Related issue
#34306
Task
We found out that Entra doesn't support a silent/clean migration from one conditional access Multi-tenant application (JAMF) to another (Fleet).
So we should roll back the changes to ingest the legacy "Device ID" from the keychain and always ingest the one stored in the secure enclave (via the app_sso_platform table).
More information can be found in the related story #34306.