Are you just looking for a working base for Defender settings/exclusions? My environment isn't like for like with what you describe, but may be close enough (W10 20H2 single session, FSL, WEM, Teams). If it is, here's a report of my Defender GPO settings (minus the onboarding stuff).