@Arunchandar N This would be using Automox or Intune to push a script that modifies the permissions of the amagent service to only SYSTEM account, removing the Administrator from having any permissions to change the state of the service. Think of it as a mitigating technique.
Alternatively. since your using Intune, use remediation scripts to run frequently that just put it back into the desired state.
I’m personally not worried about tamper protection myself as I’m extreme focused on overall health of Automox against the inventory of assets (analyzing metadata from every security/infrastructure tool as to what is a live asset) and then asking the data to tell me is Automox installed and scanning as expected. Any deviation from that expectation and a ticket is opened to allow triage against the problem agent.