@sam chidlow, Thanks for posting in Q&A. For our issue, could you confirm if our issue affected with all devices or some?
For 24H2, I find a known issue with DFCI enrollment.
With Windows Autopilot Deployment and Intune, Unified Extensible Firmware Interface (UEFI) settings can be managed after the device is enrolled. UEFI settings can be managed by using the Device Firmware Configuration Interface (DFCI).
https://learn.microsoft.com/en-us/autopilot/dfci-management
If your device is with Windows 11, version 24H2 Pro edition, install KB5046740 or later to see fi the result will be different.
For Conditional access policy, please check if the "Microsoft Intune Enrollment" and "Microsoft Intune" apps are excluded from your Conditional Access policies.
Please try the above suggestions and if there's any update, feel free to let us know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.