Hey Mike,
Just to further clarify, if the machine didn't come directly from Apple or an authorized retailer (e.g. with supervision out of the box) then I would need to disable iCloud entirely because those don't show in Apple Business Manager.
Is is possible to entirely disable all of iCloud in Jamf Now, or is that a Pro only feature? I don't see how to just turn it off entirely, just specific iCloud features.
You can retroactively add devices into Apple Business Manager with Apple Configurator (using either an iPhone or another Computer) which would be recommended, but this does also wipe the device so it might not be feasible to establish fleetwide for current devices: https://learn.jamf.com/en-US/bundle/jamf-now-documentation/page/Device_Preparation_for_Automated_Device_Enrollment_with_Apple_Configurator.html
Otherwise in Jamf Now inside the Blueprint you would go to Restrictions > Privacy and Security > and check off "Prevent Changes to Accounts." That will prevent them from signing into an Apple ID, and if you partner that by skipping the Apple ID during enrollment (for Automated Device Enrollment) then they would never be prompted to sign in. If your devices are enrolling via Open Enrollment then this won't work, as devices won't be supervised, and that restriction does require supervision.