@Sokoban, Thanks for posting in Q&A. In fact, to enroll Hybrid Azure AD joined device into Intune, there are Autopilot Hybrid Azure AD join (mainly for new devices), GPO enrollment (mainly for existing domain joined device, Co-management (mainly for the devices managed by Configuration Manager).
To do GPO enrollment, the setting you provided is correct. You can set it via Domain group policy to apply to bulk of devices. But before doing that, please ensure the Hybrid Azure AD joined is successfully by run "dsregcmd /status" on the device and ensure Dmainjoined, AzureADjoined and AzureAdPrt are all yes. Here is a link with more details for your reference.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.