@Greg Fletcher Thanks for reaching out. If I understand you correctly, you want to understand why few of the devices are not shown under endpoint portal but are visible under Azure AD Devices.
Devices which are present under Endpoint manager, are shown only when the devices are enrolled in Intune. The devices get Auto-enrolled if you have setup for it.
Devices can explicitly register for Azure AD without having to get enrolled into Intune.
Here is how you can remove the Stale Azure AD devices : https://learn.microsoft.com/en-us/azure/active-directory/devices/manage-stale-devices
If you want to get rid of MDM controlled devices, follow this , https://learn.microsoft.com/en-us/azure/active-directory/devices/manage-stale-devices#mdm-controlled-devices.
-----------------------------------------------------------------------------------------------------------------
Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.