Course Name
Course Code : BYS96
Venue Details
Postal Code : 1109
Session Dates
Duration: 3 days (21 hours)
This hands-on training on Microsoft Defender by Microsoft is designed to help IT professionals, security administrators, SOC analysts, and cybersecurity teams build expertise in modern endpoint protection, threat detection, vulnerability management, attack investigation, and automated incident response. Participants will gain practical experience in configuring security policies, onboarding endpoints, monitoring threats, investigating incidents, and integrating Defender with enterprise security ecosystems. The program covers real-world cyber defense strategies using Defender for Endpoint, Defender XDR, threat analytics, vulnerability management, and automated remediation workflows.
• Introduction to Microsoft Defender security ecosystem
• Defender product family, licensing models, and architecture overview
• Defender portal navigation, security roles, and administrative permissions
• Tenant preparation and deployment prerequisites
• Endpoint onboarding for Windows, macOS, Linux, Android, and iOS devices
• Device groups, tagging, and asset organization
• Antivirus configuration, EDR setup, and real-time protection
• Cloud-delivered protection and tamper protection implementation
• Security baselines and initial hardening practices
• Alert generation, detection mechanisms, and threat analytics
• Incident correlation, classification, and prioritization
• Attack surface reduction rules and policy implementation
• Device control, application control, and web protection policies
• Investigation timelines, evidence collection, and root cause analysis
• Threat intelligence integration and IOC management
• Introduction to advanced hunting concepts
• Kusto Query Language (KQL) fundamentals
• Device events, user activity, and suspicious behavior analysis
• Vulnerability assessment and exposure management
• Software inventory, security recommendations, and remediation workflows
• Risk scoring and remediation prioritization
• Automated investigation and response workflows
• Device isolation, file quarantine, and containment actions
• Defender XDR architecture and cross-domain threat correlation
• Integration with Microsoft Sentinel and enterprise security tools
• Security dashboards, compliance reporting, and executive reporting
• Enterprise incident response simulation
Hands-on Exercises
Summary and Conclusion
Mode of Delivery : The event can be attended both online and at nearby ProgNXT classroom by Individual Professionals and Corporate Employees as per the seat availability. Please Contact Us at [email protected] for checking the seat availability
Audience : We have a global audience that logs in to using their own computers to work hand in hand with our world-class instructors.
Assessment : Each training course will have ProgNXT Assessment at the end.
Certification : After successful passing of ProgNXT Assessment, ProgNXT Certification will be provided, which has got acceptance in 55+ Countries.
| Global Region | Location | Start Date | End Date | Action |
|---|---|---|---|---|
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |