In Microsoft Intune it is possible to DEP enroll a Apple device on a device level into Intune.
When working with Intune and Conditional Access for O365 it is on a user level – so this means that it does not work for DEP enrolled device before the user also has enrolled the device with the Intune company portal.
When trying to access O365 mail on a DEP enrolled device (a device that your company has control over) you still get this message that you need to install Microsoft Intune Company Portal app
So you also need to enroll the device as a user.
An now when the device is enrolled both as a user and the device there is access to O365