I did lock down those machines, and even with a lockdown script I had (closed ports, shutdown services, etc.) it still took quite some time to admin all those Windows boxes. Dealing with constant critical updates was a pain. I rarely had to touch the Linux boxes though.
And don't go on about auto updates. Every update had to be tested before it could be installed, both to check for incompatibilities and to make sure the update didn't restart any services or something. That did happen -- without telling me, Microsoft started a service I had previously disabled for security reasons. Would you call that good security practice by Microsoft?
Don't blame your poor admin skills on the OS.
I'm blaming the OS for making me use too much of my time administering it.