@Mohammed Siyam (DevOn)
Thank you for your post!
When it comes to Azure Security Center, it uses Azure role-based access control (Azure RBAC), which provides built-in roles that can be assigned to users, groups, and services in Azure. In order to modify Security Policies or gain access to Azure Defender, the user will need to be a Security Admin, Owner, or Contributor of that subscription.
Since Azure Security Center is controlled via RBAC role assignments, you can block users from turning off Azure Defender by making sure they aren't assigned roles they don't need at the Subscription level.
How do permissions work in Azure Security Center?
If you have any other questions, please let me know.
Thank you for your time and patience throughout this issue.
----------
Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.