We have discovered some anomalises wth device status under conditional access.
With a sample number of users where I expect that AAD Registered, Compliant & EAS Activated to all be at 'YES' before the device is fully enrolled and receiving policies I have a numer of devices that work when some of the statuses are at 'NO'.
Example below:

The issue I have is for a security audit I have to prove a device passed all stages of enrolment before they receive service. In every case I have confirmed the user's device is active and receiving email.