@Rookie{} , Based on my research, I find if the Windows 10 or newer domain joined devices are Azure AD registered to your tenant, it could lead to a dual state of hybrid Azure AD joined and Azure AD registered device. We recommend upgrading to Windows 10 1803 (with KB4489894 applied) or newer to automatically address this scenario
https://learn.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-plan#handling-devices-with-azure-ad-registered-state
For our situation, i would like to confirm which version our windows client is with? Is it above Windows 10 1803 (with KB4489894 applied) or newer?
In general, the Azure AD registered record needs to be removed before we plan to do Hybrid Azure AD join. And the GPO enrollment needs to be done after that. For our situation, to avoid any issue in the future, we suggest to unenroll the affected device, remove the records in Azure AD. Then do Hybrid Azure AD join again. After these are completed, apply GPO to enroll them into Intune.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.