Hybrid AD + Intune shops often keep GPO for the plant floor and Intune for knowledge workers. For CM least-functionality style practices, do you want one policy story or is a documented split acceptable?
Looking for assessor pushback patterns, not vendor wars.
A documented split is fine if both paths are covered and the boundary is clear. What fails is “Intune for most, GPO somewhere, nobody owns the matrix.”