Steve_PrenticeYes, using Client Apps > App Configuration Policies with a "managed devices" device enrolment type. Used the configuration designer to set a basic authentication profile, and this was also working fine for Android work profiles.
Two things to note:
1) The device owner preview does not support targeting policies at devices, just users. Check your policy assignments are using a user based group or "all users", not a device based group otherwise the policy won't apply. Same applies to the apps themselves, assign these to a user based target otherwise the apps won't deploy to the device.
2) Even though the policy applies OK, the user is not listed at all on the "user install status" tab of the app configuration policy. The device shows under "device install status" but with a username of "none" and device status of "pending". Clearly some reporting issues here.