The standard profile overrides the user.role.anonymous configuration. This is now used when the profile is installed. In prior versions of Drupal this would magically replace the user.role.anonymous provided by the user module. However this approach means that profile overrides that add dependencies to user.role.anonymous will break an install as no module can be installed before the User module.
One impact of this change is that configuration provided by the profile needs to reflect the final state you want the configuration to be. In Drupal 8.7 modules that were installed after the User module could change the user.role.anonymous configuration in their install hooks and these changes would survive profile install. In 8.8.x this is not the case.
The following command might be a useful starting point when comparing the default configuration and the installed versions: diff -ruw path-to-profile/config/install/ path-to-config-sync/ | grep -v ^Only. Note that it will also report expected changes like UUID. Alternatively, copy all files that are provided by the install profile back and then review the changes like that: for file in `ls path-to-install-profile/config/install/`; do awk '!/^uuid:/' path-to-config-sync/$file > path-to-install-profile/config/install/$file; done.