It actually does run locally with access to API's that you authorize. Just saying...
You can't firewall it off, but you can learn how it actually works and just turn it off.
For now. This crap is going to get a lot harder to avoid when the Intel SGX instructions are widely deployed and it becomes possible to extend the lockdown from SecureBoot to the kernel and kernel-authorized apps.
I suggest fighting it now, while it is still just an annoyance.