lots of questions... Are you using a KMS? do you have volume licensing? A digital copy is generally linked to a Microsoft account. If you have an Azure AD tenant, assign the license to the user and have them sign into the device to register it.
A digital copy for a single use license needs to be assigned to a user, and then that user needs sign in via the windows settings app (not domain joined) or into the device at the logon screen (if an AAD user).
There are too many unknowns to answer this question, but if you have port 443 open on your firewall, you should not be having these issues if you can log into *.microsoft.com