If its working with the CA Policy off you can just exclude it from the policy as a work around.
As for the non-compliance status in intune for RDS. I'm wondering if Windows Server OS are supported here. Perhaps only the windows client OS are supported.
However if you go into intune to the compliance policy is should show why that device is failing compliance. Might give you a clue where to look. Go to the Device in Intune and then select Device Compliance.