SEP Hidden Firewall Rule
There appears to be a hidden firewall rule to always allow the SEP client to heartbeat to the SEPM.
i.e. Even with a firewall rule that blocks all traffic as priority 1, a client is still able to heartbeat.
Does anyone have any documentation on this rule? As far as I can tell, this is locked to the smc.exe process, but are there any other conditions/triggers on it (filehash/directory/port/service/remote host/etc)?
<EDIT> Referenceable documentation is what I'm after, for purposes of design rationale </EDIT>