GinaKomoroske - I believe you have conflicting GPO settings - one that tells it to gets it updates from online, and another that says to get them locally. I use WSUS for controlled update releases to rings, together with a file share (on the WSUS server) to supply definition updates hourly to endpoints, and ran into a similar issue a month ago with 2012 R2. Server 2016 onwards does not have this problem for some reason.
Computer Configuration - Policies - Administrative Templates - Windows Components - Microsoft Defender Antivirus - Security Intelligence Updates
Allow security intelligence updates from Microsoft Update = Disabled
If you disable this setting, security updates will be downloaded from the configured download source
Define the file shares for downloading security intelligence updates = \\windowsupdate.mycompany.com\DefinitionUpdates$
(ensure either 'Domain Computers' or 'Authenticated Users' has read access to the files and to the share)
Define the order of sources for downloading security intelligence updates = FileShares|MicrosoftUpdateServer|MMPC