and of course, your regular reminder from someone who worked at a major MDM developer:
DO NOT USE YOUR PERSONAL PHONE FOR WORK. EVER.
DO NOT INSTALL 'WORK' APPLICATIONS ON YOUR PERSONAL PHONE. EVER. (With exceptions for 2FA/token generators that need no permissions ONLY.)
If they want you to have a 'work device,' then they have to provide it. If they refuse to provide it, then they're going to have to live with what they get.
Not negotiable.