The estate is more varied than the policy assumes.
Corporate laptops, personal phones carrying work mail, shared tablets on a site, kiosks and handhelds that never see an office, and contractors who need access for six weeks. A single policy written for one of those makes the others either insecure or unusable, and people route around whichever it is.
Enrolment is easy. The end of life is not.
Getting a device into management is a solved problem. What is usually unplanned is what happens when it is lost, when someone leaves, when a shared device changes hands, or when a personal phone has to lose its work data without touching the photographs. Those cases arrive whether or not they were designed for.
We segment first, then automate the lifecycle.
Group devices by how they are actually used and who carries the risk, then write a policy per group rather than one for everything. Automate enrolment so a new device is usable without a technician touching it. Define the retirement and loss paths explicitly, including the split between work and personal data. Then report on what is enrolled, compliant and drifting.
What you are left with.
A device estate you can describe, policies proportionate to how each group is used, enrolment that does not need a person, and a defensible answer to what happens when a device is lost or an employee leaves.

