You can use a Configuration Profile to disable Users and Groups, but Configuration Profile would not do anything like blocking a command from running unless apple made a domain to manage that function like they do with FileVault.
What you are wanting is something Jamf Protect can do or pretty much any other EDR tool like CyberArk, Carbon Black or Sentinel One. However, this is not something a Mobile Device Management platform like Jamf Pro can't do as this is a part of Apples Security Framework not the MDM Framework.
TL;DR: Use the right tool for the job or have a bad time, you need an EDR client and want to look at removing Admin access from users.
I believe you should be able to use Restricted Software for this. Just enter the process name in the Process Name field.
Be careful when restricting access to sysadminctl. This is a system binary that macOS may call for some operations. You might break some core functionality it or Jamf Pro needs.