How is that keeping Microsoft from accessing your GPS, sensor data, wifi, camera/microphone etc? Sure, they can't get at SMS or your other apps and your work won't have access to your entire device but it means MS can still access your location (using GPS and nearby bluetooth/wifi), record audio/video, read/control sensors (accelerometer, proximity, gravity, temperature, pressure, magnetic field etc), have full network access, etc and can record and collect that data whenever they feel like it for the most part.
That's true with a separate work phone too right? And once I turn off the AWP for the day, all of that stops.
A work phone I could leave in a lead lined box until I needed to log into the company network. My personal device is often carried with me and in use at other times. If your IT people let you pause your work profile indefinitely that could help protect you though.
There's different kinds of intune enrollment. Generally if it's not a company phone, they can only see your IMEI, last 4 of your phone number, OS version etc. They'll be able to isolate and control the work apps but nothing else because it's in a separate profile.