The short story is that you can only have computer accounts with AD in place, as these accounts are created in/by AD.
If your goal is to Onboard devices that can be used by multiple Windows users (local accounts ;-), you can configure in the Network Settings that the credentials should be stored in the machine account of your client:
That will allow multiple users to use the same computer. The Onboard certificate (identity of the requester) will be bound to the computer instead of the account on the computer.
Please note that for pushing certs in the Machine account, you will need local administrator privileges.
And you still need to re-onboard all your devices, which might be automated by creating a new CA, check if the cert is from the old CA and redirect in that case to the onboarding page where you Onboard with a certificate from the new CA.