The question of whether managed Android devices are prone to malware is due to the flexible use of Android. And I see that as something fundamentally positive. As a user, you don't have any hard barriers, but can sometimes override security features and look for other sources for apps, for example.
As a user, however, you should be aware of the risks. And even more importantly: as a company, you should set strict barriers to avoid common risks.
We regularly check whether we need to adjust our MDM policies for device security.
Google Play Protect, prevented sideloading and forbidden USB debugging already help enormously with device security.
However, accessibility services should not be underestimated. A few years ago, we created an accessibility whitelist to provide additional protection. 😀
This is because a sideloaded PHA-app that uses accessibility services can cause enormous damage to users and their data.