Totally removing defender as TI is the only option if you dont want it turning itself back on arbitrarily. I went through this hell yesterday for about 3 hours.
> It was working like that before, but on latest updates it automatically turns on every restart (or so).
that's if you disable through the normal settings interface. the group policy settings stick, although you might have to turn off "tamper protection" first before applying the group policy.
I disabled it via group policy 2 years ago and just checked, still disabled.