Windows users who are members of the Standard users group are able to click on "Configure Settings" for Web and Cloud Access Protection ( formerly Network Traffic Redirection) feature.
Release : 14.3 RU 1, 14.3 RU 1 MP 1, 14.3 RU 2
This is working as designed.
This also allows the end user to disable it (so that they are still able to access websites, perform windows updates, etc.). while SEP/WSS is first being deployed. Once it all works the way they want it, the admin locks the policy and takes away the ability for user to bypass WSS.
SEP Product management made a decision to allow limited users to make changes if needed when customer first rollout WSS so that an end user can work with their internal IT/WSS team to fix WSS policies, etc.
This is also aligns with how our stand alone WSS agent works.