The answer is yes & no at the same time :) Let me explain:
If you use the "AzureAD group filtering" feature, you can target devices or users. If you target devices, those must be (H)AADJ. AADR does not work.
If you don't use the "AzureAD group filtering" feature (your desired state, selecting 'all devices' on the settings page) we don't have any requirement regarding the directory membership. Servicing profiles will take all devices from inventory and check them against all selection criteria. Devices which match all criteria will be added to the profile.
So in your scenario, it would include AADR or workgroup devices.
What is the scenario behind the approach to exclude all non-AAD-aware devices?