@AZee, Thanks for posting in Q&A. From your description, i know the devices are failed to enroll into Intune via GPO enrollment. From the error message, it seems we use device credential to enroll. In fact, Device Credential is only supported for Microsoft Intune enrollment in scenarios with Co-management or Azure Virtual Desktop multi-session host pools
If we are not Co-management or Azure Virtual Desktop multi-session host pools, please change the credential type to "user credential" in GPO.
Meanwhile, please also ensure it has both Microsoft Intune Plan 1 and Microsoft Entra related licenses assigned and MDM user scope is set all or some which include the users under automatic enrolment.
Please check the above information and if there's any update, feel free to let us know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.