@Eduards
Thank you for posting in Microsoft Q&A forum.
In client setting, try to set the Disable alternate sources (such as Microsoft Windows Update, Microsoft Windows Server Update Services, or UNC shares) for the initial definition update on client computers option to False.
After you change this setting, the clients can download and install antimalware definition file updates immediately after installation as long as the client has access to one of the sources that hosts the files.
For reference:
https://learn.microsoft.com/en-us/troubleshoot/mem/configmgr/antimalware-definition-files-not-updated
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.