Azure Desired State Configuration policy service has the ability to manage GPO and Firewall settings.
The setting in DCS below was over-riding any of the GPO settings which had been set to allow the application of local firewall rules:
9.3.5 (L1) Ensure 'Windows Firewall: Public: Settings: Apply local firewall rules' is set to 'No' (Automated)