LSC and MIC are two different things. The former is issued by CAPF while the latter is burned in at the factory. If you have mixed mode enabled with TFTP encryption that would explain why the config file is incomplete; the unencrypted portion of it is just a stub file with the bare minimum info. Please mention that you are running mixed mode with CAPF on future posts; very few customers use that feature.
I'd seriously consider RMAing the phones if they do not have MIC. That's a serious miss, if that is what actually happened. It seems more likely that their MIC was issued by a newer CA that is missing from your CAPF-trust store. They won't be able to get their LSC without a MIC unless you use an auth string (difficult to scale, but safe if handled out of band properly) or null string (super insecure).