The Policy on the client has the Windows Integration Setting on its Firewall Policy. But even after the heartbeat it does not disable Windows Firewall. Just trying to figure out why that would be.
And the policy on the client matches what's showing in SEPM?
If nothing has changed on the SEP end, it will be tough to say from my perspective. Since you can re-produce this, I'd suggest collecting data and getting it over to support: