@WKATCL, Thanks for posting in Q&A.
For your issue, here are some information you can refer to.
Q1. Is it normal to ask for the unlocking code to a personal cell phone when accessing the work email via the Outlook app?
A1. If you have deployed app protection policy to Outlook app, it is normal to ask for the unlocking code to a personal cell phone when accessing the work email via the Outlook app.
Q2. Can a personal cell phone (BYOD) used to access work email via the Outlook app be changed to restricted or managed phone?
A2. Yes, you can change the MDM profile to Automated device enrollment (ADE) or Apple Configurator and apply an app protection policy to achieve that.
https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-ios-ipados
Q3. Why does the "wipe pending" stays for several months since the mobile device was wiped via the work email account after the Outlook app was already deleted from cell phone? The MicroSoft web site states that it would only take 5 minutes.
A3. It could be a show error; you can contact your IT department to clear or cancel the pending wipe request and re-try the wipe action.
Q4. Why does the phone still appear to be controlled by MDM after removing the Outlook app, performing a factory reset, and not seeing MDM listed under "VPN & Mobile Device Management"?
A4. If the MDM profile was removed and you cannot find it under Settings > Tap General > Scroll down and select VPN & Device Management, it means the device was out of Intune control.
Q5. How can this MDM be completely removed? Is there an MDM central server where the MDM profile is saved and controlled by an admin?
A5. To remove an MDM profile:
Open Settings.
Tap General.
Scroll down and select VPN & Device Management.
If an MDM profile is present, tap on it to view the details.
Tap Remove Management.
Q6. Can the MDM profile be removed by completely eliminating the work email account where the "wipe" is still pending?
A6. Removing the work email account from your device doesn't necessarily remove the MDM profile. The MDM profile is a separate entity that manages device configurations, policies, and accounts. To ensure complete removal of the MDM profile, follow the steps mentioned above. If the "wipe pending" status persists on your organization's server, it's advisable to inform your IT department so they can update their records and ensure your device is no longer listed under their management.
Hope above information can help you.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.