Authorization of an Entra Joined Device is not currently possible in ISE, and neither is EAP Chaining an authenticated User session and Computer session. This is specifically stated in the ISE 3.2 Release Notes
With Windows 11, most organisations are moving from the legacy on-corporate-network PC staging/build process that is controlled by SCCM and uses the PXE boot process to a Windows Autopilot process. For Autopilot, the user would just need a bare internet connection to complete the build, so this could be potentially be accomplished by connecting to a Guest BYOD portal or hotspot of some kind. Part of the AutoPilot process would be enrolment with Intune which would also enrol the Device/User certificates, after which point the user could connect to the secure Corporate network.