ictoukit sounds like we're in the same boat. I don't know which clever person at Microsoft decided it was a great idea to assign two completely different enrolment types under the single 'Android' type. We have a few dynamic groups set up as well - Fully Managed Devices, Work Profile - Personal Devices and Work Profile - Corporate Devices. Now they're no longer adding new devices, as you'd expect and I can't see an obvious way to separate them for the dynamic groups.
I did notice, when using the Get-MsolDevice command, the only difference appeared to be the 'DeviceTrustLevel' property. Fully Managed appear to be listed as 'Managed' and Work Profile as 'Compliant' (and I'm assuming 'Non-compliant' too). I haven't had a chance to see if this property can be used though.