
Explore Microsoft Defender for endpoint, a security solution formerly Defender ATP, delivering prevention, detection, investigation, and response across Windows, iOS, Android, Linux, and Mac endpoints.
Access the Microsoft Defender for Endpoint portal to review OS support, network requirements, and license needs, and explore Intune integration and advanced features for Linux, Android, iOS, and Mac.
Explore role based access control for Microsoft Defender for Endpoint by mapping Azure roles to device groups, granting read or full access, and applying least privilege for governance.
Implement role-based access control in Microsoft Defender for Endpoint by creating Azure AD groups, assigning roles, and mapping to device groups to restrict device visibility.
Learn to implement rbac by creating and mapping groups, assigning a custom group role, and linking devices to a device group so only group members access endpoints and dashboards.
Onboard Windows 10 to Microsoft Defender for Endpoint with the local script, download the onboarding package, and run the script with administrator rights.
Onboard Windows Server 2019 to Microsoft Defender for Endpoint using a local script. Ensure Windows Defender Antivirus is installed and enabled, then verify registry steps and onboard via the script.
onboard Windows Server 2016 to Microsoft Defender for Endpoint using a local script, with installation and onboarding packages that enable antivirus and EDR.
Explore threat and vulnerability management in Microsoft Defender for Endpoint, including vulnerability classification with CVSS scoring, exposure scores, and guided remediation using device inventory, recommendations, and role-based access control.
Explore the dashboard in Microsoft Defender for Endpoint to monitor threat and vulnerability management, view exposure scores, and track security recommendations, remediation actions, and top vulnerable software.
Learn how threat and vulnerability management uses software inventory from onboarded endpoints to map installed software, common platform enumeration standards, and vulnerabilities, with navigation of the inventory view and recommendations.
Learn how Microsoft Defender for Endpoint's weakness and vulnerability management aggregates telemetry, analyzes device and software vulnerabilities, and delivers actionable recommendations and email alerts.
Explore how security recommendations from Microsoft Defender for Endpoint trigger remediation actions and exceptions within threat and vulnerability management, using telemetry from onboarded devices to address weaknesses and CVEs.
Enable attack surface reduction rules in Microsoft Defender for Endpoint to block malicious activity. Understand the attack surface, ESR deployment, and how to configure rules via the security portal.
Learn how to deploy attack surface reduction rules across endpoints using Intune, MDM (CSP), SCCM, and group policies, with testing via PowerShell and remediation guidance.
Explore attack surface reduction rules, blocking exploited signed drivers and creating child process blocks for Adobe Reader and Office apps, with deployment via Intune and PowerShell and advanced hunting.
Explore Microsoft Defender for Endpoint attack surface reduction rules, including blocking obfuscated scripts, downloaded JavaScript content, Office macros, WMI persistence, unsigned USB drives, and ransomware protection.
Enable attack surface reduction rules on endpoints onboarded to Microsoft Defender for Endpoint using PowerShell, switch between audit and block modes, and test with sample files.
Enable attack surface reduction rules with group policy in Microsoft Defender for Endpoint, test via audit and block modes, and review reporting and testing results in the Defender portal.
Learn to test and observe attack surface reduction rules in Microsoft Defender for Endpoint, generate reports, and perform advanced hunting with queries to detect blocked and audited activities.
Course Overview:
In today's evolving threat landscape, organizations require robust endpoint security solutions to protect their critical assets. This comprehensive course dives deep into the world of Microsoft Defender for Endpoint, empowering participants with the knowledge and skills to effectively safeguard their endpoints from advanced cyber threats.
Course Description:
The "Mastering Endpoint Security" course is designed to provide IT professionals, security analysts, and decision-makers with the expertise needed to harness the full potential of Microsoft Defender for Endpoint. Participants will gain a solid understanding of the solution's capabilities, enabling them to detect, investigate, and respond to sophisticated threats targeting their endpoints.
Through a combination of Hands-on exercises, and real-world examples, participants will explore essential topics such as endpoint threat protection, endpoint detection and response (EDR), advanced threat analytics, and operationalizing Microsoft Defender for Endpoint within their organization's security framework.
Participants will gain a deep understanding of Microsoft Defender for Endpoint, a powerful security solution that provides advanced threat protection, detection, and response capabilities.
By the end of this course, participants will possess the knowledge and confidence to effectively utilize Microsoft Defender for Endpoint as a key component of their organization's endpoint security strategy. Join us on this immersive learning journey and emerge as a proficient defender of endpoints in the ever-changing landscape of cybersecurity.