When enrolling a device, the device requests and receives a cert from SM. This is used to authenticate the device for ongoing management. You CAN'T use the cert store without the device being encrypted
Secondly, putting a PIN on the device will also encrypt the device
Expected behavior and you really should be encrypting devices anyway 🙂