Seems that the problem is resolved.
We had to reset the laptop and let it hybrid join and sign to intune again.
The only difference this time is that we had the laptop connected to the network by cable and not over wifi but I think that has nothing to do with the fact it worked.
Another odd thing we were getting before and didn't mention is that there
was a message that can't access company resources because Windows defender antimalware real time protection is off...something that apparently wasn't true. That caused the laptop to show as non compliant.
Luckily by redoing the whole process on a formatted laptop worked this time.