How can we control users 'registering' their devices with Azure AD. Currently, we don't allow anyone to 'join' the device with AAD. However, control to 'register' the device is disabled with a message saying "Allow users to register their devices with Azure AD (Workplace Join). Enrollment with Microsoft Intune or Mobile Device Management for Office 365 requires Device Registration.If you have configured either of these services, ALL will be selected and the button will be disabled."
Now, no one in the organisation can recall ever configuring MDM or InTune. May be it's activated by Microsoft by default.
Intune is a separate subscription, so unless you paid for it/trialed it, it shouldn't be available. MDM is part of all O365 Enterprise plans though, so if you are using such plan you can assume it's MDM's "fault". Even if you haven't configured any additional policies for it (as found under https://protection.office.com/?rfr=AdminCenter#/devicev2)