We may earn an affiliate commission when you visit our partners.
Course image
John Christopher

We really hope you'll agree, this training is way more than the average course on Udemy.

Have access to the following:

  • Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer

  • Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material

  • Instructor led hands on and simulations to practice that can be followed even if you have little to no experience

  • Understanding the Microsoft 365 and Azure Environment

  • Read more

    We really hope you'll agree, this training is way more than the average course on Udemy.

    Have access to the following:

    • Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified Trainer

    • Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material

    • Instructor led hands on and simulations to practice that can be followed even if you have little to no experience

  • Understanding the Microsoft 365 and Azure Environment

  • A Solid Foundation of Active Directory Domains

  • A Solid Foundation of

  • High level overview of Microsoft Defender for Endpoint

  • Licensing and Plan Comparison (P1 vs P2)

  • Microsoft 365 Defender Portal Tour

  • How Defender for Endpoint relates to Microsoft Intune

  • Introduction to Microsoft Intune for device management

  • Setting Up Defender for Endpoint

    • Prerequisites and Supported Operating Systems

    • Creating a Microsoft Defender Admin role for permissions

    • Onboarding a Windows device to Defender for Endpoint

    • Mass automatic onboarding with Microsoft Intune

    • Verifying Windows devices have been onboarded

    • Implementing device discovery

    Defender for Endpoint Vulnerability Management

    • What are Common Vulnerabilities and Exposures (CVEs)?

    • Inspecting vulnerabilities on a specific device

    • Using the vulnerability management dashboard for high level overview

    • Improving security with the help of vulnerability recommendations

    • Utilizing remediation within vulnerability management

    • Creating and managing Device Groups for Defender for Endpoint

    Configuration and Policy Management

    • Hardening endpoint security by using Endpoint Security Policies

    • Attack Surface Reduction (ASR) Rules

    • What is Next-Gen Protection with Microsoft Defender for Endpoint?

    • Understanding the local anti-virus settings on Windows 11

    • Implementing Next-Gen Protection for devices

    • Understanding the local Defender Firewall settings on Windows 11

    • Implementing Firewall Rule Policies using Defender for Endpoint

    • Using Security Baselines in securing our devices

    Utilizing Microsoft Purview Endpoint DLP (Data Loss Prevention)

    • Understanding the concepts of DLP (Data Loss Prevention)

    • Considering device requirements before using Endpoint DLP

    • Settings for configuring Endpoint DLP

    • Configuring DLP policies with advanced rules

    • Enabling just-in-time (JIT) protection

    • How to monitor for endpoint activities

    Incident Response and Investigation

    • What is Automated Investigation and Remediation (AIR)?

    • Implementing Automated Investigation and Remediation (AIR) within device groups

    • Triggering incidents using a client device for testing

    • Investigating incidents generated by Defender managed devices

    • Viewing alerts generated by Defender managed devices

    • Managing and classifying detected alerts

    Kusto Query Language (KQL)

    • What is Kusto Query Language (KQL)?

    • Using the Microsoft KQL Demo environment, downloading resource materials and AI

    • Basic KQL syntax for searching for information

    • Summarizing KQL results and filtering based on time ranges

    • Controlling KQL data displayed based on columns, amounts and characters

    • Using KQL variables and combining output data

    • Running Threat Hunting Queries with Advanced Hunting (KQL)

    • Utilizing Microsoft's Sentinel and Defender repository of premade KQL Queries

    Enroll now

    What's inside

    Learning objectives

    • Learn the concepts and perform hands on activities needed to master microsoft defender for endpoint
    • Gain a tremendous amount of knowledge involving microsoft defender for endpoint
    • Learn using hands on simulations on how microsoft defender for endpoint is administered!
    • Learn how to set up your own test lab for practicing the concepts!

    Syllabus

    Introduction
    Welcome to the course!
    Understanding the Microsoft 365 and Azure Environment
    A Solid Foundation of Active Directory Domains
    Read more

    Save this course

    Create your own learning path. Save this course to your list so you can find it easily later.
    Save

    Activities

    Coming soon We're preparing activities for Microsoft Defender for Endpoint course with hands on sims. These are activities you can do either before, during, or after a course.

    Career center

    Learners who complete Microsoft Defender for Endpoint course with hands on sims will develop knowledge and skills that may be useful to these careers:

    Reading list

    We haven't picked any books for this reading list yet.
    Provides a CLI reference for Microsoft Defender for Endpoint. It covers everything from CLI commands to CLI syntax. It is written by the Microsoft team and valuable resource for anyone who wants to manage this security tool from the command line.
    Covers the threat intelligence capabilities of Microsoft Defender for Endpoint. It provides detailed information on how to use the product's features to gather and analyze threat intelligence.
    Covers the incident response capabilities of Microsoft Defender for Endpoint. It provides detailed information on how to use the product's features to respond to and investigate security incidents.
    Comprehensive guide to Microsoft Defender for Endpoint, covering everything you need to know to get started with this powerful security solution.
    Provides a PowerShell reference for Microsoft Defender for Endpoint. It covers everything from PowerShell cmdlets to PowerShell syntax. It is written by the Microsoft team and valuable resource for anyone who wants to manage this security tool from PowerShell.
    Comprehensive guide to using Microsoft Defender for Endpoint to protect cloud environments. It provides a number of step-by-step examples that show how to use Microsoft Defender for Endpoint to detect and respond to threats in the cloud.
    Provides an API reference for Microsoft Defender for Endpoint. It covers everything from API functionality to API syntax. It is written by the Microsoft team and valuable resource for anyone who wants to develop applications that integrate with this security tool.
    Provides a comprehensive guide to endpoint security for cloud environments, covering topics such as malware detection, prevention, and response. It valuable resource for anyone responsible for securing endpoints in the cloud.
    Provides a comprehensive guide to endpoint security for mobile devices, covering topics such as malware detection, prevention, and response. It valuable resource for anyone responsible for securing mobile endpoints.
    Provides a comprehensive guide to endpoint security for MacOS, covering topics such as malware detection, prevention, and response. It valuable resource for anyone responsible for securing MacOS endpoints.
    Provides a comprehensive guide to endpoint security for Linux, covering topics such as malware detection, prevention, and response. It valuable resource for anyone responsible for securing Linux endpoints.
    Classic in the field of incident detection and response, which is closely related to endpoint security monitoring. It teaches how to use network security monitoring to enhance an organization's security posture. While not strictly about endpoints, the principles and techniques discussed are highly relevant to understanding how endpoint activity can be monitored and analyzed for threats.
    Provides a basic overview of endpoint security, covering topics such as malware detection, prevention, and response. It good resource for anyone new to endpoint security.
    Provides a comprehensive and proven approach to securing network endpoints. It covers a wide range of endpoint devices and offers strategies to prevent and eliminate network contamination. It's a valuable reference for understanding the foundational concepts of endpoint security and different endpoint types.
    Offers comprehensive insights into Microsoft Defender for Endpoint, a leading cross-platform endpoint security solution. It covers the product's history, features, deployment, and operationalization. It is particularly relevant for organizations using or planning to use Microsoft's security stack and provides practical guidance for security professionals and incident responders.
    Must-read for anyone interested in EDR. It covers the basics of endpoint security and the importance of EDR, then dives into advanced areas like EDR architecture and popular tools. It includes real-world case studies and best practices, making it valuable for both beginners and experienced professionals.
    Delves into the challenges of balancing security and usability in endpoint protection. It provides practical recommendations and tips for successful implementation of endpoint security measures. This book is particularly useful for professionals involved in designing and deploying security solutions.
    While not solely focused on endpoints, this book provides a broad understanding of network security threats and countermeasures, which is foundational for understanding endpoint security in a larger context. It covers various attack techniques and how to defend against them. valuable reference for gaining a wider perspective on cybersecurity.
    Provides a layered approach to endpoint security, covering topics such as network security, host security, and application security. It valuable resource for anyone looking to implement a comprehensive endpoint security solution.
    Provides a detailed guide to endpoint protection, covering topics such as malware detection, prevention, and response. It valuable resource for anyone responsible for securing endpoints.

    Share

    Help others find this course page by sharing it with your friends and followers:

    Similar courses

    Similar courses are unavailable at this time. Please try again later.
    Our mission

    OpenCourser helps millions of learners each year. People visit us to learn workspace skills, ace their exams, and nurture their curiosity.

    Our extensive catalog contains over 50,000 courses and twice as many books. Browse by search, by topic, or even by career interests. We'll match you to the right resources quickly.

    Find this site helpful? Tell a friend about us.

    Affiliate disclosure

    We're supported by our community of learners. When you purchase or subscribe to courses and programs or purchase books, we may earn a commission from our partners.

    Your purchases help us maintain our catalog and keep our servers humming without ads.

    Thank you for supporting OpenCourser.

    © 2016 - 2025 OpenCourser