I feel your ‘pain’ with SCCM. Its not mean to provision servers or worry about state. Else it would go head to head vs puppet or chef and it isnt.
Seems were back to my initial reply to your question at the top of this thread.
Any chance you uninstall the agent, restart and try and ask your Security team to exclude that node for the day of testing or use a server that hasnt gone through your normal hardning procedures ?