feel comfortable that they understand what's going on, when nothing could be further from the truth.
Privacy is a separate issue and is confused by the fact that most discussing it have no idea how Microsoft treats this information any more than they do with Apple or Google. The fact that Microsoft provides more granular and understandable control over this information escapes most consumers, while they also have no idea that Google is infamous for collecting far more with virtually no personal control over its collection. The ability to control this information is a tradeoff with the need for access in order to use certain features such as Cortana, but that's far too confusing for the typical consumer to grasp.
I personally don't need Cortana with my Windows 10 system, since it has no microphone and is primarily used as a media PC for browsing. For that reason most of those features and privacy settings are turned off in my case anyway, including location, since I only wish to receive the default advertising for websites and block most of this with the Tracking Protection settings mentioned earlier anyway.
This latter setting is enabled more to block the random malicious material pushed through the advertising networks, with the lack of personal tracking and display of most obnoxious ads simply a nice side effect.
Rob