I finally got this resolved. Turns out the firewall rules were corrupted. I deleted the old rules and ran the following command.
netsh advfirewall firewall add rule name="Windows Remote Management (HTTP-In)" dir=in action=allow service=any enable=yes profile=any localport=5985 protocol=tcp
From <https://support.logbinder.com/SuperchargerKB/50218/WinRM-says-Unable-to-check-the-status-of-the-firewall>
The only change I can think of is we moved from 2008R2 forest functional level to 2012R2.