Registering devices with Intune for management and policy enforcement
Hi Sanjit,
Since certificate enrollment works over the internet but fails only on the corporate network, I would first check the internal firewall, proxy, or SSL inspection rules rather than the Intune profile itself.
Microsoft requires managed devices and the Intune Certificate Connector to reach specific Intune endpoints. If you are using SCEP, also confirm that devices can reach the NDES URL over HTTPS from the intranet and that NDES can communicate with the CA, DNS, domain controllers, and Intune.
Comparing the network traffic from a working internet connection with the corporate network should help identify which endpoint or request is being blocked.
Thank you, and feel free to respond back for more assistance.