When using proxy mode, you can see the checkbox for HTTPS decryption is unchecked.
When using DPI mode, the HTTPS inspection is controlled by the rules in the SSL/TLS inspection rules tab.
I don't know what safetynet uses, but can you temporarily disable all scanning rules (or put in a high level Do Not Decrypt rule in) and try again.
I just want to make sure you are doing an apples-to-apples comparison.