It is possible that the device's hardware ID has somehow been associated with an organization through Windows Autopilot. (This "brand new" unit was very likely enrolled in someone's Autopilot/Intune tenant before you got it -open box, returned, or demo stock mislabeled as new).
Windows Autopilot enrollment tied to the device's hardware hash, not anything on the local drive. Autopilot profiles live in the cloud against the device's serial number/hardware ID, so wiping or reimaging the SSD does nothing to remove it — the moment Windows connects to the internet, it looks up that hardware ID, finds it's registered to an organization, and forces the "work or school account" flow, then hangs while trying to apply that organization's policies (which you don't have access to).
At the 'Please wait' screen or the account prompt, press Shift+F10 to open Command Prompt, then run: dsregcmd /status. Look for 'AzureAdJoined: YES' or references to an enrollment/MDM URL tied to a company name you don't recognize. That confirms the hardware hash is registered to someone else's tenant.
On the 'Let's connect you to a network' screen, press Shift+F10 and type: OOBE\BYPASSNRO then hit Enter. The machine reboots and gives you an option to continue with limited setup. This sometimes lets you get into a local account and bypass the forced work-account flow entirely, since Autopilot enrollment usually triggers only when the device is online during OOBE.
Because the lock lives on Microsoft's servers against the hardware ID, Best Buy generally cannot remove it themselves — only the organization that registered it can deregister it from Autopilot.
Your fastest real fix is an exchange for a different unit, especially if you're within the return window. Mention explicitly that it's hitting a forced 'work or school account' / Autopilot enrollment screen — that phrase will get you routed faster internally.