It's somewhat different than doing it through policy.
If you disable a feature (Like Anti-Malware) through policy the inspection does stop, but the service itself is still running, albeit at "idle".
If you use an E86.40 or newer client and use the "Edit Capabilities" option with the new interface, the service itself will be stopped entirely.
I myself keep a "DISABLE BLADE" policy at the top of my rulesets with an empty virtual group as placeholder. That way I can disable blades when troubleshooting without much hassle.
But this built-in capability of the client makes that even easier, though it's unlikely that we'll be moving straight to E86.40 & newer just because of this.
Current recommended version is still quite good.