When a firewall which is acquired on NSM is modified locally, that is, by directly logging into the firewall, the firewall goes out of sync on NSM.
In order to fix the out of sync issue on NSM for the firewall, we need to Synchronize it on NSM in the following way:
Whenever there is a need to change the firewall configuration locally, we need to synchronize the firewall on NSM in order for it to sync up with the latest configuration of the firewall.
NOTE: It is not advisable to make changes locally once it is acquired on NSM. If NSM is not able to decrypt the heartbeat syslog messages sent by the firewall, it will not be able to show if the device is out of sync ever.
Here is the KB link which explains how NSM decides if a Firewall is in Managed or Out of sync whenever a change is locally applied: