Because defender will not spot that you have an outdated copy of the Struts library in your Apache installation, or that a adobe reader install has a known vulnerability etc. The attack surface is *way* bigger than just the OS. It does not matter how well the OS is patched, if an outdated web browser gives an attacker shell access via a compromised web page or malicious spreadsheet.