Microsoft Defender Fundamentals, Deployment & Endpoint Protection
• Introduction to Microsoft Defender security ecosystem
• Defender product family, licensing models, and architecture overview
• Defender portal navigation, security roles, and administrative permissions
• Tenant preparation and deployment prerequisites
• Endpoint onboarding for Windows, macOS, Linux, Android, and iOS devices
• Device groups, tagging, and asset organization
• Antivirus configuration, EDR setup, and real-time protection
• Cloud-delivered protection and tamper protection implementation
• Security baselines and initial hardening practices
Threat Protection, Investigation & Advanced Hunting
• Alert generation, detection mechanisms, and threat analytics
• Incident correlation, classification, and prioritization
• Attack surface reduction rules and policy implementation
• Device control, application control, and web protection policies
• Investigation timelines, evidence collection, and root cause analysis
• Threat intelligence integration and IOC management
• Introduction to advanced hunting concepts
• Kusto Query Language (KQL) fundamentals
• Device events, user activity, and suspicious behavior analysis
Vulnerability Management, Automation & Enterprise Security Operations
• Vulnerability assessment and exposure management
• Software inventory, security recommendations, and remediation workflows
• Risk scoring and remediation prioritization
• Automated investigation and response workflows
• Device isolation, file quarantine, and containment actions
• Defender XDR architecture and cross-domain threat correlation
• Integration with Microsoft Sentinel and enterprise security tools
• Security dashboards, compliance reporting, and executive reporting
• Enterprise incident response simulation
Hands-on Exercises
Summary and Conclusion