@Lu Dai-MSFT I may have discovered the cause, which was missing various scope tags for the tokens. Going to try to see if various device managers are available to give this a whirl.
Grant user ability to assign auto enrollment profiles
I have recently been handed the Intune administrator role or a system with the base set up. I have created multiple auto enrollment profiles that I would like each "device manager" assigned to various departments to set to a device based off their needs. I have a custom role in place to try to allow these device managers access to view the token and assign profiles, the only problem is that they are unable to even see the token. These roles are similar to the built in Policy and Profile manager roles in Intune, but with a little more rights. I have all of the Enrollment program settings set to update/assign profiles and read tokens but missing a setting somewhere if they can't even view the token to start viewing devices and profiles.