As our organization is slowly rolling out Windows 10, I made the observation of a DirectAccess GPO linked to the Windows 10 PCs OU (which contain internal desktops, laptops, and even VMs for VDI). This GPO was identical to our standard DA GPO, except it was scoped to Authenticated Users, instead of a "DA PCs" security group. I pointed out this oddity to our senior admin, and interestingly, he says that because Windows 10 supports DirectAccess, it should be enabled just because we already have it set up.
I see several problems with this, but the major one would be increased load on the DirectAccess server from clients who don't even need it. Is deploying DirectAccess to all clients a reasonable design choice, or is it bizarre? What are the benefits/drawbacks of doing so?