Hi Craig,
I do not think it is due to any security concerns but more of what customers needed by default.
WindowsVPNEstablishment AllowRemoteUsers (default is LocalUsersOnly)
"Allows remote users to establish a VPN connection. However, if the configured VPN connection routing causes the remote user to become disconnected, the VPN connection is terminated to allow the remote user to regain access to the client PC".
Since the establishment of connection may result in disconnection of user depending upon routing, it is left to administrator (asa, vpn) to decide if such a functionality should be allowed or not.
Regards,
Kanwal
Note: Please mark answers if they are helpful.