When installing Defender it installs software locally, updates the AD schema, creates AD Defender objects and creates service connection points (SCP).
Schema Update
As with any AD schema update they cannot be safely removed.
Software (Desktop Login, Defender Security Server, Management Portal)
You can delete all the software through the standard uninstall option in Programs and Features
AD Defender Objects
From ADUC all the Defender objects (Defender License, Defender Access Node, Defender Policy etc) can all be deleted. They are by default created in the "Defender" OU. This whole OU can be removed.
Management Portal SCP
If the Management Portal was installed, a Quest.Defender.LogReceiver SCP container will have been created in Active Directory on the AD Computer objects that had the Management Portal software installed.
To confirm these have been deleted use Active Directory Users and Computers. Ensure that in View "Users, Contacts, Groups, and Computers as containers" & "Advanced Features" are both ticked. Then go into the Computers objects, any Quest.Defender.LogReceiver objects within can be deleted.