Ok, spoke with Engineering. Here are the specifics to your questions.
At present, this is a core limitation of Plesk. Our own extensions (Amazon Route53 and Slave DNS) are Linux-only as well. The engineering team is planning an SDK extension which will enable such scenario in Plesk 12.1
Until...
Ok. Thanks for the additional info. The WordPress toolkit will not change all file permissions of every file in a WordPress distribution, but it should cover the ones that would be compromised in the event that a WordPress install is attacked. I'll connect you with an engineer to dig deeper and...
What edition of Plesk 12 are you using? Or is it an upgrade from Plesk 11?
Also, are you using the WordPress Toolkit to harden the WordPress installations which applies all of the security settings you mentioned in your post?