I ran into this issue a couple of weeks ago and came to a similar conclusion. Everyone should check out MacMule's article. This is a solid explanation and resolution to the issue.
https://macmule.com/2016/05/09/icloud-spotlight-login-window-issues-with-jss-9-9-the-security-privacy-profile-payload/#more-2591
