Maybe, I guess I don’t know enough to answer that. I do know that being on a company VPN isn’t always a requirement, though.
Either way, I’m not trying to argue for one approach to ad blocking over another as a one-size-fits-all solution, I just wanted to point out that it’s possible to have more control over the network than the computer in some cases.
Typically yes, assuming that the company VPN sets DNS to a set of company DNS servers. That is how my company’s works and several others I’ve worked for in the past.
Depends on how lax the IT department is when it comes to random executables. I was able to move the firefox installer to the appdata root, and run a non-admin install to my user profile.
Or a variation of this is TailScale configured to use NextDNS and a TS exit node. That's for anyone who doesn't want to maintain a PiHole. I've done both. Personal choice.
I recommended pihole to my senior webdeveloper. She didn't know about it and was blown away by the concept. She installed it immediately and is now living happily ad free.