The Defender Certification Training Course is a comprehensive cybersecurity program designed to provide participants with the knowledge and practical skills required to protect enterprise environments using the Microsoft Defender security ecosystem.
The course covers core capabilities across Microsoft Defender technologies, including endpoint protection, identity protection, email and collaboration security, cloud application security, vulnerability management, threat detection, incident investigation, and automated response. Participants will learn how Microsoft Defender integrates with the broader Microsoft security environment to provide centralized visibility and coordinated protection against modern cyber threats.
The training is suitable for cybersecurity professionals preparing for Microsoft security certification pathways or professionals responsible for implementing, administering, monitoring, and operating Microsoft Defender solutions in enterprise environments. certification pathways.
Duration 5 Days – 35 hrs.
Objectives
- Understand the Microsoft Defender security ecosystem and its major components.
- Explain modern cybersecurity threats and Microsoft’s approach to threat protection.
- Configure and manage Microsoft Defender for Endpoint.
- Implement endpoint security policies and attack surface reduction controls.
- Configure endpoint detection and response capabilities.
- Perform vulnerability and exposure management.
- Protect identities and investigate identity-based threats.
- Understand Microsoft Defender for Identity capabilities.
- Configure protection for email and collaboration environments.
- Understand Microsoft Defender for Office 365 security capabilities.
- Identify threats involving cloud applications and services.
- Understand Microsoft Defender for Cloud Apps.
- Use Microsoft Defender XDR for centralized threat detection and investigation.
- Investigate security alerts, incidents, users, devices, and other affected assets.
- Perform advanced threat hunting using security data.
- Apply automated investigation and response capabilities.
- Understand threat intelligence and indicators of compromise.
- Strengthen an organization’s overall security posture using Microsoft Defender.
- Apply Defender capabilities to common enterprise cybersecurity scenarios.
- Prepare for further study toward relevant Microsoft security certification pathways.
Target Audience
- Cybersecurity Analysts
- Security Operations Center (SOC) Analysts
- Security Engineers
- Security Administrators
- Microsoft 365 Administrators
- Endpoint Administrators
- Systems Administrators
- Network and Infrastructure Administrators
- Incident Response Professionals
- Threat Hunters
- IT Security Specialists
- Cloud Security Professionals
- IT Professionals responsible for Microsoft security environments
- Professionals preparing for Microsoft security certification examinations
Prerequisites
- Basic knowledge of cybersecurity concepts and terminology.
- Familiarity with common security threats, vulnerabilities, and attack techniques.
- Basic understanding of Microsoft Windows and endpoint administration.
- General understanding of Microsoft 365 and cloud services.
- Basic knowledge of identity and access management concepts.
- Familiarity with networking concepts such as TCP/IP, DNS, firewalls, and network security.
- Basic understanding of Microsoft Entra ID is beneficial.
Course Outline
Day 1 – Microsoft Defender and Modern Threat Protection
Module 1: Cybersecurity and Modern Threat Landscape
- Current cybersecurity threat landscape
- Common attack vectors and techniques
- Malware, ransomware, phishing, and credential attacks
- Identity-based and endpoint-based threats
- Principles of Zero Trust security
- Defense-in-depth security strategy
Module 2: Introduction to Microsoft Defender
- Microsoft security ecosystem overview
- Microsoft Defender architecture
- Understanding Microsoft Defender XDR
- Defender security components and services
- Security signals and telemetry
- Integration across endpoints, identities, email, applications, and cloud environments
Module 3: Microsoft Defender Portal
- Navigating the Defender portal
- Security dashboards
- Alerts and incidents
- Assets and inventories
- Reports and security information
- Security recommendations
- Understanding security roles and permissions
Module 4: Security Posture and Exposure Management
- Understanding security posture
- Identifying organizational exposure
- Security recommendations
- Vulnerability prioritization
- Reducing attack surfaces
- Tracking remediation activities
Day 2 – Microsoft Defender for Endpoint
Module 5: Introduction to Microsoft Defender for Endpoint
- Defender for Endpoint architecture
- Endpoint security capabilities
- Device onboarding concepts
- Supported endpoints
- Device inventory
- Endpoint security configuration
Module 6: Endpoint Protection and Attack Surface Reduction
- Antivirus and antimalware protection
- Cloud-delivered protection
- Attack surface reduction rules
- Network protection
- Web protection
- Controlled folder access
- Device control concepts
- Security policy configuration
Module 7: Endpoint Detection and Response
- Understanding EDR
- Endpoint behavioral monitoring
- Alert generation
- Device timelines
- Process and event investigation
- Evidence collection
- Device isolation
- Response actions
Module 8: Vulnerability Management
- Discovering vulnerabilities
- Software inventory
- Security recommendations
- Vulnerability prioritization
- Remediation workflows
- Monitoring remediation progress
Day 3 – Identity, Email, Collaboration, and Cloud Application Protection
Module 9: Microsoft Defender for Identity
- Identity threat protection concepts
- Defender for Identity architecture
- Identity security monitoring
- Detecting suspicious identity activities
- Compromised account investigation
- Identity-related alerts
- Lateral movement and credential attack detection
Module 10: Microsoft Defender for Office 365
- Email and collaboration security
- Anti-phishing protection
- Anti-malware protection
- Safe Attachments
- Safe Links
- Threat protection policies
- Email investigation
- Campaign and phishing attack analysis
Module 11: Microsoft Defender for Cloud Apps
- Cloud application security concepts
- Cloud application discovery
- Application risk assessment
- User and application monitoring
- Cloud security policies
- Detecting anomalous behavior
- Managing risky cloud applications
Module 12: Coordinated Threat Protection
- Correlating endpoint, identity, email, and application signals
- Cross-domain attack detection
- Understanding attack chains
- Identifying compromised users and devices
- Coordinated response across Microsoft Defender services
Day 4 – Microsoft Defender XDR, Incident Investigation, and Response
Module 13: Microsoft Defender XDR
- Defender XDR architecture
- Unified security operations
- Alerts and incident correlation
- Incident queues
- Incident prioritization
- Understanding affected assets
- Attack story visualization
Module 14: Security Incident Investigation
- Reviewing security incidents
- Analyzing alerts
- Investigating users
- Investigating devices
- Investigating mailboxes and applications
- Reviewing evidence and entities
- Determining incident scope and impact
Module 15: Incident Response
- Security response processes
- Device response actions
- User response actions
- File investigation and remediation
- Device isolation
- Blocking malicious indicators
- Incident containment
- Recovery considerations
Module 16: Automated Investigation and Response
- Automated investigation concepts
- Investigation packages
- Automated remediation
- Reviewing pending actions
- Approving or rejecting remediation actions
- Automation levels
- Improving SOC operational efficiency
Day 5 – Threat Hunting, Threat Intelligence, and Certification Preparation
Module 17: Advanced Hunting
- Introduction to threat hunting
- Advanced hunting architecture
- Understanding Defender security data
- Introduction to Kusto Query Language concepts
- Querying security events
- Hunting across devices and users
- Investigating suspicious activities
- Building reusable hunting queries
Module 18: Threat Intelligence and Indicators
- Threat intelligence fundamentals
- Indicators of compromise
- Managing security indicators
- IP, URL, domain, certificate, and file indicators
- Threat intelligence investigation
- Applying intelligence to security operations
Module 19: Security Operations and Defender Best Practices
- Security monitoring best practices
- Alert prioritization
- Incident management practices
- Reducing alert fatigue
- Security policy optimization
- Improving endpoint and identity security posture
- Defender operational considerations
- Continuous security improvement
Module 20: Integrated Microsoft Defender Security Scenarios
- Phishing-to-endpoint compromise scenario
- Identity compromise scenario
- Malware and ransomware investigation
- Suspicious endpoint activity investigation
- Cross-domain incident analysis
- Threat containment and remediation
- Security posture improvement scenarios
Module 21: Certification Review and Preparation
- Review of Microsoft Defender concepts
- Review of major Defender security capabilities
- Key security operations concepts
- Endpoint, identity, email, and application protection review
- Incident investigation and response review
- Threat hunting concepts
- Certification-style scenario review
- Recommended areas for further study

