Hi PhiipDath,
thanks a lot for your replies.
Sure enough, it was a matter of recreating the certificate with the intended Apple ID it@myschool.appleid.com (which i did just in case), nuking the MDM server from the ASM (so the MDM server list in ASM was empty). Since I was deleting the server, ASM prompted me whether I wanted to unassign the devices. Confirmed the "Unassigned and delete" button so the MDM server was gone. Then I redid the certificate-token process so that both ASM and MDM/DEP knew each other.
After this, when I requested activation locks the Apple ID was the IT Team's one, instead of my "personal" one, which is the intended effect.
With your message I was a little bit more confident I was doing the correct steps (i guessed I had to redo the process but now i KNOW it), so thank you for taking the time to do that.
Cheers.