What is the benefit for allowing access even when your up to date and correctly configured? This is important, if there is the rare chance that it could be a vulnerability, is that not worth blocking access?
Its best to not allow the phpinfo() function to be used by anyone, letting users view the results is a different situation to discuss. I cant comment because I just signed up.