Windows Defender 2019 - Configuring

I've been tasked with getting Windows Defender configured to get it's updates via MECM. Some context, we have around 40 servers in our Azure tenant running Windows Server 2019, Defender is enabled, and it's currently getting its definition updates from an M$ source (I assume) We have an on-premise MECM/SCCM infrastructure, and currently, the Windows10 fleet defender updates is managed via SCCM/MECM; we setup at DP in Azure and all necessary network/firewall rules in place and we are now patching these Azure servers using SCCM without any issues; what do I need to do to get these Azure servers to point to SCCM to get it's windows definitions updates,


