
Experience hands-on learning of Microsoft Defender for Endpoint through browser-based simulations and labs, covering threat and vulnerability, attack surface reduction, endpoint detection and response, auto investigation, and remediation.
This foundation lecture covers on-premise Active Directory domain services, virtualization concepts, and cloud models like Microsoft 365 and Azure, including IaaS, PaaS, and SaaS, to build a solid understanding.
Explore the evolution from on-prem domains to active directory domains, detailing domain controllers, replication, Kerberos and LDAP authentication, DNS naming, and central management through GPOs in a cloud oriented environment.
Establish secure remote access with ras and vpn, implement a dmz perimeter network, and leverage virtualization with Hyper-V and VMware for scalable, resilient infrastructure.
Learn how cloud services emerged, including IaaS with Azure, PaaS and SaaS in Microsoft 365, and how Intra ID (formerly Azure AD) and interconnect tools link on-premises and cloud identities.
Learn how Microsoft renames portals, such as Azure Active Directory to IntraID, and Defender, Purview, and Intune move to new URLs on portals.examlabpractice.com.
Don’t skip assignments; simulations teach core skills, and only video checkboxes count toward your certificate, not assignment checkboxes. Open simulation links in a new tab, complete them, then submit.
John Christopher invites questions and shows how to search docs.microsoft.com for official, up-to-date Defender for Endpoint guidance, assignments, and Udemy exam materials.
Learn how to earn your certificate of completion by watching all videos, as assignments are not required, and follow the final video for certificate details.
Learn how to set up a personal lab with Microsoft 365 and Azure, including a free Office 365 trial to access Microsoft 365 E5, and an optional Teams trial.
Learn to create a free Microsoft 365 trial account, navigate licensing options like E5, assign licenses, and cancel after 30 days, with tips on links, verification, and developer programs.
Learn how to disable security defaults in Microsoft Entra ID to enable more granular conditional access policies and tailor security settings for your tenant.
Configure Microsoft Entra ID to allow all users to join devices, and enable Microsoft Intune as the MDM to manage joined devices with automatic enrollment.
Choose a hands-on VM path for the Defender for Endpoint course: Hyper-V or Azure, weighing Windows edition, hardware, and cost; Azure offers credits and scalability.
Learn to install Hyper-V, Microsoft's virtualization software, on Windows Pro or Enterprise; home editions cannot install, enable Hyper-V via turn Windows features on or off, reboot, and open Hyper-V Manager.
Set up a virtual switch in Hyper-V to allow a virtual machine to access the internet, by creating an external switch and selecting the network interface.
disable large send offload version 2 on the Hyper-V virtual Ethernet adapter to fix internet slowdowns or outages.
Download the Windows 11 ISO for a Hyper-V setup from the exam lab practice ISO download page, then choose English United States 64-bit and save the file.
Learn how to install and configure a Windows 11 virtual machine using Hyper-V, including generation choices, memory settings, TPM, virtual processors, ISO boot, and post-install setup.
Map how Microsoft intra ID, Intune, and Defender for Endpoint work together to manage identities, devices, and compliance policies.
Understand registered versus joined devices in Microsoft Entra, including personal bring-your-own-device policies and how Intune controls access to company resources with personal and organizational sign-ins.
Manually join a Windows 11 device to Microsoft Entra ID, using a work or school account, and verify enrollment appears in the Azure portal.
Learn how to redo simulations after completing an assignment by accessing the summary, returning to the assignment, and opening the instructions to reach the simulation link.
Discover how endpoint security protects desktops, laptops, smartphones, servers, and IoT by defending against malware, phishing, data leaks, and zero-day threats with antivirus, EDR, and policy enforcement.
Explore Microsoft Defender for Endpoint, an enterprise-grade security platform delivering threat and vulnerability management, attack surface reduction, next-gen protection, and endpoint detection and remediation with cloud analytics and threat intelligence.
Compare Microsoft Defender for Endpoint plan P1 and plan P2, and learn how Microsoft 365 E5 licenses unlock plan 2 access with advanced features like endpoint detection and response.
Take a guided tour of the Microsoft Defender for Endpoint portals—admin.microsoft.com, security.microsoft.com, and endpoints settings—covering licensing, Purview integration, and areas like vulnerability management and configuration management.
Discover how Microsoft Defender for Endpoint and Microsoft Intune work together to enhance device management and enable Defender features through Intune.
Learn how Microsoft Intune delivers MDM and MAM across Windows, iOS, iPadOS, macOS, Android, and Linux devices, with enrollment, apps, policies, and compliance management.
Outline the prerequisites for Defender for Endpoint onboarding, including hardware and software requirements, browser support, and memory guidance, covering Windows, Mac, Linux, WSL, Android, and iOS.
Create a defender admin role with read and manage permissions for security operations and authorization, assign it to a user, and apply least privilege to defender for endpoint access.
Onboard a Windows device to Defender for Endpoint using the local script method, selecting standard onboarding, and confirm the device appears in the portal within 5 to 30 minutes.
Mass onboard hundreds of Windows devices with automatic enrollment via Microsoft Entra ID and Intune, then configure Defender for Endpoint onboarding and force a sync to complete setup.
Verify that a Windows device is onboarded in Defender for Endpoint by checking asset status and sensor health, then confirm with the sense service and a PowerShell onboarding state check.
Discover unmanaged devices with defender for endpoint's device discovery, then onboard or alert admins. Use basic passive collection and standard active probing to build an inventory of onboarded devices.
Identify how common vulnerabilities and exposures (CVEs) are defined and tracked by MITRE, and how CVSS scores guide vulnerability scanning with Microsoft Defender for Endpoint.
Learn how Defender for Endpoint inventories a device, discovers vulnerabilities and CVEs, and demonstrates that installing an out-of-date program can reveal security risks.
Explore the vulnerability management dashboard in Microsoft Defender for Endpoint to view a single pane of glass, exposing the exposure score, top threats, and security recommendations for devices.
Apply vulnerability recommendations from Microsoft Defender for Endpoint to strengthen your environment. Explore remediation options, view affected devices and CVEs, and use secure score to prioritize actions.
Learn to use vulnerability management within Defender for Endpoint to request and track remediation, apply software updates, and manage exceptions, tickets, and device groups for efficient risk reduction.
Create and manage device groups in Defender for Endpoint to control remediation levels and automation. Assign the NYC device admins group to govern access for NYC client machines.
Explore how endpoint security policies in Intune and the Microsoft Defender portal lock down windows settings, covering templates for antivirus, firewall, ASR rules, EDR onboarding, and device control.
Explore attack surface reduction rules in Microsoft Defender for Endpoint, learn to create ASR policies, audit settings, and monitor ASR events and reports.
Explore next generation protection in Microsoft Defender for Endpoint, using machine learning, AI behavioral analysis, and cloud delivered protection to detect polymorphic malware beyond traditional virus signatures.
Explore how Windows 11 Defender antivirus works, including virus and threat protection, quick and full scans, cloud protection, and managing settings with Intune or Group Policy.
Implement next-gen protection for devices by creating a Microsoft Defender Antivirus policy via Intune or the Defender portal, enabling features like archive scanning, cloud protection, real-time monitoring, and email scanning.
Explore managing Windows Defender firewall on Windows 11 across domain, private, and public profiles. Learn inbound/outbound rules and blocking telnet port 23.
Configure firewall rules with Microsoft Defender for Endpoint by creating a Windows firewall policy to block telnet on port 23, then apply to devices and synchronize across devices.
Explore how Defender for Endpoint security baselines deployed via Intune create a foundation of preconfigured Windows settings, including BitLocker and Edge configurations.
Explore data loss prevention concepts and design use cases across emails, SharePoint, OneDrive, Teams, and endpoints to prevent data leakage and protect regulatory, internal, and industry-specific data.
Explore endpoint data loss prevention in Microsoft purview for on-prem devices, configuring cloud egress, file extensions, path exclusions, and policy tips with auditing of Office, pdf, and csv files.
Explore configuring endpoint dlp in microsoft purview, from advanced classification and file path exclusions to network share coverage, restricted apps, and vpn policies.
Configure advanced data loss prevention rules for devices by editing low and high volume DLP rules with conditions and actions, and run simulations to enforce restrictions and notifications.
Enable just-in-time protection in data loss prevention, using the insider risk management engine to monitor medium or high risk users and enforce policies across devices with configurable actions.
Explore the activity explorer in compliance to monitor endpoint activities, viewing endpoint devices, client IPs, locations, and users, with filters by date and sensitivity label.
Explore how Air automates investigation and remediation in Microsoft Defender for Endpoint, automatically analyzing alerts, distinguishing real threats from false positives, and quarantining or reversing changes without user intervention.
Enable automated investigation and remediation (AIR) for device groups in Microsoft Defender for Endpoint by turning on full remediation, ensuring all devices in the group are automatically managed.
trigger incidents on a client device using Microsoft Defender for Endpoint demonstration scenarios, including attack surface reduction scripts, PowerShell actions, and log synchronization to analyze security responses.
Explore how to investigate incidents in Defender managed devices, using attack story visuals, URL and file details, and automated remediation to prevent malware and review evidence across devices.
Explore how alerts accompany incidents in Microsoft Defender for Endpoint, view alert stories and timelines, and configure alert policies for threat management, data loss prevention, and email notifications.
Learn to assign, classify, and manage security alerts in Defender for Endpoint, using automated investigations, and set classifications such as new, in progress, resolved, malicious activity, phishing, or compromised accounts.
Learn to query and analyze large security data with Kusto query language (KQL) across Defender XDR, Sentinel, and Purview, using filtering, aggregation, and time-based analysis to investigate alerts and IOCs.
Navigate to the microsoft kql demo environment at aka.ms/demo, download the provided resource, and use ai copilots to generate and run kql queries on the security event table.
Learn basic kql syntax in the kusto query language within a Microsoft demo environment to search security events using where and pipe filters such as event id 4624.
Learn to summarize KQL results and filter by time ranges, using counts, dcount, and top five by count by event source name, with dynamic time filters and custom ranges.
Learn to control KQL data displays by projecting columns, calculating event ages, showing earliest successful logon events, sorting by time generated, and filtering with operators to reveal PowerShell activity.
Declare temporary variables with let, use them across queries, and combine data with union and join to correlate logon (4624) and process creation (4688) events.
learn to run advanced hunting queries with kql in microsoft defender for endpoint, exploring device events, registry and logon data, email and alert data, and cve-based searches through hands-on sims.
Explore the premade KQL queries in the Azure Sentinel repository for Microsoft Defender and Sentinel, then practice hands-on with device inventory queries in Microsoft 365 Defender.
Delete your Azure virtual machine and associated resource groups in portal.azure.com by copying the resource group names, applying force delete, and removing Network Watcher to stop using Azure credit.
We really hope you'll agree, this training is way more than the average course on Udemy!
Have access to the following:
Training from an instructor of over 25+ years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course!
Understanding the Microsoft 365 and Azure Environment
A Solid Foundation of Active Directory Domains
A Solid Foundation of RAS, DMZ, and Virtualization
A Solid Foundation of the Microsoft Cloud Services
IMPORTANT Using Assignments in the course
Questions for John Christopher
Certificate of Completion
Setting up for hands on
DONT SKIP: Before beginning your account setup
Creating a trial Microsoft 365/Azure Account
Disable Security Defaults in Entra ID before proceeding
Configuring Microsoft Entra for device management
Using a Hyper-V virtual machine or an Azure virtual machine
Setting up an Azure virtual machine for hands on
HYPER-V: Getting Hyper-V Installed on Windows
HYPER-V: Creating a Virtual Switch in Hyper-V
HYPER-V: Downloading the Windows 11 ISO
HYPER-V: Installing a Windows 11 virtual machine
Device management support with Microsoft Entra
Overview of device management of Microsoft device managements concepts
Registering devices vs joining devices with Microsoft Entra
Joining our virtual machine to Microsoft Entra
Introduction to Endpoint Security & Microsoft Defender for Endpoint
What is Endpoint Security?
High level overview of Microsoft Defender for Endpoint
Licensing and Plan Comparison (P1 vs P2)
Microsoft 365 Defender Portal Tour
How Defender for Endpoint relates to Microsoft Intune
Introduction to Microsoft Intune for device management
Setting Up Defender for Endpoint
Prerequisites and Supported Operating Systems
Creating a Microsoft Defender Admin role for permissions
Onboarding a Windows device to Defender for Endpoint
Mass automatic onboarding with Microsoft Intune
Verifying Windows devices have been onboarded
Implementing device discovery
Defender for Endpoint Vulnerability Management
What are Common Vulnerabilities and Exposures (CVEs)?
Inspecting vulnerabilities on a specific device
Using the vulnerability management dashboard for high level overview
Improving security with the help of vulnerability recommendations
Utilizing remediation within vulnerability management
Creating and managing Device Groups for Defender for Endpoint
Configuration and Policy Management
Hardening endpoint security by using Endpoint Security Policies
Attack Surface Reduction (ASR) Rules
What is Next-Gen Protection with Microsoft Defender for Endpoint?
Understanding the local anti-virus settings on Windows 11
Implementing Next-Gen Protection for devices
Understanding the local Defender Firewall settings on Windows 11
Implementing Firewall Rule Policies using Defender for Endpoint
Using Security Baselines in securing our devices
Utilizing Microsoft Purview Endpoint DLP (Data Loss Prevention)
Understanding the concepts of DLP (Data Loss Prevention)
Considering device requirements before using Endpoint DLP
Settings for configuring Endpoint DLP
Configuring DLP policies with advanced rules
Enabling just-in-time (JIT) protection
How to monitor for endpoint activities
Incident Response and Investigation
What is Automated Investigation and Remediation (AIR)?
Implementing Automated Investigation and Remediation (AIR) within device groups
Triggering incidents using a client device for testing
Investigating incidents generated by Defender managed devices
Viewing alerts generated by Defender managed devices
Managing and classifying detected alerts
Kusto Query Language (KQL)
What is Kusto Query Language (KQL)?
Using the Microsoft KQL Demo environment, downloading resource materials and AI
Basic KQL syntax for searching for information
Summarizing KQL results and filtering based on time ranges
Controlling KQL data displayed based on columns, amounts and characters
Using KQL variables and combining output data
Running Threat Hunting Queries with Advanced Hunting (KQL)
Utilizing Microsoft's Sentinel and Defender repository of premade KQL Queries