Use the software restriction policies of your Windows Pro. Apply them except admins so you can still install eveything using right click "run as admin".
It would be interesting to tweak/harden Windows Defender default settings with 3rd party tools as HardConfigurator (@Andy Ful) or SysHardener (@NoVirusThanks), thanks for sharing