Hi there Josh,
hmmm I though I had updated this page with my latest 'progress'.
Anywho - I had a ticket logged with MS support, and it was assigned to various teams over a month long period. It was closed with the following "resolution";
Please be informed that, we discussed this issue with research team, currently, We do not have any workaround regarding the issue we are facing.
This technical functionalities do not exist or are not supported in the requested manner, hence, not much we can do as support.
I'm trying to follow up and get clarification on the following;
For Intune only joined devices (no SCCM presence) there is currently no way to configure Intune Company Portal as a managed installer in an MDAC/WDAC deployment.
As such the following article does not apply to Intune Company Portal;
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/configure-wdac-managed-installer
Still waiting on a reply back.... I'll keep trying though.
Doesn't give you a solution, but hopefully saves you wasting time on it (like I did!!).
Shane.