SharePoint Conditional Access

I have a question about the CA policies that are created if you enable SharePoint Admin > Policies > Access Control > Unmanaged Devices and Apps that don't user modern authentication.
Enabling both of these creates a corresponding CA device policy, but they are applied even if a user does not have Azure AD P1 license applied. For instance, we have users with F3 licenses, but they will still receive the prompt that their org has not permitted them to download/save/print from this site. Are these two policies special and do not require a license to enforce? It's always confused me about Microsoft and what policies they'll apply, because it says you need an Intune license for app protection policies to be enforced, and it "looks" to be true. We also have a location based CA and I would assume it would be enforced on anyone...
I'm just confused on the differences of what CA policies/app protection policies can apply to our users even if the said user account doesn't have an Azure AD P1 license or Intune license.