For anyone that is using an on-prem RMM the IP(s) in use for the system will be known. Being able to create per-RMM destination IP allow/block rules would catch malicious usage even if it was an otherwise allowed RMM with a valid signing cert in an allowed install location.