Lawful interception requires things like paperwork, warrants, probably cause, and some kind of reason why you need to tap cellular comms in the first place. If you're operating a deportation agency in the style of roaming gangs of officers, you're probably not going to want to wait for the courts to dismiss your brute-force attempts to find illegals behind every door you break down.
The anti-2G security measure is pretty much exclusive to a few high-end phones as far as I can tell. iPhones can enable it with lockdown mode (which also disables things like JIT and can make websites and app run slower), Google has added a toggle, and I think a few other manufacturers have it too, but you need support in the modem firmware to actually do anything with it.
Even then, 3G and 4G can also leak identifiers if you can fake being a base station. The identifiers are not as easy to obtain as on 2G, but there's a reason 5G added a masking feature to LTE. Especially combined with access to an SS7 capable line, you can pretty much replicate all of the 2G hacks with cellular tech at least up to 4G, maybe even newer than that.
Cellular firmware protection mechanisms seem to be targeting 2G exploitation so far. It'd be extremely unpractical (and probably impossible) to enforce some kind of "5G NR only" mode, but without such a mode you're going to be at risk of Stingray-like devices.