The issue is if the update is installed automatically in the background then it would no longer be possible to restart without the update and this is what it does it installs as much as it can before wanting a restart ;)
I'd recommend that you go into Networking and choose your network connection then simply toggle on metered connection (even when not on a metered connection, you can simply toggle it on but don't touch the limits and its fine).
Windows Update would then not automatically download nor automatically install updates as it has a setting to not download on metered connection if you can understand what I'm saying lol. Test that with your work use there. Then you can manually install updates when you want (which includes the AntiVirus stuff so you will want to get used to doing that manually).
That would solve your problems here in a nice way and it will be the only nice way you will find.