There is currently no way to enforce Windows Defender policies on an org level. Each and every machine has to be set to enforced manually.
Please add the ability to enforce an org and all machines added to that org will auto enforce.