There seems to be a hint here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
We can only access certificates that were installed together with the VPN profile.
It can either be a configuration profile, including both the certificate and a Capsule Connect VPN profile that uses this certificate, which is then sent to the device and installed locally, or be pushed from MDM with a Capsule Connect VPN profile referencing the certificate. This way, the certificate is stored in a special keychain that we can access.
My guess is some integration is needed between Intune and the Apple Volume Purchase Plan (which I think is also like an MDM).