Seeing the same issue for a client wanting to move all their devices to Intune and the first test device, joined through a bulk enroll provisioning package, had the Company Portal pushed as required but I have many Win32 apps I've built in Intune that are set as available because they're large installations the customer wants on demand. In Intune the Owner and User name fields are populated with package_{GUID}, which I'm guessing is the sticky point for why CP is freaking out over the wrong user opening the portal. The client also doesn't want each user to be an admin on their system, which is a requirement for the account joining AAD and staying connected (if you remove admin privs you lose AAD connectivity), so joining devices as each user is not only a security requirement but the manual effort required is the whole reason for a bulk enrollment solution in the first place.