Ever since Windows 10 came out and I used to remove Defender, about 3 months later a MS update would not apply due to "missing components", that is the only reason I don't nuke Defender (or anything) anymore. I disable Services and leave them part of the OS, because I've not had a problem with things being disabled, only when they are removed. So keep this in mind if your making a Lite OS, sometimes things don't go as you expect with Microsoft, for the sake of less than 100mb, I'd rather know that if it goes pear shaped I can re-enable whatever I disabled, I tried to make a way to restore Defender back into the OS after I stripped it out, but then the protected files and keys were either blocking me or causing errors when not able to set them as such.
UUP Dump allows you to make a ISO without Defender ever being included, but as I said, a bad idea. I once made a OS without the Security stuff etc, got it under 2GB as a .esd, but wouldn't update. UUP Dump is the best way to make a lite OS as it allows removing components from the Building ISO before they are ever added.