@Yevhen Thank you for reaching out to us, above mentioned ask ( Defender Enforcement Scope API ) - Defender Portal ==> Settings ==> Endpoints ==> Configuration Management ==> Enforcement Scope
Enable: "Use MDE to enforce security configuration settings from Intune"
Check Windows Server Devices
Set to "On tagged devices"
Its not possible to automate this setting via API.
Let me know if you have any further questions, feel free to post back.