Hello Jesse,
Question 1)
In your article you mention: Note: Defining a security intelligence location only works https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/deployment-vdi-windows-defender-antivirus#set-up-a-dedicated-vdi-file-share.
If I follow the link, the article begins with: In Windows 10, version 1903, we introduced the shared security intelligence feature.
So little confusion here is it from 1703 or 1903. I configured it here with 1809 and it seems to work.
Question 2)
I also have an other question. If the fileshare isn't available the VDI clients will boot without definitions.
Is it possible to start with a local definition set (build in the masterimage, this image is mostly build once in a month with new security patches.)
So the image have at least a defnition set to start (of course it get outdated) and as soon as it start it trggers a update and update to the newest definiton set. In case the DFS/Fileshare is not available there is at least an definiton set loaded, there is some protection?
question 3)
We did some testing and see that immediatly after placing a new definition set on the file share als VDI client get updated in a few minutes
How do the clients know so fast that a new definition set is placed on the wdv-update share?
regards
Bert