I got halfway, and then gave up as we, at the time, didn't have an MDM, nor do I ever want to touch new devices before the user logs in the first time. Now we have Mosyle, and just ponied up the cash for oneK12-version, so we can look into using their own Mosyle Auth 2, which will let users log into their Macs with their Workspace credentials.
An alternative I have been looking into a little is Xcreds. Cheap and can be free if you compile it yourself.
--
https://wheretofind.me/@NoSubstitute