@MeliWil Thanks for posting in our Q&A.
Based on my understanding, it is not an expected behavior. If the VPN profile isn't deployed to the device, we will do some check:
1.Verify that the VPN profile is assigned to the correct group in Device configuration > Profiles > select the target VPN profile > assignments.
2.Verify that the device can sync with Intune by checking the "Last check-in" time.
3.If the VPN profile is linked to the Trusted Root and SCEP profiles, verify that both profiles have been deployed to the device. The VPN profile has a dependency on these profiles.
If all the above are normal, it is needed to check some logs in the AnyConnect app.
If there is anything update, feel free to let us know.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.