Greg_A You would have been my hero if i hadnt figured out that what you described in your comment above was the exact issue we were having, we dont have any corporate Android devices, so disabled this setting under customization a couple of years ago to avoid confusion with our Android BYOD users. This was killing the Android MTR devices we had from enrolling.
I found this article (https://learn.microsoft.com/en-us/mem/intune/apps/company-portal-app#device-enrollment-setting-options) and spotted the lines about “The following settings do apply to Android devices configured with Samsung Knox Mobile Enrollment (KME). If a device has been configured for KME and device enrollment is set to Unavailable, the device will not be able to enroll during the out of box flow.”
Got me thinking about how these devices essentially operate in a similar way, so i created a separate customization policy and assigned it to the dynamic user group with our MTR accounts in it and bingo the test device i was working with flashed straight into corporate ownership and intune managed !
Intune_Support_Team Highly agree with your suggestion that this be included in the guidance article above and any other MS docs on hand, wouldnt be the worst idea to also link off to the required URLs pages to help identify firewall rules as well (aka all the manage.microsoft.com ones are not required for Teams, so were not part of our Voice VLAN firewall rules, had to add these too).