Classify your user group and determine the required access level for them.
The Endpoint Security Common policy provides:
Full access — Allows the managed system user to view or change all feature settings using the local system password credentials. You can provide Full access to users for whom you don't want to restrict any action.
Tip
If the managed system user changes the protection settings locally, the subsequent policy enforcement overrides the changes.