Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Secure Windows Server infrastructure

Microsoft via Microsoft Learn

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
  • Learn how to harden the security configuration of your Windows Server operating system environment. Secure administrative access to Privileged Access Workstations (PAWs), apply security baselines, and secure domain controllers and SMB traffic.

    After completing this module, you will be able to:

    • Manage local administrator passwords using Local Administrator Password Solution

    • Limit administrative access to Privileged Access Workstations (PAWs)

    • Explain how to secure domain controllers from being compromised

    • Describe how to use the Microsoft Security Compliance Toolkit to harden servers

    • Secure SMB traffic using SMB encryption

  • This module explores using Microsoft Defender for Endpoint to provide additional protection and monitor devices against threats.

    After this module, you should be able to:

    • Describe Microsoft Defender for Endpoint.

    • Describe key capabilities of Microsoft Defender for Endpoint.

    • Describe Microsoft Defender Application Guard.

    • Describe Microsoft Defender Exploit Guard.

    • Describe Windows Defender System Guard.

  • This module explains the built-in security features of Windows clients and how to implement them using policies.

    After this module, you should be able to:

    • Describe Windows Security capabilities
    • Describe Windows Defender Credential Guard
    • Manage Microsoft Defender Antivirus
    • Manage Windows Defender Firewall
    • Manage Windows Defender Firewall with Advanced Security
  • This module focuses on maintaining security in an Active Directory environment. It covers things from permissions management to authentication methods to identifying problematic accounts.

    By the end of this module, you'll be able to:

    • Configure user account rights.

    • Configure user account rights to restrict access.

    • Delegate permissions in Active Directory.

    • Protect User Accounts with the Protected Users group.

    • Describe Windows Defender Credential Guard.

    • Block Windows NTLM authentication.

    • Locate problematic accounts.

  • Protect your Active Directory environment by securing user accounts to least privilege and placing them in the Protected Users group. Learn how to limit authentication scope and remediate potentially insecure accounts.

    After completing this module, you'll be able to:

    • Configure and manage user accounts to limit security threats across an organization
    • Apply Protected Users settings, policies, and authentication silos to protect highly privileged user accounts
    • Describe and configure Windows Defender Credential Guard
    • Configure Group Policy to block the use of NTLM for authentication
  • This module focuses on effectively managing security controls in Microsoft Entra ID by securing identities, authentication, and authorization to protect users, groups, and external identities against threats while ensuring secure and seamless access to resources.

    By the end of this module, participants will be able to:

    • Secure user identities in Microsoft Entra ID by implementing strong authentication and access management controls.

    • Protect groups and access management by enforcing security measures to prevent unauthorized changes or misuse.

    • Manage external identities securely by defining policies that ensure confidentiality, integrity, and proper access control.

    • Implement Microsoft Entra ID Protection to detect, investigate, and mitigate identity-related security threats.

    • Apply Conditional Access policies to enforce security controls based on user behavior, device compliance, and contextual risks.

  • Learn security monitoring and governance with Microsoft Defender for Cloud, Azure Policy, resource locks, Microsoft Defender for Identity, and GitHub Advanced Security integration for comprehensive DevSecOps protection.

    By the end of this module, you're able to:

    • Implement pipeline security best practices and secure DevOps workflows.

    • Configure Microsoft Defender for Cloud for threat protection and compliance monitoring.

    • Create and manage Azure policies for governance and compliance enforcement.

    • Understand policy initiatives, resource locks, and governance frameworks.

    • Deploy Microsoft Defender for Identity threat detection.

    • Integrate GitHub Advanced Security with Microsoft Defender for Cloud.

    • Configure GitHub Advanced Security features including code scanning, secret scanning, and dependency scanning.

Syllabus

  • Hardening Windows Server
    • Introduction
    • Describe Local Password Administrator Solution
    • Configure Privileged Access Workstations
    • Secure domain controllers
    • Analyze security configuration with Security Compliance Toolkit
    • Secure SMB traffic
    • Module assessment
    • Summary and Resources
  • Manage Microsoft Defender for Endpoint
    • Introduction
    • Explore Microsoft Defender for Endpoint
    • Examine key capabilities of Microsoft Defender for Endpoint
    • Explore Windows Defender Application Control and Device Guard
    • Explore Microsoft Defender Application Guard
    • Examine Windows Defender Exploit Guard
    • Explore Windows Defender System Guard
    • Module assessment
    • Summary
  • Manage Microsoft Defender in Windows client
    • Introduction
    • Explore Windows Security Center
    • Explore Windows Defender Credential Guard
    • Manage Microsoft Defender Antivirus
    • Manage Windows Defender Firewall
    • Explore Windows Defender Firewall with Advanced Security
    • Module assessment
    • Summary
  • Manage security in Active Directory
    • Introduction
    • Configure user account rights
    • Configure user account rights to restrict access
    • Delegate permissions in Active Directory
    • Protect User Accounts with the Protected Users group
    • Describe Windows Defender Credential Guard
    • Block Windows NTLM authentication
    • Locate problematic accounts
    • Module assessment
    • Summary
  • Secure Windows Server user accounts
    • Introduction
    • Configure user account rights
    • Protect user accounts with the Protected Users group
    • Describe Windows Defender Credential Guard
    • Block NTLM authentication
    • Locate problematic accounts
    • Module assessment
    • Summary
  • Manage security controls for identity and access
    • Introduction
    • Microsoft cloud security benchmark: Identity management and privileged access
    • What is Microsoft Entra ID?
    • Secure Microsoft Entra users
    • Create a new user in Microsoft Entra ID
    • Secure Microsoft Entra groups
    • Recommend when to use external identities
    • Secure external identities
    • Implement Microsoft Entra Identity Protection
    • Microsoft Entra Connect
    • Microsoft Entra Cloud Sync
    • Authentication options
    • Password hash synchronization with Microsoft Entra ID
    • Microsoft Entra pass-through authentication
    • Federation with Microsoft Entra ID
    • What is Microsoft Entra authentication?
    • Implement multifactor authentication (MFA)
    • Kerberos authentication
    • New Technology Local Area Network Manager (NTLM)
    • Passwordless authentication options for Microsoft Entra ID
    • Implement passwordless authentication
    • Implement password protection
    • Microsoft Entra ID single sign-on
    • Implement single sign-on (SSO)
    • Integrate single sign-on (SSO) and identity providers
    • Introduction to Microsoft Entra Verified ID
    • Configure Microsoft Entra Verified ID
    • Recommend and enforce modern authentication protocols
    • Azure management groups
    • Configure Azure role permissions for management groups, subscriptions, resource groups, and resources
    • Azure role-based access control
    • Azure built-in roles
    • Assign Azure role permissions for management groups, subscriptions, resource groups, and resources
    • Microsoft Entra built-in roles
    • Assign built-in roles in Microsoft Entra ID
    • Microsoft Entra role-based access control
    • Create and assign a custom role in Microsoft Entra ID
    • Zero Trust security
    • Microsoft Entra Privileged Identity Management
    • Configure Privileged Identity Management
    • Microsoft Entra ID governance
    • Identity lifecycle management
    • Lifecycle workflows
    • Entitlement management
    • Delegation and roles in entitlement management
    • Access reviews
    • Configure role management and access reviews by using Microsoft Entra ID governance
    • Implement Conditional Access policies for Cloud Resources in Azure
    • Azure lighthouse overview
    • Module assessment
    • Summary
  • Security monitoring and governance
    • Introduction
    • Implement pipeline security
    • Explore Microsoft Defender for Cloud
    • Examine Microsoft Defender for Cloud usage scenarios
    • Explore Azure Policy
    • Understand policies
    • Explore initiatives
    • Explore resource locks
    • Understand Microsoft Defender for Identity
    • Integrate GitHub Advanced Security with Microsoft Defender for Cloud
    • Configure GitHub Advanced Security for GitHub and Azure DevOps
    • Module assessment
    • Summary

Reviews

Start your review of Secure Windows Server infrastructure

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.