Tag not monitored by Microsoft.
Hello,
Yes your understanding is absolutely correct the machine either needs to be hybrid azure ad join or azure ad join in order to push updates from Intune console. The reason why you need this is that Intune is a SAAS service and in order to connect with Intune it needs a dependent for authentication that is azure AD.
If you don't have azure ad you can not enroll your machines into Intune. If you don't have azure ad and you can use any on prem solution for deploying the updates like system center config manager and through that channel the Feature updates will be deployed.