Are the endpoints in question updated with the AV fix (ie: their AV products have updated to allow the “QualityCompat” field to be set? If it doesn’t have any AV running we have a fixlet to set the registry entry.
Also are these AMD endpoints? We changed the relevance last night to only block the AMD specified problem processors with the patch ( see https://www.amd.com/en/corporate/speculative-execution ) so you would have have to have gathered that to clear the complete block on AMD processors.
Additionally there are 4 fixlets that cover KB4056891 so make sure you are looking at all of them as it depends on if you have caught up or not to the other Jan patch stream.
Defender should have placed the value there when it updated. Its possible that Defender was the item holding you up as it had to be updated to place the Compat flag in the registry.