Below is the response from Azure Sphere Product Team, I hope this helps in your query.
As part of device registration process, manufacturer uploads the device public key files to Microsoft through a secured connection. Microsoft associates devices with the public keys.
Do let us know if you have further queries.
Please accept helpful responses as 'Answer', which will be helpful to others as well.