Forum update:
This issue is now resolved.
The reason the renewal is pending is that the CA expect the SubjectAltName in the previously issued certificate to be either of type cert_alt_name_other_name or cert_alt_name_rfc822_name. The name in the previously issued certificate is of type dns name. For this reason, the renewal gets pended. The document is correct as far as the flags priority is concerned. A bug has been filed against MS-WCCE to add the subjectAltName requirements for renewal.
Regards,
Obaid Farooqi - MSFT