I have found
sudo profiles renew -type enrollment
To be very hit and miss. The only things you can check is:
1. The device is assigned an MDM server in ADE
2. The device is assigned a network and ADE profile, that's valid, in SM
Lastly, it's very picky with demanding that the command be run in the same user account that enrolled the device.