There is no way (that I can see) to no have patching turned on in an agent config.
We have devices that need to be unmanaged and not get updates like the rest of the enterprise. I'd rather not have to 'just remember' what 20 PCs shouldn't get the patch pushes we do.