- Learn how to harden the Windows Server operating system using LAPS for local admin password management, Privileged Access Workstations (PAWs), domain controller hardening with Server Core and BitLocker, security baselines with the Microsoft Security Compliance Toolkit, and SMB encryption.
After completing this module, you will be able to:
Manage local administrator passwords using Local Administrator Password Solution
Limit administrative access to Privileged Access Workstations (PAWs)
Explain how to secure domain controllers from being compromised
Describe how to use the Microsoft Security Compliance Toolkit to harden servers
Secure SMB traffic using SMB encryption
- This module explores using Microsoft Defender for Endpoint to provide additional protection and monitor devices against threats.
After this module, you should be able to:
Describe Microsoft Defender for Endpoint.
Describe key capabilities of Microsoft Defender for Endpoint.
Describe Microsoft Defender Application Guard.
Describe Microsoft Defender Exploit Guard.
Describe Windows Defender System Guard.
- This module explains the built-in security features of Windows clients and how to implement them using policies.
After this module, you should be able to:
- Describe Windows Security capabilities
- Describe Windows Defender Credential Guard
- Manage Microsoft Defender Antivirus
- Manage Windows Defender Firewall
- Manage Windows Defender Firewall with Advanced Security
- Learn how to configure, audit, and manage Group Policy Security Settings in Active Directory environments.
By the end of this module, you're able to:
- Describe how Group Policy security settings are structured, processed, and targeted, and select the right tool to author and test them.
- Configure Account Policies (password, lockout, and Kerberos) and explain the domain-scope rule and fine-grained password policies.
- Assign user rights and configure security options to enforce least privilege and harden authentication.
- Configure auditing, secure group membership, services, registry, file system, and event logs.
- Deploy network and application security policies, and manage security settings at scale with the Windows Server 2025 OSConfig baseline.
- Learn how to manage security in Active Directory, including configuring user rights with least privilege, delegating permissions, using the Protected Users group and Credential Guard, blocking NTLM authentication, and finding problematic accounts.
By the end of this module, you'll be able to:
Configure user account rights.
Configure user account rights to restrict access.
Delegate permissions in Active Directory.
Protect User Accounts with the Protected Users group.
Describe Windows Defender Credential Guard.
Block Windows NTLM authentication.
Locate problematic accounts.
- Describe the purpose and common problems of Windows Server service accounts, and select and configure the correct local or managed account type, including the Windows Server 2025 delegated Managed Service Account (dMSA).
By the end of this module, you're able to:
- Describe the purpose of Windows Server service accounts and the common problems associated with them.
- Identify and configure the local service account types.
- Compare the managed service account types (sMSA, gMSA, and dMSA) and select the correct one for a workload.
- Learn how to secure Active Directory user accounts using least privilege, Protected Users group, authentication policy silos, Windows Defender Credential Guard, NTLM blocking, and account remediation techniques.
After completing this module, you'll be able to:
- Configure and manage user accounts to limit security threats across an organization
- Apply Protected Users settings, policies, and authentication silos to protect highly privileged user accounts
- Describe and configure Windows Defender Credential Guard
- Configure Group Policy to block the use of NTLM for authentication
- This module focuses on effectively managing security controls in Microsoft Entra ID by securing identities, authentication, and authorization to protect users, groups, and external identities against threats while ensuring secure and seamless access to resources.
By the end of this module, participants will be able to:
Secure user identities in Microsoft Entra ID by implementing strong authentication and access management controls.
Protect groups and access management by enforcing security measures to prevent unauthorized changes or misuse.
Manage external identities securely by defining policies that ensure confidentiality, integrity, and proper access control.
Implement Microsoft Entra ID Protection to detect, investigate, and mitigate identity-related security threats.
Apply Conditional Access policies to enforce security controls based on user behavior, device compliance, and contextual risks.
- Learn security monitoring and governance with Microsoft Defender for Cloud, Azure Policy, resource locks, Microsoft Defender for Identity, and GitHub Advanced Security integration for comprehensive DevSecOps protection.
By the end of this module, you're able to:
Implement pipeline security best practices and secure DevOps workflows.
Configure Microsoft Defender for Cloud for threat protection and compliance monitoring.
Create and manage Azure policies for governance and compliance enforcement.
Understand policy initiatives, resource locks, and governance frameworks.
Deploy Microsoft Defender for Identity threat detection.
Integrate GitHub Advanced Security with Microsoft Defender for Cloud.
Configure GitHub Advanced Security features including code scanning, secret scanning, and dependency scanning.
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Learn Backend Development Part-Time, Online
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Syllabus
- Hardening Windows Server
- Introduction
- Describe Local Password Administrator Solution
- Configure Privileged Access Workstations
- Secure domain controllers
- Analyze security configuration with Security Compliance Toolkit
- Secure SMB traffic
- Module assessment
- Summary and Resources
- Manage Microsoft Defender for Endpoint
- Introduction
- Explore Microsoft Defender for Endpoint
- Examine key capabilities of Microsoft Defender for Endpoint
- Explore Windows Defender Application Control and Device Guard
- Explore Microsoft Defender Application Guard
- Examine Windows Defender Exploit Guard
- Explore Windows Defender System Guard
- Module assessment
- Summary
- Manage Microsoft Defender in Windows client
- Introduction
- Explore Windows Security Center
- Explore Windows Defender Credential Guard
- Manage Microsoft Defender Antivirus
- Manage Windows Defender Firewall
- Explore Windows Defender Firewall with Advanced Security
- Module assessment
- Summary
- Understand Active Directory Group Policy security settings
- Introduction
- Configure account policies
- Assign user rights
- Configure security options
- Configure audit policy
- Secure groups, services, registry, files, and logs
- Deploy network and application security policies
- Design, deploy, and manage security settings at scale
- Knowledge check
- Summary
- Manage security in Active Directory
- Introduction
- Configure user account rights
- Configure user account rights to restrict access
- Delegate permissions in Active Directory
- Protect User Accounts with the Protected Users group
- Describe Windows Defender Credential Guard
- Block Windows NTLM authentication
- Locate problematic accounts
- Module assessment
- Summary
- Understand Windows Server service accounts
- Introduction
- Understand local service account types
- Understand managed service account types
- Service account best practices
- Knowledge check
- Summary
- Secure Windows Server user accounts
- Introduction
- Configure user account rights
- Protect user accounts with the Protected Users group
- Describe Windows Defender Credential Guard
- Block NTLM authentication
- Locate problematic accounts
- Module assessment
- Summary
- Manage security controls for identity and access
- Introduction
- Microsoft cloud security benchmark: Identity management and privileged access
- What is Microsoft Entra ID?
- Secure Microsoft Entra users
- Create a new user in Microsoft Entra ID
- Secure Microsoft Entra groups
- Recommend when to use external identities
- Secure external identities
- Implement Microsoft Entra Identity Protection
- Microsoft Entra Connect
- Microsoft Entra Cloud Sync
- Authentication options
- Password hash synchronization with Microsoft Entra ID
- Microsoft Entra pass-through authentication
- Federation with Microsoft Entra ID
- What is Microsoft Entra authentication?
- Implement multifactor authentication (MFA)
- Kerberos authentication
- New Technology Local Area Network Manager (NTLM)
- Passwordless authentication options for Microsoft Entra ID
- Implement passwordless authentication
- Implement password protection
- Microsoft Entra ID single sign-on
- Implement single sign-on (SSO)
- Integrate single sign-on (SSO) and identity providers
- Introduction to Microsoft Entra Verified ID
- Configure Microsoft Entra Verified ID
- Recommend and enforce modern authentication protocols
- Azure management groups
- Configure Azure role permissions for management groups, subscriptions, resource groups, and resources
- Azure role-based access control
- Azure built-in roles
- Assign Azure role permissions for management groups, subscriptions, resource groups, and resources
- Microsoft Entra built-in roles
- Assign built-in roles in Microsoft Entra ID
- Microsoft Entra role-based access control
- Create and assign a custom role in Microsoft Entra ID
- Zero Trust security
- Microsoft Entra Privileged Identity Management
- Configure Privileged Identity Management
- Microsoft Entra ID governance
- Identity lifecycle management
- Lifecycle workflows
- Entitlement management
- Delegation and roles in entitlement management
- Access reviews
- Configure role management and access reviews by using Microsoft Entra ID governance
- Implement Conditional Access policies for Cloud Resources in Azure
- Azure lighthouse overview
- Module assessment
- Summary
- Security monitoring and governance
- Introduction
- Implement pipeline security
- Explore Microsoft Defender for Cloud
- Examine Microsoft Defender for Cloud usage scenarios
- Explore Azure Policy
- Understand policies
- Explore initiatives
- Explore resource locks
- Understand Microsoft Defender for Identity
- Integrate GitHub Advanced Security with Microsoft Defender for Cloud
- Configure GitHub Advanced Security for GitHub and Azure DevOps
- Module assessment
- Summary