Intune_Support_Team According to MC284343 this is now GA. I tested this myself and experienced the same as the first 2 posters about an additional device management profile now tries to download. We don't really have a simple Intune Environment and have heavily locked down DEP devices that have no apple id on them. As I tested the following:
Changed the enrollment profile to:
Authentication Method: Setup Assistant w/ Modern Auth
Install company portal with VPP: Token specified.
Device was wiped from the intune console. Upon going through the setup assistant everything went ok, eventually some apps started to deploy to the device. Company portal didn't install until 30 minutes later along with the rest of our deployed apps, based of an Azure function app which moves devices to device based azure groups to separate out device types. At this time I tried to open Outlook, which I believe it stated the device needed to be registered, added to Authenticator, then proceeded to open CP. At this time it downloaded another device management profile, which can't be installed. I only have the CP deployed to a device based group but there is no app config policy for it. Same issue as the above posters.