I partly solved. First thing is, that you should not use User-based MFA in Entra for users who are attempting to log in to macos.
Second discovery is, that the m365 user who enrolls macos in Company Portal, later cannot login in his own desktop. So, for that, the workaround is to enroll macos with using User A account, but real use will be then performed with User B account. That being said, a user who enrolls macos with CP, cannot login to desktop, other m365 users can.