Question: I've always assumed that if a workstation has been shut down, that when it's restarted, it will query the SEP managmement server for A/V definition updates. Is this true?
Ans: Yes it is true by default SEP clients configured to get the liveupdate through the SEPM server as a primary source.
Question: What if the LU policy says that the Retry Windows is X hours and it's been more than that since the workstation was turned off? .
Ans: IF the workstations are turned off for couple of days it wont run the liveupdate to connect internet when it starts. And it cannot retry after x hours if configuration is only to get the update from SEPM server.
If the secondary source is enabled that means your LU configuration for clients is enabled to update using Symantec LU server as well.
Then also the clients will reach out the SEPM server as it is the primary source in case if the clients unable to reachout the SEPM server then only it will try to reach out the internet to receive their updates. tat time it will connect to the symantec LU server. even if the client cannot connect LU server it will use the scenario Retry LU after X hours.
Hope this helps.....