
Build a solid foundation by exploring on premise active directory, domain services, RAR and DMZ, virtualization, and the Microsoft cloud landscape including Microsoft 365, Azure, and IaaS, PaaS, SaaS.
This lecture will draw out the basic concepts behind the purpose of Active Directory Domains
This lecture will draw out some of the basic concepts of Remote Access Demilitarized Zones and Virtualization
This lecture will draw out the basic concepts behind Microsoft Cloud Services
Learn to complete assignments and simulations in ms-102: start the simulation, open the link in a new tab, create a user, assign an EMS license with admin rights, and submit.
Explore why a practice lab is optional and you can skip it and still gain significant knowledge by watching the course or practicing on your own, with simulations available 24/7.
download Windows 11 ISO to set up a Windows 11 virtual machine by following the Microsoft ISO download link on exam lab practice, selecting the English United States 64-bit edition.
Set up a Windows 11 virtual machine in Hyper-V manager, allocate four gigs of RAM, enable TPM, attach the ISO, and complete the installation steps to finish the VM.
Disable large send offload version 2 on the Hyper-V virtual ethernet adapter via device manager to fix slow or failing internet connections.
Choose a unique domain name for your Microsoft tenant, verify availability with a registrar like GoDaddy, and consider a low-cost option such as a 99-cent domain for practice.
Deploy an on-premises active directory domain controller on Windows Server 2022, installing AD DS, promoting to a new forest exam lab practice.com, and configuring DNS and NetBIOS.
Join exam lab practice domain on Windows 11 by setting DNS to domain controller at 192.168.1.213, using manual IPv4, disabling IPv6, renaming computer, and logging in as domain administrator.
Set up a personal lab with Microsoft 365, sign up for a free Office 365 E5 trial, learn to activate Microsoft 365 E5 and Teams, and note regional restrictions.
Create a free Microsoft 365 and Azure trial by opening a new email and verifying a code, then learn to assign an E5 license and cancel after 30 days.
Define tenants in Microsoft Entra ID, Azure, and Microsoft 365 and their IAM boundary for security and access management. Learn how to create, switch, and delete tenants, with MFA notes.
Register and verify a custom domain in Microsoft 365 or Azure via Microsoft Entra ID, using DNS text records to own the domain and enable Exchange Online.
Explore org settings in Microsoft 365 to configure service-wide options and security and privacy. Manage organizational profile, app launcher, themes, and release preferences for the whole tenant.
Monitor the health of Microsoft 365 services using the service health blade in the admin center to view active issues, user impact, history, and report or notify about issues.
Learn to configure and manage Microsoft 365 backup for SharePoint, OneDrive, and Exchange, set retention and ten-minute restore points, and apply pay-as-you-go pricing at $0.15/GB/mo.
Learn to monitor Microsoft 365 adoption and usage with the admin center, interpret adoption score components, and use usage reports to drive digital transformation across Teams, SharePoint, and email.
Learn to redo simulations easily by going to summary, back to assignment, clicking instructions, and clicking the simulation link.
Learn how identities in Microsoft Entra ID centralize user, guest, service principal, and device identities across cloud and on-premises, using portals, synchronization, and managed versus user-assigned identities.
Explore Azure, Microsoft 365, and intra ID groups, the directory for identities. Learn the four group types and how assigned or dynamic membership governs access.
Create and manage Microsoft 365 groups, distribution lists, and security groups (including mail-enabled) in the admin center, assign owners, add members, and configure privacy and team integration settings.
Explore how to create and manage groups in the azure portal, including microsoft 365 and security groups, with manual and dynamic membership, dynamic queries, and device-based rules.
Learn to manage and monitor Microsoft 365 licenses, including group-based licensing, by assigning licenses to individuals or groups, comparing license options in marketplace, and using reports to track usage.
Learn how Azure RBAC and Entra ID roles govern who can access and manage resources across Azure, Microsoft 365, and Entra ID, applying least privilege and PIM for just-in-time access.
Manage roles and role assignments across Microsoft 365, Defender XDR, Purview, and Entra ID in the admin center. Learn to search roles, view permissions, and assign users or groups.
Create and manage administrative units in Azure AD, apply restricted management for scoped roles like user administrator, and see how New York admin can manage only its unit.
Understand privileged identity management (PIM) and its role in zero trust and least privilege. Explore just-in-time access, approvals, multi-factor authentication, and audit history across Azure AD and Microsoft 365.
Learn to implement Microsoft Entra privileged identity management to grant temporary access by creating role assignments, activating eligible roles with multi-factor authentication, and reviewing access.
Master bulk user management by creating users via the Azure portal and the Microsoft 365 portal, using a CSV template and uploading it for bulk enrollment.
Build a solid foundation in PowerShell through hands-on practice with verb-noun commands, IntelliSense, and piping for remote administration across Windows and Microsoft 365.
Understand Microsoft Graph as a unified API endpoint for Microsoft 365 and Azure. Explore how Graph enables cross-service automation with OAuth 2.0 and PowerShell, replacing legacy commands.
Install Microsoft Graph PowerShell modules, set execution policy, and connect to Microsoft Graph with scopes like group.readwrite.all and user.readwrite.all to access Azure and Microsoft 365 services.
Compare Entra connect sync and Entra cloud sync for hybrid identity, highlighting authentication options, single sign-on, and writeback capabilities.
Deploy an Azure virtual machine, promote it to a domain controller, install Active Directory Domain Services, and configure Microsoft Entra Cloud Sync to synchronize a test user via an OU.
Monitor synchronization with Microsoft Entra Connect Health by installing health agents on domain controllers and federated servers, then review sync errors and health analytics for troubleshooting.
Troubleshoot Entra Connect Sync and Entra Cloud Sync by checking health and analytics, reviewing sync errors, verifying services and agent status, and rebooting or restarting components as needed.
Explore password management in Microsoft Entra ID and Microsoft 365, covering password expiration policy, cloud identities versus on-premises sync, and lockout thresholds, ban lists, and Windows Server AD integration.
Investigate authentication issues in Entra ID by monitoring activity, reviewing registration and reset events, and inspecting user registration details across Azure and Microsoft 365.
Configure intra-identity protection using risk-based conditional access in Microsoft Entra ID protection, define user and sign-in risk levels, and enforce controls like multi-factor authentication for all users.
Plan conditional access policies using signals from identities, devices, and apps within a zero-trust framework, and enforce access with real-time risk detection and multi-factor authentication.
Learn to create and manage conditional access policies in the azure portal, selecting users, target apps, conditions, and grant or block actions with risk and device considerations.
Explain multifactor authentication, requiring two or more factors such as something you know, have, or are, and its conditional, risk-based deployment within Azure and Microsoft 365.
Enable multi-factor authentication across Azure and Microsoft 365 by configuring security defaults or conditional access policies, and deploy MFA for all users or groups.
Explore threat analytics in Microsoft Defender 365 and threat intelligence to monitor ransomware, phishing, and vulnerabilities, review analyst reports and attack scenarios, and set up email notifications.
Explore Defender for Office 365 threat policies and rules, including anti phishing, anti spam, anti malware, safe attachments and safe links, plus dynamic delivery and zero hour auto purge.
Identify and respond to threats in Microsoft Defender for Office 365 using Threat Explorer to analyze emails, phishing, and content malware, then apply remediation.
Master the attack simulator in Microsoft 365 defender to create credential harvesting campaigns, run phishing simulations, trigger training, and measure user susceptibility with automated feedback.
Unblock restricted users in Microsoft 365 Defender by navigating to portal.microsoft.com, opening the security blade, and unblocking the user on the restricted entities page.
Discover how Microsoft Defender for Endpoint turns devices into sensors, offering threat and vulnerability management, attack surface reduction, next gen protection, endpoint detection and response, automated remediation, and threat intelligence.
Learn to onboard Windows devices to Defender for Endpoint, including licensing, Azure AD join, onboarding package, local script, and verifying enrollment in the Defender portal dashboard.
Explore how to configure Microsoft Defender for Endpoint settings in Microsoft 365 Defender, including advanced options, licenses, roles, device groups, alert rules, and integrations with Intune and threat intelligence.
Explore defending endpoints with Defender for Endpoint in Microsoft 365 Defender, run a detection test with a suspicious PowerShell command, and review alerts and incidents in configuration management.
This course is way more then the average training course on Udemy! Have access to the following:
Training from an instructor of over 20 years who has helped thousands on their certification journey
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on that can be followed even if you have little experience
Hands on simulations that can be practiced 24/7 regardless of if you have Windows, Server or even a Microsoft 365/Azure Subscription in front of you
This course will prepare you for either MS-102, whichever you decide to take.
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
AB-650 and MS-102 material differences
Understanding the Microsoft Environment
Foundations of Active Directory Domains
Foundations of RAS, DMZ, and Virtualization
Foundations of the Microsoft Cloud Services
IMPORTANT Using Assignments in the course
DONT SKIP: The first to know about Microsoft cloud services
Setting up for hands on
Introduction to practicing hands on
Downloading Windows Server 2022 ISO
Getting Hyper-V Installed on Windows
Creating a Virtual Switch in Hyper-V
Installing a Windows Server 2022 Virtual Machine
Downloading the Windows 11 ISO
Installing a Windows 11 virtual machine
Use an internet unique domain name
Deploy and manage domain controllers on-premises
Joining Windows 11 to a domain
Creating a trial Microsoft 365/Azure Account
Configure and manage a Microsoft 365 tenant
Configure branding in a Microsoft 365 tenant, logo, URL, themes and backgrounds
Implement and manage domains
Configure & manage organizational settings, security & privacy & org profile
Manage and monitor Microsoft 365 licenses, including group-based licensing
Understanding the capabilities of Copilot and Agents in Microsoft 365
Manage and monitor licenses for AI services, including Microsoft 365 Copilot
Configure and use Microsoft 365 Backup, including setup, restore, etc
Configure and review network connectivity insights
Monitor the health of Microsoft 365 services by using Service health
Manage identities in Microsoft Entra
Concepts of identities in Azure/Microsoft 365/Entra ID
Create and manage Microsoft 365 users
Create and manage external users in Microsoft Entra
Create and manage contacts in the Microsoft 365 admin center
Concepts of Groups in Azure/Microsoft 365/Entra ID
Create and manage groups, including Microsoft 365 groups and shared mailboxes
Create and manage groups, including Microsoft 365 using the Azure portal
Manage and monitor Microsoft 365 licenses, including group-based licensing
Concepts of roles in Microsoft 365 and Microsoft Entra
Implement and manage roles in Microsoft Entra
Manage roles/role groups in MS Defender XDR, MS Purview, and Microsoft 365
Concepts of delegation by administrative units
Manage delegation by using administrative units
Understanding privileged identity management (PIM)
Manage Microsoft Entra roles in Entra privileged identity management (PIM)
Perform bulk user management
Foundational hands on experience with PowerShell
Concepts of using Microsoft Graph with PowerShell management
Setting up for connecting to MS Graph to support cloud services with PowerShell
Create and manage users and groups, as well as bulk management with PowerShell
AB-650: Manage Microsoft 365 workloads
Create and manage teams in Microsoft Teams, including channels, owners, and members
Configure settings for Copilot in Teams meetings, including transcription
Create and manage SharePoint sites
Manage SharePoint site roles and permissions
Features and capabilities of SharePoint Advanced Management
MS-102:Implement and manage identity synchronization with Microsoft Entra tenant
Concepts of Entra Connect Sync vs Entra Cloud Sync for Hybrid scenarios
Drawing out Entra Connect Sync and Entra Cloud Sync
Implement and manage directory synchronization by using Microsoft Entra Connect Sync
Implement and manage directory synchronization by using Microsoft Entra Cloud Sync
Monitor synchronization by using Microsoft Entra Connect Health
Troubleshoot synchronization, including Entra Connect Sync and Entra Cloud Sync
Implement and manage authentication and access in Microsoft Entra
Implement and manage authentication methods
Implement and manage self-service password reset (SSPR)
Implement and manage Microsoft Entra Password Protection
Investigate and resolve authentication issue
Plan for identity protection
Implement and manage Microsoft Entra ID Protection
Plan Conditional Access policies
Implement and manage Conditional Access policies
Concepts of multi-factor authentication (MFA)
Implement multi-factor authentication (MFA) by using conditional access policies
MS-102: Review & respond to security reports & alerts by Microsoft Defender XDR
Review & take actions to improve the MS Secure Score in the Microsoft Defender
Review & respond to security incidents & alerts in Microsoft 365 Defender
Review and respond to issues identified in security & compliance reports
Review and respond to threats identified in threat analytics
Secure Microsoft 365 workloads
Understanding Defender for Office 365
Implement policies and rules in Defender for Office 365
Review and respond to threats identified in Defender for Office 365
Create and run campaigns, such as attack simulation
Unblock users
MS-102: Implement & manage endpoint protection by using MS Defender for Endpoint
Understanding Defender for Endpoint
Onboard devices to Defender for Endpoint
Configure Defender for Endpoint settings
Review and respond to endpoint vulnerabilities
MS-102: Implement and manage Microsoft Defender for Cloud Apps
Understanding the configuration of app connections with Defender for Cloud Apps
Configure MS Defender for Cloud app alerts, policies, and Cloud App Discovery
Protect data in Microsoft 365 by using Microsoft Purview
Concepts of data loss prevention (DLP)
Configure DLP policies for Exchange, SharePoint, OneDrive, and Teams
Configure data loss prevention policies for Adaptive Protection
Understanding policy and rule precedence in data loss prevention
Understanding device requirements for Endpoint DLP
Configure Endpoint DLP
Review and respond to DLP alerts, events, and reports
Understanding sensitive information requirements for an organization's data
Implement & manage sensitive info types by using keywords, keyword lists, regex
Understanding sensitivity labels
Implement sensitivity labels for items and containers
Implement protection settings and content marking for sensitivity labels
Implement sensitivity label policies
Implement auto-labeling policies for sensitivity labels
How sensitivity labels apply to containers, such as Teams, SharePoint etc
Implement sensitivity labels manually using Microsoft Word
Understanding retention and disposition
Retention labels, retention label policies, and retention policies
Implement and manage adaptive scopes
Implement retention labels for data lifecycle management
Implement a retention label policy to publish labels
Implement a retention label policy to auto-apply labels
Implement and configure retention policies
Monitor label usage by using Content explorer, Activity explorer, & label reports
AB-650: Enable and manage Microsoft 365 Copilot
Assess tenant readiness for Copilot, including in-app experiences
Identify and resolve data readiness issues for Copilot, data leaks, oversharing
Manage web search for Copilot and Microsoft 365 Copilot Chat
Configure Microsoft 365 Copilot Search
Assess what Copilot is and how accesses data in your tenant
Identify how Microsoft Graph and Copilot work together in your tenant
Configure Copilot settings for a tenant, including self-service purchases & more
Manage Copilot user licenses
Configure Copilot connectors
AB-650: Implement and manage agents in Microsoft 365 and Agent 365
Identify how agents perform Researcher, Analyst, and custom agent roles
Review prompts, including saving, sharing, scheduling, and deleting
Configure user access to agents
Configure a license for Agent 365
Configure an agent
Manage agent approval as an administrator
Manage the lifecycle workflows for agent identities by using MS Entra Agent ID
Secure agent access, including access packages and conditional access
Manage agent owners
AB-650: Secure and govern agents by using Agent 365
Monitor agent activity by using Agent 365
Protect sensitive data by using Agent 365
Evaluate compliance gaps by using Agent 365
AB-650: Monitor AI services in Microsoft 365
Manage and monitor costs for AI services in Microsoft 365
Monitor usage reports for Copilot in the MS365 admin center, including adoption
Monitor agents, usage, operational insights, and agent lifecycle