@Stefan D, Thanks for posting in Q&A. From your description, I know you are doing Windows Autopilot user-driven Microsoft Entra hybrid join. But it is failed. For the domain join profile, I find you have assigned it to user group. In fact, the domain join profile applied before user sign in. Therefore, we see it not applicable when you assign it to user group. We need to assign it to the device group. Please change it and see if it can work.
Please try the above suggestion and if there's any update, feel free to let us know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.