Ensuring devices meet organizational security and compliance policies
A bit late to the conversation sorry. I had this issue on one of our compliance policies. We have ours setup into an immediate and a 24hr delay.
Immediate
and 24hrs
At first the firewall had this syncml issue however we also had bitlocker failed to encypt. Once the bitlocker was encrypted for silent encryption (i missed some components for it) (https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows#configure-silent-bitlocker-encryption), it then encrypted, did a Check Access in CP, rebooted, did another sync and the Immediate was working. The FW was then resolved by doing another sync in CP, restarting. To help I was using the event logs in Apps and services > MS > windows > deviceMGMT-Ent and looking there for the warning 2750 for (WSC_security_provider_firewall). After the last sync locally, the event logs no longer showed the 2750, i redid a check access in CP and it then synced back to Intune.
TLDR: I suspect FW was being prevented from working due to bitlocker not encypting.... No idea why though.