I might be too late to the plate, and I have stopped trying full managed functionality as I suffered the compliance policy issue, plus the never ending installation of the default apps. I thought I would take a fresh look at this, and was grateful that I did, it would seem that the majority of issues being suffered have been resolved.
I have recently enrolled a couple of devices from OOBE into fully managed with everything applied (configuration and compliance policies) and noted that the enrollment was fast and reliable. We are using dynamic groups to assign the apps and some policies, all of which are quickly assigned deployed to the devices. Also performed some more testing on updating the configuration policies whilst a compliance policy is applied and all settings were updated quickly. We have seen some of the new functionality apply (as mentioned by PKlapwijk and these devices are nearing feature parity to where we need it to be.
Feature Request: Make the Intune App setup as part of the enrolment process (similar to the process Apple DEP devices now go through).
Feature Request: As Authenticator App is a default app deployed, make this setup part of the compliance policy / enrolment process (however also make it something that can be excluded for businesses whom use MFA alternatives.
Feature Request: Ability to set the launcher to Microsoft Launcher so that the experience can be standardised across different devices / vendor devices.
Feature Request: More configuration settings that can customise the end user experience similar to supervised devices in iOS e.g. wallpaper, page layouts etc even if this is tied to Microsoft Launcher for Enterprise.