If this is deployed within a customer's environment, you are unable to hide it, as they are essential resources sitting within the customer's Azure boundary.
You can force customers to only have read, but you can't remove that right.
"For example, the publisher can specify that customers can restart virtual machines. All other actions beyond read actions are still denied. Changes to resources in a managed resource group by a customer with granted actions are subject to the Azure Policy assignments within the customer's tenant scoped to include the managed resource group."