It ended up being a bug in our MDM's profile editor. Creating the profile outside the MDM, sending it to devices, and never touching it in the profile editor allowed the settings to apply. Not quite sure what was happening, but it wasn't the device's fault.