If you are asking if Wi-Fi Profiles can be assigned and work with Android Enterprise Work Profile enrolled devices using Certificate based Auth or a User based certificate profile (that was a mouth full)? Yes, this should work without issue.
Do note, that currently, as per our Android Enterprise Fully Managed Preview blog, Certificate and Wi-fi Profiles are not yet available for Fully Managed devices..... only BYOD Work profile enrolled devices.
As per our Docs, Create a SCEP certificate profile, Step 6 details:
..."Certificate type: Choose User for user certificates. A User certificate type can contain both user and device attributes in the subject and SAN of the certificate. Choose Device for scenarios such as user-less devices, like kiosks, or for Windows devices, placing the certificate in the Local Computer certificate store. Device certificates can only contain device attributes in the subject and SAN of the certificate. Device certificates are available for the following platforms"....
The NDES Connector and related server configuration is the same for User and Device based certificate deployments. the Difference is in the settings of the SCEP Policy define in the Intune Admin Console. When selecting Device based certificates, the device's attributes are used to build the Subject and SAN for the certificate request vs the User's attributes. Device Based CAN be used for devices that do not have User Affinity as well.
Hope the helps clear up the confusion. If you are facing an issue with Profiles not deploying as expected, please open a support case via the Intune Admin console's Help and Support. Our support folks would be happy to assist in determine what's wrong with your configuration.