Keliath We have same handsets, and looking at rollout of a few across the business. The test phone we setup we put on a new vlan with dhcp provided by the firewall. We added any/any rules outbound and had no issue with it connecting to the Company Portal, as long as the devices can contact all M365 services they should be OK? Our test device went straight thru the intune enrollment and to the Company Portal where i was able to sign in (with MFA enable) on my Teams user account.
Once I can verify the logs on what its accessing and where I can look at locking down the rule further moving forward from testing.
On checking intune I didnt see it registered or any failed attempts for that matter, however it did appear almost staraight away on the Teams/Devices/IP Phones tab - It appears that management of the teams phones is being pushed to teams as updates/configs etc can be managed thru teams.