RESOLVED!
After disabling / relaxing every 'common culprit' local security policy, I bit the bullet and reset all to defaults:
secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose
[https://www.tenforums.com/tutorials/68588-reset-local-security-policy-settings-default-windows.html][1]
I was then able to manually run the DISM command - successfully!
With the #1 issue out of the way, the automated WIN 10 update process ran without an issue.
Dev box is now running 21H1.