
Build a solid foundation by exploring on-premise Active Directory domain services, virtualization concepts, and the Microsoft cloud framework, including Microsoft 365, Azure, and IaaS, PaaS, and SaaS.
Explore the foundations of Active Directory domains, domain controllers, and centralization through DNS, Kerberos, LDAP, and group policy objects to manage authentication and policy replication.
Explore how Active Directory Domain Services, LDAP, and Kerberos underpin secure remote access with RAS and VPN. Review the DMZ perimeter network and virtualization using Hyper-V for scalable hosting.
Explore the origins of cloud services and core IaaS concepts with Azure, and how Microsoft 365 apps align with SaaS and PaaS via Entra ID and Azure AD Connect.
Explore frequent Microsoft portal renames and updates, from Azure Active Directory now named IntraID, to new access points like admin.Microsoft.com, defender.Microsoft.com, purview.Microsoft.com, and intune.Microsoft.com, plus the portals.examlabpractice.com resource.
Set up a free Microsoft 365 E5 trial to activate your subscription and optionally enable a 30-day Teams trial, noting regional limitations.
Create a free Microsoft 365 trial with a new email, verify by phone, and assign the Microsoft 365 E5 license to your user; cancel after the 30-day trial.
Watch the course videos to earn a certificate; assignments are optional, as simulations require opening links in a new tab and submitting progress with next and submit.
Learn to ask questions effectively, contact the instructor, and search official Microsoft Docs for updated guidance on topics like Microsoft 365 dynamic groups, exam labs, and Udemy policies.
Complete all the videos to earn a certificate of completion; assignments do not matter. Stay tuned for a final video that explains how to obtain your certificate.
Explore the transition from the classic to the new Purview portal on admin.microsoft.com and navigate with solutions such as information protection and data loss prevention.
Identify sensitive information types such as PII, financial data, health information, intellectual property, classified government data, and confidential business information, and apply data sensitivity labels and governance with security controls.
Learn how to translate sensitive information requirements into built-in or custom sensitive information types, using manual, automated, and machine learning classifications, patterns, and Purview licensing concepts.
Learn to create and manage custom sensitive info types in Microsoft Purview, using primary elements like credit card patterns (regex), keywords, and dictionary lists, with testing and policy setup.
Explore document fingerprinting in Microsoft 365, creating sensitive info type fingerprints from templates to support data loss prevention across Exchange, SharePoint, OneDrive, and Teams.
Learn to create exact data match (EDM) classifiers in Microsoft Purview by uploading sample data, selecting primary elements like credit card numbers, and configuring detection rules for sensitive data.
Learn how trainable classifiers in Microsoft 365 gather and classify documents to support retention, sensitivity, and communication compliance policies, requiring Microsoft 365 E5 and 50 samples along a phased timeline.
Use data explorer to surface sensitive data and labels, and activity explorer to monitor user actions; learn how connectors ingest external data, like Salesforce, into Purview.
Activate optical character recognition in Microsoft Purview to scan sensitive information types in PDF, JPG, and PNG files, with costs at $1 per 1000 items, and scan Exchange, SharePoint, OneDrive.
Understand how sensitivity labels classify and protect data across documents and emails, using manual or automated labeling, encryption, watermarks, and data loss prevention policies via metadata in Microsoft 365.
Assign roles in Microsoft Purview to manage sensitivity labels—compliance administrator, information protection admin, and analyst—and recognize investigators and readers with least privilege for label policies and DLP in Microsoft 365.
Create and manage sensitivity labels in Microsoft Purview by defining a label, configuring protection and access controls, and applying scope to data assets, emails, meetings, and groups.
Configure protection settings and content marking for sensitivity labels in Microsoft Purview, including control access, dynamic watermarking, and double key encryption across files, emails, meetings, groups, and sites.
Publish sensitivity labels by creating a publishing policy, selecting the label, assigning admin units, and applying the policy to all users and groups across Office apps and Power BI.
Learn how auto labeling policies apply sensitivity labels across Exchange, SharePoint, and OneDrive. Create rules for sensitive data like US social security numbers, understand encryption implications, and run simulation testing.
Learn how to apply sensitivity labels to data assets and containers such as emails, meetings, teams, groups, and SharePoint sites, and configure protection settings and auto labeling across the environment.
Learn how users apply sensitivity labels to Word documents using desktop and web Word after signing in with a Microsoft 365 license. Note possible label delays up to 24 hours.
Monitor label usage with Purview by using Data Explorer, Content Explorer, and Activity Explorer, plus label reports, to view labeled data, sensitive info, and related activities.
Defender for cloud apps secures cloud usage by monitoring user activities, preventing shadow IT, and enforcing data policies across on-prem and cloud apps through discovery, app connectors, and remediation policies.
Shows how to auto apply sensitivity labels using Microsoft Defender for Cloud Apps by creating a file policy that labels external document sharing in SharePoint with a top secret label.
Discover how to easily redo simulations after completing an assignment by using the course interface: go to summary, return to the assignment, open instructions, and access the simulation link anytime.
Explore the Microsoft Purview information protection client, a Windows-based tool for classifying, labeling, and encrypting sensitive data across files and emails, with file explorer integration and on-prem data scanning.
Download and install the Microsoft Purview Information Protection client on a Windows machine or an Azure virtual machine, then verify it appears in control panel.
Learn how to apply sensitivity labels with the Microsoft Purview Information Protection client to a file on Windows 11, including login checks and label verification.
Install the Microsoft Purview Information Protection scanner on Windows servers and configure SQL to scan on-prem files for labels and DLP policies, with results visible in Content Explorer.
Delete the virtual machine by removing its resource group in portal.azure.com to conserve Azure credits. Use the force delete option, confirm the name, and delete so you can move on.
Explore the main Microsoft 365 email encryption designs, including information rights management and S/MIME, with a focus on Microsoft Purview Message Encryption, its licensing requirements, TLS-based protection, and Outlook compatibility.
Enable Microsoft Purview message encryption in the Exchange admin center by creating a mail flow rule to encrypt all messages or selected senders and recipients.
Explore purview advanced message encryption, enhancing encryption with sensitivity labels, compliance features, and custom branding, managed via the exchange admin center and PowerShell configuration.
Explore data loss prevention concepts and design use cases across exchange online, sharepoint, teams, and endpoints, applying pci dss and hipaa sensitive data controls to prevent leakage of pii.
Explore data loss prevention roles and permissions in Microsoft Purview, focusing on built-in roles like compliance administrator, compliance data administrator, and information protection admin to create policies and view reports.
Create a data loss prevention policy in Microsoft Purview by selecting financial templates, configuring locations, and defining conditions, with policy tips, alerts, and simulation mode before activation.
Explore how adaptive protection in Microsoft Purview uses insider risk management and monitoring to tailor data loss prevention policies to user risk levels, enabling proactive protection with alerts and actions.
Learn how data loss prevention policies in Microsoft Purview use priority and precedence. Policies use lower numbers for higher priority, and when rules conflict, the most restrictive rule applies.
Learn to deploy data loss prevention file policies using Defender for Cloud Apps in Microsoft Purview, including creating a SharePoint-based file policy with sensitivity labels, monitoring, and alerts.
Learn to monitor DLP alerts, enable and customize DLP rules, and view reporting data across Data Explorer, Content Explorer, and Defender incidents to inform response.
Explore how endpoint data loss prevention in Microsoft Purview helps monitor and manage on-premises and cloud-connected devices, including Windows and Mac, with policy controls, exclusions, and advanced classification.
Configure endpoint DLP settings in Microsoft Purview, including advanced classification, file path exclusions, evidence collection, network shares, app groups, file extension groups, browsers, justifications, VPN, and onboarded servers.
Demonstrates configuring advanced DLP rules for devices in Purview, creating and editing low and high volume rules, setting conditions and actions, and testing via simulation before deployment.
Just-in-time protection in Purview data loss prevention dynamically evaluates files during share, copy, or move to block or allow actions in real time.
Monitor endpoint activity and data loss prevention using the activity explorer in compliance, then filter by location, endpoint devices, user, sensitivity label, IP, and date.
Apply retention policies and labels to manage content, preserve copies when edited, and perform disposition reviews to archive or delete data under compliance.
Compare retention policies, labels, and label policies, and learn how policies apply broadly to locations, labels to items, and label policies publish to users.
Learn how adaptive scopes dynamically apply retention policies in Purview by using department or site URL attributes to auto-update targets as employees move between departments.
Create a seven-year retention label in Microsoft Purview, choose whether to retain forever or for a period, decide post-retention actions, and publish the label to Microsoft 365 locations.
Publish a seven-year retention label as a label policy in Purview, using an adaptive scope and applying it to Exchange mailboxes and OneDrive, with a typical 24-hour activation.
Configure auto apply label policies in purview to enforce seven year retention on financial data, applying the label to content that contains sensitive info across exchange mailboxes and OneDrive.
Explore policy precedence in conflicts within Microsoft Purview: retention wins over deletion, longest retention prevails when conflicts persist, and explicit deletions outrank implicit ones.
Create a five-year retention policy in Microsoft Purview by selecting exchange mailboxes, SharePoint, and OneDrive, using a static retention period and start date from creation or last modification.
Explore how retained content in Microsoft 365 is recovered across Exchange Online, SharePoint, OneDrive, and Teams, using Microsoft Purview, content search, discovery, and PowerShell to recover from various retention stages.
Explore insider risk management in Microsoft Purview, using policy-driven alerts, triage, and case-based investigations to detect, analyze, and take action on internal data threats.
Configure data connectors in Microsoft Purview to ingest third-party data for insider risk management, enabling connectors with permissions, eDiscovery, and retention in insider risk policies.
Explore insider risk management settings in Microsoft Purview, including analytics, data sharing, detected groups, exclusions, inline alert customization, and policy indicators to tune alerts and privacy options.
Learn how policy indicators activate after triggering events and shape risk scores. Explore built-in and custom indicators across devices, cloud storage, generative AI apps, intra ID, and data loss prevention.
Explore insider risk policy templates in Microsoft Purview, covering data theft by departing users, data leaks, risky and priority users, and security policy violations.
Create an insider risk management policy in Microsoft Purview by using a custom policy, configuring data leaks and DLP rules, and setting triggering events and thresholds.
Learn how to enable forensic evidence in Microsoft Purview, capture and upload 1080p video clips for insider risk investigations, with 120-day retention, capacity limits, and admin controls.
Enable adaptive protection in Microsoft Purview to manage insider risk levels; configure elevated, moderate, and minor risk from alerts and exfiltration activity, then apply DLP and conditional access.
Explore how insider risk alerts trigger automatic notifications and how to create and manage cases from those alerts, collaborating with admins to investigate and save findings.
Explore how notice templates in insider risk management trigger email notifications when cases are created from alerts, enabling messages about code of conduct violations to employees.
Explore licensing paths for Microsoft Purview Audit premium, including Microsoft 365 E5 and eDiscovery and Audit add-on, and how premium enables longer retention and intelligent insights.
Learn to audit with Microsoft Purview by navigating to compliance, opening audit, and filtering by dates, activities, users, and workloads, then review details and export results.
Create an audit retention policy in Microsoft Purview to retain exchange admin audit entries for up to ten years, prioritizing specific activities and users like John Christopher.
Learn to use Activity Explorer in Microsoft Purview to analyze activities, filter by date, location, users, and sensitivity labels; export results, and leverage Copilot for insights.
Learn how data loss prevention alerts appear in Microsoft Purview by activating DLP policies; view, filter by user, status, and severity in the compliance portal.
Explore how to investigate insider risk management activities in Purview using the audit log, filter by category and date range, and export findings for review.
Explore how to view and respond to Purview-generated alerts inside Microsoft Defender XDR by navigating to admin.microsoft.com, security, and the alerts blade under incidents and alerts.
Explore Defender for cloud apps to view alert matches for file access policies, filter by apps, owner, access level, file type, and organizational unit, and receive email alert copies.
Protect content in AI environments with purview controls, including data classification and retention labeling, DLP, and access controls, and monitor with audit logs while integrating AI models for secure usage.
Implement data security posture management to discover sensitive data, assess risk, enforce compliance, and monitor controls across Microsoft 365 AI workloads, including SharePoint over sharing, DLP, and insider risk management.
Deploy and configure a Windows 11 Azure virtual machine for hands-on practice, including resource group setup, VM creation, remote access with an rdp file, and basic defaults.
Learn to set up DSPM for AI with Purview, including prerequisites, analytics, data discovery, risk assessments, access control, and AI privacy and compliance.
Explore how to configure AI policies with DSPM in Microsoft Purview, including DLP and insider risk management policies, customizing rules, thresholds, and generative AI data sharing controls.
Explore how to monitor for DSPM AI activities using Microsoft Purview, Activity Explorer, and DLP alerts, with policy investigations, insider risk tools, and comprehensive AI activity reports.
Delete the Windows 11 virtual machine to stop Azure credit. From portal.azure.com, go to virtual machines, open the Win 11 RG resource group, and delete it with force.
Explore how Udemy role plays use ai-generated scenarios to practice Azure basics, cloud vs on-prem decisions, and security tools like Defender and Sentinel in a demo guided by expert explanations.
Learn how to download your Udemy certificate for this course by completing all videos; assignments do not count, and contact Udemy support if issues arise.
Find more courses on Exam Lab Practice and Udemy. Subscribe to the YouTube channel and join the email list for coupon codes, free vouchers, and giveaways.
We really hope you'll agree, this training is way more than the average course on Udemy!
Have access to the following:
Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on and simulations to practice that can be followed even if you have little to no experience
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the course!
Understanding the Microsoft 365 and Azure Environment
A Solid Foundation of Active Directory Domains
A Solid Foundation of RAS, DMZ, and Virtualization
A Solid Foundation of the Microsoft Cloud Services
DONT SKIP: Before beginning your account setup
Creating a trial Microsoft 365/Azure Account
IMPORTANT Using Assignments in the course
Questions for John Christopher
Certificate of Completion
Using Data Classification and Sensitivity Label in Microsoft Purview
Introducing the new Microsoft Purview portal
Understanding requirements for sensitive information
Concepts of built-in or custom sensitive information requirements
Creating custom sensitive info types
Document Fingerprinting
Working with exact data match (EDM) classifiers
Understanding trainable classifiers
Working with trainable classifiers
Using data explorer & content explorer for monitoring data classification
Sensitive info types with optical character recognition (OCR)
Understanding sensitivity labels
Administering permissions for sensitivity labels
Creating sensitivity labels
Sensitivity label protection settings and content marking
Publishing sensitivity labels in Microsoft Purview
Using auto-labeling policies for sensitivity labels
Controlling sensitivity label to containers
How users can apply sensitivity labels manually using Microsoft Word
Monitor label usage by using Content explorer, Activity explorer, & label reports
Concepts of Microsoft Defender for Cloud Apps
How Microsoft Defender for Cloud Apps can apply sensitivity labels
Using Microsoft Purview for information protection of clients and data
Concepts of the Microsoft Purview Information Protection Client
Setting up the Microsoft Purview Information Protection Client
Using the Microsoft Purview Information Protection client to manage files
Understanding MS Purview Information Protection scanner bulk classifications
Deleting the Azure VM that is no longer needed
Understanding the Microsoft 365 email Encryption solutions
Microsoft Purview Message Encryption
Microsoft Purview Advanced Message Encryption
Using Data Loss Prevention with Microsoft Purview
Understanding data loss prevention policies
Data loss prevention roles and permissions
Creating data loss prevention policies
Using Adaptive Protection with data loss prevention
Data loss prevention policy and rule precedence
Using Defender for Cloud apps to deploy DLP file policies
Monitor for DLP alerts, events, and view reports
Concepts of Endpoint DLP device requirements
Settings used to manage Endpoint DLP
Managing DLP policies using the advanced rules
Working with just-in-time (JIT) protection
How to monitor endpoint activities
Using and maintaining retention in Microsoft Purview
Understanding information retention and disposition
Retention Policies vs Retention Labels vs Retention Label Policies
Using adaptive scopes
Creating retention labels
Publishing a retention label using a label policy
Using auto-apply labels for retention
Understanding policy precedence in regards to conflicts
Creating retention policies
Concepts for recovering retained content in Microsoft 365
Using Insider Risk Management in Microsoft Purview
Understanding Insider Risk Management in Microsoft 365
Concepts of Insider Risk Management roles and permissions
Using Insider Risk Management connectors
Managing Insider Risk Management settings
Managing the settings for policy indicators
Understanding the concepts of policy templates
Creating Insider Risk Management policies
Working with forensic evidence settings
Managing insider risk levels for Adaptive Protection
Insider risk alerts and cases
Using notice templates within Insider Risk Management
Using alert monitoring and protecting data used by AI services
Understanding the license concepts for Microsoft Purview Audit (Premium)\
Looking into activities by using Microsoft Purview Audit
Working with audit retention policies
Using activity explorer to analyze Microsoft Purview activities
Data loss prevention alerts in Microsoft Purview
Viewing insider risk activities
Viewing Purview alerts in Microsoft Defender XDR
Working with file policy alerts using Defender for Cloud Apps
Performing content searches
Understanding controls for the AI services in Microsoft Purview
Concepts of Microsoft 365 workload controls
Setting up a Windows 11 VM for hands on
Setting up the pre-requisites involving DSPM for AI
AI policies with DSPM
DSPM for AI activity monitoring
Deleting the Windows 11 VM from the lab