I really appreciate your comment, I'm hoping I am wrong about my experiences!
But, this is the issue I believe:
https://mjtsai.com/blog/2023/09/15/limitations-on-macos-virt...
(or, the original is here: https://eclecticlight.co/2023/12/26/when-macos-wont-work-wit...)
You cannot login using AppleID. If you can't do that, aren't you prevented from basically doing any kind of stapling and/or retrieving certificates for signing?
I would LOVE to be wrong about this. You've done that?