When I am on a client machine, how can I tell which of the policies are applied by the Domain Controller, which are local GPOs and which are coming from the WS1 baselines?
So I am not familiar with your use case but their is some general guidance in this tutorial. It should be able to answer all of your questions and concerns.
You can see how to validate what policies are on the device. The MDM diagnostic will tell you more around what’s MDM policy and what’s GPOs.
It’s generally not advised to use all of these different options together at the same time.