Try as they might, no antivirus can block EVERY intrusion attempt and running too many active antivirus scanners in the background bogs the system down way too much. Like Sharpuser said, Windows Defender does a really good job of this so I don't see a point in running two active antivirus applications in the background. I have found in the past, however, that Windows Defender misses an infection, but when I run Malwarebytes and find/remove the infection, Windows Defender pulls a "..I found a virus and am cleaning it now" after Malwarebytes detects the infection.
Regarding windows updates, on my Surface Pro and Surface 3, I let them handle updates on their own since the devices usually automatically update themselves on a regular basis. I stopped forcing the updates on my Surface devices because Microsoft announced that sometimes when you force windows updates, you download beta updates that haven't been fully tested and can cause issues with your machine. On my laptop, I will run updates manually just because it's not always checking for updates on its own and gets powered off often.
So for my Surface Pro 6, I try to make sure the battery has enough of a charge that if I put it to sleep on the table or in its case, it has enough power to periodically check for updates and install them on its own without running out of power and not being able to install the updates as a result.