Thanks for following up, I'm glad it's working in at least some form. As far as I know Windows Defender doesn't use any ML for virus detection, it relies on signature database files the way most AV programs have for years. But the UI around when it has and hasn't flagged something has always been a bit opaque and not predictable from system to system.
(For anyone else coming across this comment, I didn't end up doing the official 9.18 release then obviously. Still gotta work out some stuff with the mac build.)