Ironically, this feature works on Intune for MacOS...
It works for Hybrid Joined, but you need to use GPO/BULK autoenrollment, unfortunately. It needs manual enrollment support too.
Apparently this is still not fully supported. For Hybrid Joined devices, you have to use GPO to get this working even though this is not stated anywhere. It only states you have to have auto-enrollment setup (MDM page).