Processes in Microsoft 365 for setting up Office apps, redeeming product keys, and activating licenses.
First, I'd like to clarify that this is a user-to-user public forum and not an official Microsoft support channel. I am a forum user and do not have the ability to initiate, or request internal engineering investigations on Microsoft's behalf. The information I conducted are based on publicly available documentation, and my own research.
Based on the information provided, I cannot confirm that the cause is specifically a split-token handoff issue, Click-to-Run defect, or bootstrapper problem. These remain possible hypotheses and would require appropriate diagnostic data and investigation to establish.
The observation that the migration succeeds from an elevated interactive Administrator session but fails when deployed through Intune does indicate that the two execution paths are behaving differently. However, Intune-managed application deployments commonly run in a different security context than an interactive administrator session, so a difference in behavior by itself does not identify the specific component responsible for the failure.
Regarding Secure Score, Microsoft does document that Secure Score for Devices currently has only partial Intune support. As a result, configurations set through Intune may appear as misconfigured in Secure Score even when the actual device configuration is correct. This is an assessment/reporting limitation and does not establish that the security configuration is incompatible with Intune or Microsoft 365 Apps deployment.
Ref: Microsoft Secure Score for Devices - Microsoft Defender Vulnerability Management | Microsoft Learn
Determining whether the reported Office migration failure represents a product defect or an expected limitation would require review of the relevant Intune and Click-to-Run diagnostic data.
If you do not wish to open a support request, I recommend file a feedback via Feedback portal.