@Miyajima, Norikazu, Thanks for posting in Q&A. From your description, it seems you want to enroll the devices into Intune and the devices are joined to on-premise domain. If there's any misunderstanding, feel free to let us know.
From the steps you provided, it seems you are doing Azure AD registered with auto enroll into Intune. One device is only Azure AD registered without enrolling into Intune.
You can follow the following steps to see if it can help:
- Please check if the user has both Azure AD Premium license and Microsoft Intune Plan 1 license assigned in Intune portal.
- Please check if the automatic enrollment is enabled. You can set MDM user scope as All and MAM user scope as none.
In addition, for your situation, I want to say something. For the Azure AD registered devices, they will have some limitation when using Intune to manage these devices. like Feature update policy is not available.
https://learn.microsoft.com/en-us/mem/intune/protect/windows-10-feature-updates
I think you can consider doing Hybrid Azure AD join for these devices. This is recommended for your situation.
https://learn.microsoft.com/en-us/azure/active-directory/devices/howto-hybrid-azure-ad-join
After the devices have been Hybrid Azure AD joined, you can choose GPO enrollment method to enroll these devices into Intune. Here is a link with more details for your reference:
Hope the information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.