Coopem16 Yes, Microsoft confirmed that this was not the expected behaviour, but could not provide an answer on why a different unlisted cloud app had been authenticated against. After the 2003 Intune service release, authentication resumed using the "Microsoft Intune" and "Microsoft Intune Company Portal" cloud apps, as designed.
The cloud app "Microsoft Intune Company Portal" is used for portal.manage.microsoft.com, so you can target that cloud app while creating your CA policy. The "Microsoft Intune" cloud app is only used for Android Enterprise fully managed and dedicated devices.