I strongly dislike antivirus software. In my opinion, the av software behaves much like a virus. The recent Symantec incident of actually causing server crashes, resource use, software interference, and user safety bias are each very problematic.
If I have locked down servers behind a firewall, with admins following security protocol (no surfing, no downloads, etc.). What benefit would I have from installing antivirus software on these machines? I must install something for insurance purposes...
When i researched AV products a few years ago, the coverage was 95% at best - and these are of known security issues. That means that the best AV protection is vulnerable to thousands of known viruses and worms.
Every single infection I have encountered has been on a machine with AV software on it. The user always says - but I have antivirus software...
Can anyone provide metrics on the utility of av software on servers that will make me feel better about having to do it?
Plenty of data provided by the companies selling their anti virus software.
Best practices and regulatory practices in certain industries require its installation. For example, the PCI DSS requires it.
If you have a workstation that gets compromised by a self propagating worm, it's likely that any Windows servers on the same subnet will be compromised as well. Unless the servers are storing restricted data, the only risk is to availability.
If you are able to justify the potential risk, go for it. I believe the argument you provide is technically legitimate. You also risk the perception of those who can influence your success within your career, as most people believe it to be absolutely necessary for Windows.
Of course, if you want to make this risk, you should enforce certain practices including but not limited to:
Ultimately, good anti virus software will potentially reduce the technical risk. However, it's unlikely to be much if you have good security policies. Usually the most risk will be introduced with unrestricted users who are not very technical.
Servers on more restricted subnets with specialized purpose and software will often not have anti virus software installed. At one point, it was recommended not to install on certain server roles. I believe this is less common these days.