The firewall will work in two modes -- managed and unmanaged. Under the managed mode, corporate IT will have the ability to specify what applications may open ports -- when a user runs afoul of the policy the Windows Firewall will furnish the user with a simple notice that the application isn't allowed to open ports. In the unmanaged mode for home users and similar environments, the user will have the option of allowing the application to open the requested port.
Nice. Not being able to use WMI on firewalled machines has been a less-than-ideal solution.