>Without looking towards the MDM solution, I guess the admins/guest will also be used for the ownership of devices?
No. MDM owners are a seperate entity again. MDM owners are often only used to denote the owner, but can optionally be used for authentication in the MDM environment as well.
>Is there a reason those dB's are separate? Because I see a big potential for overlapping users without the option to share users between those dB's.
The Organization/Network administrators tend to be static. The guest users tend to turn over much quicker.
You could always use something external like Active Directory if you like.