@All,
with the help of the Sophos-Support we solved the issue, at least know where the problem is. In our MDM exist more then one Enrollment-Groups linked to Active-Directory-Groups. The Default-Enrollment-Group is not active.
Here is the clue: if…