To manage Device1 using both Microsoft Intune and Configuration Manager, the device must be co-managed. Co-management requires the device to be joined to Azure AD or hybrid Azure AD, and managed by Configuration Manager. Unjoining the device from Active Directory would remove it from the domain, thereby making it unmanaged by both Configuration Manager and Intune. Thus, unjoining Device1 from the Active Directory domain does not meet the goal of enabling management by both systems.
To deploy Windows Hello for Business on Windows 10 Enterprise devices in an Active Directory domain, the prerequisites are having Microsoft Azure Active Directory (Azure AD) and TPM-enabled devices. Azure AD is necessary because Windows Hello for Business is designed to work with Azure AD for identity protection and authentication. TPM (Trusted Platform Module) is required to securely store and protect cryptographic keys, which is crucial for the security features provided by Windows Hello for Business.
To ensure that when users join their device to Microsoft Azure Active Directory (Azure AD), the device is enrolled in Microsoft Endpoint Manager automatically, you should configure the MDM User scope from the Azure Active Directory admin center. This setting allows you to specify which users' devices should be automatically enrolled in Microsoft Endpoint Manager when they join Azure AD. The other options do not directly address the automatic enrollment of devices upon joining Azure AD.