Someone posted on here earlier but it seems to have disappeared - but thank you anyway! Resolved for us by changing the MAM/WIP intune setting to "Some" and excluding (well, not including) certain users (in particular those with AD joined machines - they are not hybrid joined, just AAD registered) - took about 20-30 mins to take effect but it worked.
Thank you!