
Explore on-premise Active Directory domain services, RAS and DMZs, virtualization, and key concepts of Microsoft 365 and Azure, including IaaS, PaaS, and SaaS.
Explore the foundations of Active Directory domains, domain controllers, and centralization, covering Kerberos, LDAP, DNS, and GPOs, and the transition from on-premise to cloud with RAS, VPNs, and virtualization.
Discover how Microsoft renames portals and what to use for navigation, including IntraID replacing Azure AD and updated links like admin.microsoft.com, defender.microsoft.com, purview.microsoft.com, and Intune.microsoft.com, plus portals.examlabpractice.com.
Access the course assignments to run simulations, open links in a new tab, follow step-by-step prompts, and rely on video checks—not assignment checks—to earn your certificate.
Learn to create a free Microsoft 365 E5 account for hands-on cloud work, using examlabpractice.com steps, verify by phone, cancel after 30 days, and assign the Microsoft 365 E5 license.
Explore IntraID (formerly AzureAD) for IAM and device registration with single sign-on, plus Intune for MDM/MAM and compliance, protected by Defender for Endpoint under conditional access in a zero-trust model.
Configure Microsoft Entra ID to allow all users to join devices, then enable Microsoft Intune as the MDM and turn on automatic enrollment and Windows Information Protection.
Learn how to redo simulations after completing an assignment by going to summary, returning to the assignment, and opening instructions to access the simulation link anytime.
Defender for Cloud is a cloud-native security platform offering CSPM and CWP across multi-cloud and on-prem environments. It continuously assesses posture, detects threats, and guides centralized remediation.
Defender for Cloud acts as a security management layer, discovering devices via Azure Arc and Defender for Endpoint, with IntraID context, across cloud and on-prem environments, guided by policies.
Understand Defender for Cloud pricing by region and billing period. Learn CSPM free tier, paid features, per-resource plans for servers, containers, databases, storage, and commit units with the pricing calculator.
Explore the secure score in Microsoft Defender for Cloud to assess security posture, view recommendations, and improve the score by addressing the attack path and controls like disk encryption.
Learn to quickly set up a Windows Server virtual machine in Azure using the portal, configure basic settings (resource group, region, image, size), enable auto shutdown, and connect via RDP.
Verify that the Windows Server is onboarded to Defender for Cloud by checking the Azure portal: inventory shows the server and Defender for Servers is active under the security settings.
Azure Arc enables managing on-premises servers and other non-azure resources from the Azure portal, onboarding machines for centralized governance, policies, and Defender for Cloud across hybrid and multi-cloud.
Compare the free foundational CSPM with the paid Defender CSPM and note Defender for cloud's asset management, data exporting, cloud security benchmarks, and secure score across Azure, AWS, and Google.
Enable the full Defender for Cloud CSPM in the Azure portal to unlock features; note a $5 per month billable resource and activation delays (an hour, 24 hours for scans).
Now with full CSPM enabled, Microsoft Defender for Cloud shows risk factors and attack paths that explain how misconfigurations and exposure to the internet can lead to breach, guiding prioritization.
Learn to create a Microsoft 365 group to represent the SecOps security team, and compare security groups with Microsoft 365 groups, which provide shared mailbox, calendar, Teams, and OneNote.
Define endpoint security for desktops, laptops, smartphones, tablets, servers, and IoT devices, protecting against malware, unauthorized access, phishing, and data leaks with real-time monitoring and endpoint detection and response.
Explore Defender for Endpoint licensing options (P1 and P2) and how Microsoft 365 subscriptions (E3 or E5) determine access to features like endpoint protection, threat management, and automated remediation.
Enable Defender for Endpoint and Defender for Cloud to deliver layered protection from cloud resources to endpoints, with automatic server deployment, threat detection, and unified security signals.
Create a custom Defender admin role with read and manage permissions across security operations and posture, then assign it to a user for Microsoft Defender management under least-privilege principles.
Learn how devices are onboarded into Microsoft Defender for Endpoint from Defender for Cloud, including automatic onboarding, streamlined connectivity, deployment via local script or group policy, and verification.
Explore Defender for Endpoint's device overview, vulnerabilities, incidents, timeline, and security recommendations for NYC Server 1, and see how Defender for Cloud complements endpoint data to reduce the attack surface.
Create and configure an Azure storage account in the portal, selecting resource group, region, performance, redundancy, security settings, network access, data protection, and encryption options.
Enable Defender for Storage on a storage account, upgrade to the new Defender for Storage plan, configure upload malware scanning and sensitive data threat detection, and manage costs.
Upload a malware file to an Azure storage container to trigger Defender for Cloud malware scanning, view security alerts, and validate storage threat detection.
Understand relational databases store tables of rows and columns linked by relationships. Learn SQL with DDL and DML to define and manipulate data, with ACID rules and a transaction log.
Create an Azure SQL database on the platform option, configuring a resource group, database name, and server, with SQL authentication and the AdventureWorks sample.
Enable vulnerability assessment for Azure SQL databases through Microsoft Defender for Cloud, configure express mode, and monitor weekly scans and findings to identify security risks.
Manually investigate high-severity alerts in Defender for Cloud by examining a ransomware indicator on a sample VM, then remediate with guided steps, malware scans, and optional logic app automation.
Explore attack path analysis in microsoft defender for cloud, identifying an internet-exposed azure vm with high severity vulnerabilities, revealing the attack sequence and actionable remediation steps.
Investigate attacks, alerts, and incidents in Defender XDR. Prioritize high-severity alerts, analyze evidence from processes and command lines, and guide remediation and ownership through the incident workflow.
Automated investigation and remediation (AIR) analyzes endpoint alerts with AI to distinguish real threats from false positives and automatically remediate, including stopping processes and quarantining files across platforms.
Describe device groups in microsoft defender for endpoints, using rule-based conditions like device name, domain, tags, and operating systems to enable automated investigation and remediation with configurable remediation levels.
We really hope you'll agree, this training is way more than the average course on Udemy!
Have access to the following:
Training from an instructor of over 25+ years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course!
Understanding the Microsoft 365 and Azure Environment
A Solid Foundation of Active Directory Domains
A Solid Foundation of RAS, DMZ, and Virtualization
A Solid Foundation of the Microsoft Cloud Services
Portals renamed!
Using Assignments in the course
Questions for John Christopher
Certificate of Completion
Hands on setup videos for the course
Before beginning your account setup
Creating a trial Microsoft 365/Azure Account
Preparing Microsoft Entra for Device Management
Device management concepts in Microsoft's cloud services
Disable Security Defaults in Entra ID before proceeding
Setting up device management support in Microsoft Entra ID
Introduction to Microsoft Defender for Cloud
Introduction to Microsoft Defender for Cloud
How devices get managed by Defender for Cloud
Exploring the Microsoft Defender for Cloud dashboard
Understanding the cost of Microsoft Defender for Cloud Plans
Enabling plans for Microsoft Defender for Cloud
Using the Secure Score to monitor security posture
Monitoring Servers with Microsoft Defender for Cloud / Defender for Servers
What is Microsoft Defender for Servers?
Setting up a Windows Server virtual machine in Azure
Verifying the Windows Server virtual machine is seen by Defender for Cloud
Concepts of using Azure Arc to manage On-Premises servers
Using Defender for Cloud recommendations without full CSPM support
Cloud Security Posture Management (CSPM)
What is Cloud Security Posture Management (CSPM)?
Checking the features supported by Cloud Security Posture Management (CSPM)
Enabling Cloud Security Posture Management (CSPM)
Understanding the purpose of Common Vulnerabilities and Exposures (CVEs)
Risk Factors and Attack Paths now that full CSPM is enabled
Creating a Microsoft 365 group to represent a SecOps Security Team
Assigning recommendations to SecOps
Strengthening Security with Microsoft Defender for Endpoint
Understanding the concepts of Endpoint Security
What is Microsoft Defender for Endpoint?
How licensing works with Microsoft Defender for Endpoint
How Defender for Endpoint and Defender for Cloud work together
Assigning role permissions for Microsoft Defender management
How devices get onboarded into Defender for Endpoint
Exploring the information for a device managed by Defender for Endpoint
Strengthening Storage Security
Understanding the concepts of Azure storage accounts
Creating an Azure storage account
Configure Defender for Storage settings on a storage account
Testing Defender for Storage by uploading malware
Viewing storage account recommendations and alerts
Database Security with Defender for Cloud
Understanding the basic concepts of relational databases
Creating an Azure Microsoft SQL Database
Using SQL Server Management Studio (SSMS) for connecting to SQL
Connecting to a SQL database with SSMS
Managing Defender for Cloud support for SQL Databases
Enabling Vulnerability Assessment support for SQL
Investigations in the Microsoft Defender environments
Triggering sample events through Defender for Cloud
Manual investigation and remediation with Defender for Cloud
Investigating an Attack path analysis
Investigations with Microsoft Defender XDR
Automated investigation and remediation (AIR)
Using a device group to enable automated investigation and remediation
Performing searches with Cloud Security Explorer and Kusto Query Language (KQL)
Using Cloud Security Explorer for locating possible vulnerable resources
Concepts of Kusto Query Language (KQL)
How to use the Microsoft KQL Demo environment
Using basic KQL syntax for searching
How to summarize KQL results and filter based on time ranges
Using KQL with columns, amounts and characters
Variables and combining output data with KQL
Searching for Defender for Cloud alert data with KQL
Cloud Security blades in Defender for Cloud
Reviewing security posture
Understanding Regulatory Compliance
Securing resources with Workload Protections
Data and AI security
Viewing Network Security methods in Defender for Cloud
Concepts of securing development pipelines with DevOps security