CIS 12.3.4.8162.
If using an environment variable and selecting Ask in a firewall rule, the traffic will be allowed without a pop-up asking for the user action.
Replacing the environment variable with the actual path resolves the problem.