Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Secure Windows Server on-premises and hybrid infrastructures

Microsoft via Microsoft Learn

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
  • Learn how to implement network security for Windows Server IaaS VMs using network security groups (NSGs), Azure Firewall, Windows Defender Firewall, and Azure Network Watcher for traffic capture and flow logging.

    After completing this module, you'll be able to:

    • Implement Network Security Groups (NSGs) with Windows Server IaaS VMs.

    • Implement adaptive network hardening.

    • Implement Azure Firewall.

    • Implement Windows Defender Firewall in Windows Server IaaS VMs.

    • Choose an appropriate filtering solution.

    • Capture network traffic with Network Watcher.

  • Learn about Microsoft Defender for Cloud and how to onboard Windows Server computers to Defender for Servers by using Azure Arc. Also learn about Microsoft Sentinel, security information and event management (SIEM), and security orchestration, automation, and response (SOAR).

    After completing this module, you'll be able to:

    • Describe Microsoft Defender for Cloud.
    • Enable Defender for Servers in hybrid environments.
    • Onboard Windows Server computers to Defender for Servers by using Azure Arc.
    • Implement and assess security policies.
    • Describe Microsoft Sentinel.
    • Implement SIEM and SOAR.
    • Protect your resources with JIT VM access.
  • Learn how to assess and deploy updates to Azure virtual machines and Azure Arc-enabled servers by using Azure Update Manager.

    After completing this module, you can:

    • Describe Azure Update Manager.
    • Prepare Azure virtual machines and Azure Arc-enabled servers for update management.
    • Assess update compliance.
    • Deploy one-time and recurring updates.
    • Monitor update operations across multiple machines.
  • Configure BitLocker disk encryption for Windows IaaS Virtual Machines

    After completing this module, you'll be able to:

    • Describe Azure Disk Encryption.
    • Configure Key Vault to support Azure Disk Encryption.
    • Explain how to encrypt Azure IaaS VM hard disks.
    • Back up and recover encrypted data from IaaS VM hard disks.
  • Implement change tracking and file integrity monitoring for Windows IaaS VMs

    After completing this module, you'll be able to:

    • Implement Change Tracking and Inventory
    • Manage Change Tracking and Inventory
    • Manage tracked files
    • Implement File Integrity Monitoring
    • Select and monitor entities
    • Use File Integrity Monitoring
  • Learn how to secure Windows Server DNS using split-horizon DNS, DNS policies for traffic management and geo-location routing, DNS cache locking, DNS socket pool, and DNSSEC for cryptographic zone signing.

    After completing this module, you'll be able to:

    • Describe split-horizon DNS and explain how to implement it.
    • Create DNS policies.
    • Implement DNS policies.
    • Describe the options for protecting the DNS server role.
    • Implement DNS security.
  • Learn how to secure Active Directory user accounts using least privilege, Protected Users group, authentication policy silos, Windows Defender Credential Guard, NTLM blocking, and account remediation techniques.

    After completing this module, you'll be able to:

    • Configure and manage user accounts to limit security threats across an organization
    • Apply Protected Users settings, policies, and authentication silos to protect highly privileged user accounts
    • Describe and configure Windows Defender Credential Guard
    • Configure Group Policy to block the use of NTLM for authentication
  • Learn how to harden the Windows Server operating system using LAPS for local admin password management, Privileged Access Workstations (PAWs), domain controller hardening with Server Core and BitLocker, security baselines with the Microsoft Security Compliance Toolkit, and SMB encryption.

    After completing this module, you will be able to:

    • Manage local administrator passwords using Local Administrator Password Solution

    • Limit administrative access to Privileged Access Workstations (PAWs)

    • Explain how to secure domain controllers from being compromised

    • Describe how to use the Microsoft Security Compliance Toolkit to harden servers

    • Secure SMB traffic using SMB encryption

  • Learn how to deploy and manage Windows Server Update Services (WSUS) for centralized update management, including deployment topologies, computer groups, and integration with Azure Automation Update Management for hybrid environments.

    After completing this module, you'll be able to:

    • Describe the role of Windows Server Update Services (WSUS)
    • Describe the WSUS update management process
    • Deploy updates with WSUS

Syllabus

  • Implement Windows Server IaaS VM network security
    • Introduction
    • Implement network security groups and Windows IaaS VMs
    • Implement Azure Firewall and Windows IaaS VMs
    • Implement Windows Firewall with Windows Server IaaS VMs
    • Choose the appropriate filtering solution
    • Deploy and configure Azure firewall using the Azure portal
    • Capture network traffic with network watcher
    • Log network traffic to and from a VM using the Azure portal
    • Module assessment
    • Summary
  • Audit the security of Windows Server IaaS Virtual Machines
    • Introduction
    • Describe Microsoft Defender for Cloud
    • Enable Defender for Servers in hybrid environments
    • Implement and assess security policies
    • Protect your resources with JIT VM access
    • Implement Microsoft Sentinel
    • Module assessment
    • Summary
  • Manage Azure updates
    • Introduction
    • Describe Azure Update Manager
    • Prepare machines for Azure Update Manager
    • Deploy updates
    • Assess updates
    • Manage updates at scale
    • Module assessment
    • Summary
  • Configure BitLocker disk encryption for Windows IaaS Virtual Machines
    • Introduction
    • Describe Azure Disk Encryption and server-side encryption
    • Configure Key Vault for Azure Disk Encryption
    • Encrypt Azure IaaS Virtual Machine hard disks
    • Back up and recover data from encrypted disks
    • Create and encrypt a Windows Virtual Machine
    • Module assessment
    • Summary
  • Implement change tracking and file integrity monitoring for Windows IaaS VMs
    • Introduction
    • Implement Change Tracking and Inventory
    • Manage Change Tracking and Inventory
    • Manage tracked files
    • Implement File Integrity Monitoring
    • Select and monitor entities
    • Use File Integrity Monitoring
    • Module assessment
    • Summary
  • Secure Windows Server DNS
    • Introduction
    • Implement split-horizon DNS
    • Create DNS policies
    • Implement DNS policies
    • Secure Windows Server DNS
    • Implement DNSSEC
    • Module assessment
    • Summary
  • Secure Windows Server user accounts
    • Introduction
    • Configure user account rights
    • Protect user accounts with the Protected Users group
    • Describe Windows Defender Credential Guard
    • Block NTLM authentication
    • Locate problematic accounts
    • Module assessment
    • Summary
  • Hardening Windows Server
    • Introduction
    • Describe Local Password Administrator Solution
    • Configure Privileged Access Workstations
    • Secure domain controllers
    • Analyze security configuration with Security Compliance Toolkit
    • Secure SMB traffic
    • Module assessment
    • Summary and Resources
  • Windows Server update management
    • Introduction
    • Explore Windows Update
    • Outline Windows Server Update Services server deployment options
    • Define Windows Server Update Services update management process
    • Describe the process of Update Management
    • Module assessment
    • Summary

Reviews

Start your review of Secure Windows Server on-premises and hybrid infrastructures

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.