@Half One Thanks for posting in our Q&A.
For this issue, it seems that you use the MAM enrollmennt and not MDM enrollment. MAM means intune manages Apps and doesn't manage the devices.
To clarify this issue, we appreciate your help to collect some information:
1.Please check if the MDM of these devices shows "Microsoft intune" in Azure AD portal. For example:
2.Please check if there is any app protection policy which managed type is "Without enrollment" protecting office apps.
If there is anything update, feel free to let us know.
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.