
Establish a well-defined baseline for Windows systems to ensure pre-hardened, consistent deployments through policies, standards, procedures, guidelines, baseline controls, and change management within a security framework.
Understand how policies, standards, procedures, and guidelines shape a Windows security program, supported by baselining, leadership endorsement, and compliance-centric controls.
Learn to create practical guidelines aligned with policies and baselines, and to embed change management through ITIL-based processes, approvals, and security baselines for consistent deployments.
Learn how to implement a security framework to reduce risk, identify gaps, and establish baseline controls using frameworks like NIST, ISO 27000, COBIT, and HITRUST.
Learn how to use CIS baselines and benchmarks to harden Windows devices, including desktop, server, mobile, and cloud benchmarks, with steps to download and implement.
Learn to secure Windows devices with Microsoft baselines via the Security Compliance Toolkit, using policy analyzer and LGPO tools to deploy Windows 11, 10, server, Office, and Edge baselines.
Adopt a structured security baseline using the NIST framework, CIS benchmarks, Windows and Intune baselines, and automate controls, monitor compliance, and maintain a risk register.
Protect Windows systems by securing hardware and virtualization, prioritizing trusted hardware, TPM, and secure boot, and deploying Hyper-V to isolate and safeguard virtual machines.
Protect hardware against BIOS/UEFI rootkits, CPU side-channel, and firmware attacks. Secure virtualization and supply chain risks by separating management and production, mitigating hypervisor threats and VM escape.
Explore BIOS and UEFI security, secure boot, and trusted hardware like TPM, plus virtualization-based security, HVCI, Credential Guard, and BitLocker to safeguard Windows startup and core defenses.
Explore virtualization-based security features in Windows, including Credential Guard, hypervisor-protected code integrity, and Application Guard for Office and Edge, to protect sign-in data, browser sessions, and documents.
Explore malware, phishing, social engineering, dos/ddos, password attacks, insider threats, and advanced persistent threats, and learn how these attacks compromise organizations. Build awareness of motivations, impacts, and defense strategies.
Explore common attacks and vulnerabilities targeting Windows Server, including ransomware, malware, denial of service, zero-day exploits, and man-in-the-middle threats, and learn how to prevent, mitigate, and patch them.
Explore how pass-the-hash attacks use password hashes to authenticate across networks, and defend with least-privilege access, strong passwords, network segmentation, multi-factor authentication, monitoring, patching, and credential guards.
Install Sysmon on Windows to provide enhanced monitoring by logging process creation, network connections, and file creation times to Windows event log; configure with a config.xml and install via sysmon64.
Explore how Sysmon for Windows monitors process creation, network connections, registry changes, and dns queries to detect malicious activity, including regsvr32 usage and indicators of command and control.
Discover how autoruns reveals every startup program in Windows, including startup folders, registry keys, and services. Learn to analyze, disable unnecessary items, and verify signatures with VirusTotal.
Learn to use the Sysinternals logon sessions command-line tool to view active Windows logon sessions, including domain, user, authentication method, logon type, and the associated processes.
Master group policy management concepts, including when to use custom GPOs, processing order, last applied policy wins, and the role of documenting settings for change management.
Explore system-level user rights like log on locally, back up files, and shut down, and how they differ from resource permissions. Follow the principle of least privilege when configuring them.
Adopt the principle of least privilege, audit and document user rights, and use built-in groups to strengthen Windows Server security and prevent privilege escalation.
Configure user rights and account security settings on Windows Server using the local security policy (secpol.msc). Assign logon locally rights and remove groups to enforce the principle of least privilege.
Configure strong password policies on Windows Server by enabling complexity, expiration, and history (24 passwords). Set account lockout thresholds (five attempts), durations (30 minutes), and reset counters; then test changes.
Secure Active Directory domain controllers and the Windows infrastructure by minimizing attack surfaces, enabling secure authentication, enforcing password security and auditing, and deploying read-only domain controllers and password replication policy.
Assess threat landscapes for Windows Server domain controllers and strengthen network boundaries. Protect credentials, guard privilege escalation, mitigate denial of service, and manage operating systems, applications, and physical security risks.
Demonstrate a kerberoasting attack by creating a vulnerable service account with an SPN, enabling auditing, exporting tickets, performing offline cracking, and outlining detection and prevention strategies.
Demonstrates a kerberoasting attack using Mimikatz to extract a service ticket, crack an RC4-encrypted hash offline, and audit Kerberos activity via security event logs.
Demonstrates kerberoasting prevention by enforcing AES encryption for Kerberos tickets, implementing gMSA, and monitoring domain controller events to detect unusual ticket requests.
Demonstrates installing and using nmap to scan a domain controller, identify open ports and potential vulnerabilities, and assess operating system details on Windows Server 2022.
Explore security concepts for Active Directory and domain controllers, including authentication credentials as a primary target, and protections against DOS, privilege elevation, physical threats, and wireless network certificates.
Centralize domain controller security by configuring default and custom GPOs, apply domain-wide account policies, and implement advanced audit policy and standardized event log settings for consistent monitoring.
Implement restricted group policies to lock down domain admins and enterprise admins, then configure system services and Windows Firewall via GPO for least privilege and consistent domain controller security.
Test your understanding of GPOs and security settings for Active Directory domain controllers, including the default domain controllers policy, custom GPOs, and auditing with advanced audit policy configuration.
Configure and verify domain controller security policies via group policy, including password length, audit settings, and event log size, then validate with gpupdate and event viewer.
Create and link a custom domain controller GPO to the domain controllers OU, configure restricted groups to control remote desktop access, and disable unnecessary services to strengthen security.
Perform hands-on domain controller security with advanced audit policy configuration and account management auditing. Enable security options, interactive logon messages, and Kerberos encryption enhancements on Windows Server 2025.
Learn to configure and verify domain controller security policies with group policy objects using GPMC, enforce minimum password length, audit event ID 4624 for logons, and apply restricted groups policies.
Create a new custom gpu for domain controllers to simplify rollback, improve organization, preserve default settings, enable granular applications, and support change management, per Microsoft's recommendations and processing order.
Learn why custom GPOs for domain controllers preserve settings, understand GPO processing order, and recognize when modifying the default policy is appropriate, with documentation aiding change management in Active Directory.
Centralize security settings for domain controllers via the domain controllers policy or a linked custom GPO in Domain Controllers OU, covering account, local, audit, firewall, PKI configurations for secure authentication.
Test your understanding of implementing secure authentication in a domain environment by analyzing two-factor authentication, elevated privilege groups, deprovisioning, ipsec, client security, and device health attestation.
Secure domain controllers by ensuring physical security and using raw DCs in less secure locations. Enforce BitLocker, monitor hot-swap disks, protect virtual disks, and store backups in secure locations.
Learn how to secure domain controllers through physical safeguards, protect credentials in Active Directory, and apply best practices for BitLocker, read-only domain controllers, backups, and disk security.
Learn how a read-only domain controller (rodc) authenticates branch office users locally. Note its limits: no operations master role, inbound replication only, and password replication policy.
Explore the role of read-only domain controllers in branch offices, including security benefits, authentication behavior, replication limits, and deployment considerations such as applications, facility security, and wan bandwidth.
Deploy a read-only domain controller (rodc) using the Active Directory Domain Services wizard remotely. Use two-stage deployment with pre-staging and delegated promotion for account creation and server attachment.
Plan and configure an RODC password replication policy by managing allowed and denied lists to control which users or computers' credentials are cached, including branch office and raw disk considerations.
Demonstrates staging a delegated rodc installation, viewing and configuring a rodc-specific password replication policy, and verifying the resultant policy across Active Directory sites, permissions, and groups such as Anna Cantrell.
Learn how to separate RODC local administration by delegating domain users or security groups as local administrators, enabling maintenance on an RODC without granting rights to other domain controllers.
Implement best practices to secure Active Directory by reducing the attack surface, enforcing least-privileged administration, securing domain controllers and admin hosts, and monitoring for breaches with comprehensive planning for compromises.
Explore best practices for securing Active Directory, including closing gaps in security updates and antivirus, enforcing least privilege, using secure administrative hosts, monitoring sensitive objects, and planning incident response.
Describe and configure Windows Server 2016+ account security, including password, lockout, Kerberos, authentication, PSR precedence, and resultant PSR with fine-grained policies, plus Windows Hello and Azure MFA.
Explore how user rights define system-level privileges and differentiate them from permissions, and learn to configure them with local security policy or group policy using least privilege.
Test your understanding of user rights versus permissions in Windows Server security. Learn how to manage system-wide privileges with Group Policy and Local Security Policy, applying the least privilege principle.
Apply least privilege, audit and document user rights, and use built-in groups to manage deny logon locally and logon through Remote Desktop Services on Windows Server.
Apply the least privilege principle by granting only needed rights. Audit and document user rights with PowerShell and Security Configuration and Analysis, control remote login, shutdown, and security logs access.
Configure and enforce robust password policies in AD DS, including history, age, length, complexity, and lockout settings, with group policy overrides and domain-wide applicability.
This knowledge check covers Active Directory password policies, including enforce password history, minimum password age, password complexity, domain-wide policy application, and recommended minimum length.
Set account lockout thresholds and durations to deter brute force attacks, with admin unlock and a 30-minute counter reset for failed sign-ins.
Explore how account lockout policies protect Active Directory by detecting and preventing brute-force attempts, and review key settings like threshold, duration, and counter resets for high-security environments.
Deploy and configure Kerberos policy settings across the domain using group policy to manage ticket lifetimes, TGTs, clock synchronization, and SSO authentication.
Explore how Kerberos policies secure domain authentication and enable single sign-on for domain users. Review enforce user logon restriction, service ticket lifetimes, claims and compound authentication, and time synchronization requirements.
Configure a domain-based password policy and an account lockout policy using Group Policy Management to enforce password history, age, length, and complexity settings; adjust lockout duration and counter reset.
Use restricted groups in Group Policy to enforce membership of local groups on servers and workstations, and review the protected users group introduced in Windows Server 2012 R2.
Explore restricted groups and protected users in Active Directory, and reinforce how membership control, authentication protocols, and encryption types secure critical accounts and local groups.
Define multiple fine-grained password policies in a single domain via password settings objects linked to users or groups; ensure domain functional level is at least Windows Server 2008.
Master the tools for creating fine grained password policies (PSOs) using PowerShell or Active Directory Administrative Center, configuring complexity, length, age, history, lockout settings, and linking policies to groups.
Explore fine-grained password policies in Active Directory by testing PSO settings such as password history, precedence, lockout behavior, and complexity requirements managed with AD tools.
Configure a fine-grained password policy named managers piezo in the Active Directory Administrative Center. Apply this policy to datum\\manager with precedence 10 and minimum length 15.
Link multiple pesos to users or groups; peso with the lowest MSDS password settings precedence becomes the resultant peso. If none linked, default domain policy applies; view MSDS resultant peso.
Explore how Active Directory resolves the effective PSOs for users and groups using MSDS password settings precedence and the MSDS resultant attribute, with viewing in Active Directory users and computers.
Protect domain accounts by enabling the Protected Users security group and configuring authentication policies with DEC claims, limiting local credential caching on domain member computers.
Explore protected users, authentication policies, and authentication policy silos in Active Directory, and test your understanding of Kerberos encryption, TGT lifetimes, and credential caching risks.
Configure local and domain user account policies via the local security policy console and group policy management, applying password, lockout, and kerberos settings under the default domain policy.
Explore configuring local and domain account policies in an Active Directory environment, covering local security policy, Group Policy precedence, Kerberos settings, and the default domain policy.
Configure auditing to track authentication events on Windows Server 2016 domain controllers, including account logon and logon events, and view security log entries to identify successful and failed attempts.
Explore the distinction between auditAccountLogonEvents and auditLogonEvents, and learn how basic and advanced audit policies control logon and logoff events across domain controllers and servers.
Configure authentication related audit policies with Group Policy Management Console, enable success and failure auditing, update policies with gpupdate, and verify events 4771 and 4768 in Event Viewer.
Scope gpo audit policies by linking logon event auditing to the ou with remote desktop servers. Audit account logon events across domain controllers using the default domain controllers gpo.
Explore how managed service accounts and group MSAs simplify authentication for applications and services in Windows, compare MSAs with standard accounts, and cover Kerberos delegation and SPNs.
Explore the use of built in local accounts for running services, including local system, local service, and network service, and assess security implications and considerations for service accounts.
Explore challenges of using service accounts for programs like SQL Server or IIS, including domain-based versus local accounts, password and SPN management, and MSAs in Windows Server 2016.
Discover managed service accounts, providing automatic password management and SP management for program-specific services, with domain functional level 2008 r2+ and route key setup on Windows Server 2016.
Group MSAs extend standard MSAs to multiple servers, enabling shared password management and SPN handling across a domain. They require a KDS root key and Windows Server 2012+ domain controllers.
Demonstrate configuring group MSAs by creating the domain root key on long DC1, creating and installing the service account, and setting it to a service like the data sharing service.
Enforce password and account lockout policies, and audit AD DS. Deploy rods for branch office authentication and implement password replication; configure a group MSA for a web app.
Implement security policies for accounts, passwords, and administrative groups in Active Directory, applying default domain policy, fine grained password policies, and restricted groups to IT admins.
Deploy and secure an Active Directory domain controller, configure password replication policies, implement read-only domain controller setup, and configure IIS to run under a managed service account.
Configure domain password policies with a PSO and high precedence for all users, linked to the domain user group, to centralize settings; use low precedence, like 10, for administrative PSOs.
Ensure physical security for domain controllers to protect all users, computers, and groups. Enable auditing for authentication and directory changes via the default domain controllers policy or a GPO.
Retire SMBv1 due to end-of-support risks and security weaknesses. Enable SMBv2/SMBv3 encryption and signing via PowerShell or Group Policy to protect data and prevent man-in-the-middle attacks.
Learn how to audit SMB v1 usage and block it with group policy, while exploring SMB v2/3 security, SMB signing, and encryption on shares.
Configure smb signing and encryption to prevent man-in-the-middle attacks by digitally signing packets, enforcing client and server signing, enabling encrypt data, and rejecting unencrypted access across shares.
Explore NTLM authentication protocols, including LMHash and NTLM version 1 and 2, and their vulnerability to pass-the-hash and brute-force attacks, plus how these hashes are stored in SAM and NTDS.
Audit ntlm usage via event 4624, enable deep domain auditing, then enforce ntlmv2 by adjusting network security settings and lan manager level, starting at 3, to phase out lm/ntlmv1 usage.
Configure NTLMv2 as default, allow a fallback to LAN manager and version one, then progressively refuse LAN manager up to level five, auditing devices and enabling Kerberos where possible.
From the domain admin machine, implement DNSSEC by signing the sectioncompany.primary zone and distributing trust anchors to DC2. Verify DNS lookups and enforce a NRPT policy to ensure DNSSEC usage.
Explore how to manage servers securely using Windows Admin Center, enabling centralized monitoring, threat protection, and update management. Integrate on-premises servers with Azure for monitoring, storage, backup, and disaster recovery.
Securely manage domain controllers and server core systems with Windows Admin Center, adding servers, extensions, PowerShell remoting, Azure integration, and remote desktop for administration.
Explore how AD DS functional levels unlock features like protected users, authentication policies and policy silos, and fine-grained password policies, and plan upgrades with rollback considerations and Azure integration.
Explore replication requirements and upgrade planning from Windows Server 2008 to 2016, migrating from FRS to DFS, and understand functional level rollback limitations and the database 32 pages optional feature.
Discover the keys to building a rock-solid IT security infrastructure with our comprehensive course, "Mastering Windows Security: Policies, Frameworks, and Virtualization". This in-depth training program is designed for IT professionals, security analysts, and system administrators who are looking to strengthen their skills and enhance their understanding of the essential components of IT security.
Throughout this course, you'll gain valuable insights into the process of creating and implementing robust security policies, standards, procedures, and guidelines to protect your organization's critical assets. You'll dive deep into the world of security frameworks and learn how to select and deploy the best-suited one for your organization's unique requirements.
But that's not all! Our course goes beyond the theoretical aspects of IT security and delves into real-world examples and best practices to ensure that you can practically apply what you've learned. We also cover the importance of hardware and virtualization security to provide you with a holistic understanding of the various layers of protection that are essential for a strong security posture.
With engaging lectures, assignments, and practical examples, you'll emerge from this course with the knowledge and confidence to build a comprehensive security baseline for your organization. Whether you're a seasoned IT professional or just starting in the field, this course is your one-stop resource for mastering IT security.
Enroll today and take the first step towards becoming an IT security expert, equipped with the skills and know-how to safeguard your organization against potential threats and vulnerabilities. Don't miss this opportunity to invest in your professional development and secure your organization's future.
Take Care Not to Miss Out!
Each second that passes without action on your part costs you valuable skills and knowledge.
Because this training comes with a money-back guarantee valid for thirty days, there is no danger in getting started right now.
Go ahead and click the button that says "take this course" to begin the process of expanding career opportunities right away!
Real Student Reviews:
★★★★★ “Very well explained and makes the concepts very easy to understand. Many thanks.” - Reina Wilson
★★★★★ “I am really enjoying this class. I am so grateful I found it. Thank you!” - Micel Jhon
★★★★★ “I learned many good things.” - Scott
★★★★★ “It is a structured presentation. Learned a lot from the lectures.” - Hamida
More than 120,000 students from over 150 different nations! This is incredible, and I want to thank everyone who supported me.