I was unable to find any logs at backend as the correlation ID that you shared is more than one month old.
And to answer your question device information is sent to Azure AD by client as a header. Azure AD captures the device information, validates if this device is registered with Azure AD and also validates if the device is allowed as per CA policy configured.
If device information is not received by Azure AD then while validating CA policies Azure AD will block that device if there are any policies configured based on devices.
In your scenario, your security system is supposed to send the device information to Azure AD.
Do let me now if you have any questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.