We don't get that problem Steve_Prentice. We enrolled the device (Android 8.1) using QR code and logged in via ADFS during the initial enrollment, but don't get prompted for any further enrollment afterwards.
Maybe worth checking all the settings in your device or app configuration policies? Did you perhaps choose Modern Authentication in your outlook app configuration? I think this authenticates directly to O365 with MFA. We use basic authentication to authenticate to on-prem Exchange using ActiveSync.
To clarify my earlier post, IF the user does manually set a PIN/password, they are required to meet the minimum requirements of the device configuration policy, and once set the errors no longer show against the device configuration policy status. So the policy is applying correctly, it's just an issue with forcing the user to add the initial PIN/password before allowing access to corporate resources.