Just an update.
I grabbed the latest fogservice client 0.12.0 off github. Set defender to remove quarantines over the next day with a GPO and added it to the exclusion list. Wrote a shutdown script to reinstall the MSI if the fogservice is missing.
Wrote a conspiracy rant to my team about MS having hurt feelings because we don’t use intune or SCCM. Thousands of different apps and the one app they false flag on us JUST HAPPENS TO BE part of our imaging system. Yeah, ok, MS, sure mm hmm… yep.