Hi Mij,
How long it has been since you updated the policy? Usually 12 hours is the time frame for the policies and data to reflect correct settings so I will suggest to wait and evaluate after 12 hours.
Also check via this command on one of the VMs to see the actual extension installed -
Get-AzVMExtension -ResourceGroupName [ResourceGroupName] -VMName [VMName] | Format-List ExtensionType