Clients connect to the WSUS server to check for applicable updates and then request the latest approved definition updates.
In addition to manual approval, you can also set an automatic approval rule for definition updates and Endpoint Protection updates.
To update antimalware definitions, you can use one or more of the following methods: You can configure multiple definition update sources and control the order in which they are assessed and applied.
This is done in the Configure Definition Update Sources dialog box when you create an antimalware policy.
For more information about the Create Automatic Deployment Rule Wizard, see Operations and Maintenance for Software Updates in Configuration Manager.You can configure clients to download definition updates from the Microsoft Malware Protection Center.This option is used by Endpoint Protection clients to download definition updates if they have not been able to download updates from another source.Use the following procedures to configure WSUS as a definition update source.Endpoint Protection definition updates must be approved and downloaded to the WSUS server before they are offered to clients that request the list of available updates.
To accomplish this task, you can configure automatic approval for revisions and automatic declining of expired updates.