How to create Device Enrollment Policy based on Serial Nubmer

I want to create a Device Enrollment Policy, so that only specific devices can even enroll/login to our Zero Trust Team. I am not talking about Application Access

I’ve created a List in My Team ->Lists of Serial Numbers.

Now when I Require this Device Posture in the Device Enrollment Policy, and try to login to a WARP Client from a Device with a valid Serial Number, it still shows 403 Forbidden.

How can I get this to work?