A protection group allows you to use a specified machine to deploy an agent to a target which is perfect from link load and firewalled system point of view but it seems the host/scan processing is still done through the server component in a direct manner. We have a bit of a paradox here.
Should It Be Considered as a Bug or left behind process that would be fixed soon