Microsoft Defender course/training: Learn how to use Microsoft Defender

preview_player
Показать описание
Watch this video to learn information on how to use and manage Microsoft Defender

CONCEPTS COVERERED IN THIS VIDEO:

Microsoft 365 Defender as an Extended Detection and Response (XDR)

*Visualizing the concepts of extended detection and responses (XDR)
*Configuring the Microsoft 365 Defender simulation lab
*Performing an attack using the simulation lab
*Microsoft 365 Defender incidents and automated investigations
*Microsoft 365 Defender action and submissions
*Using Kusto Query Language (KQL) for threat identification
*Microsoft Secure Score
*Microsoft 365 Defender threat analytics
*Custom detections and alerts

Getting started w/ Defender for Cloud,Defender for Servers & Defender for DevOps

*Introduction to Microsoft Defender for Cloud
*Regulatory compliance policies along with MCSB
*Remediations with secure score in Microsoft Defender for Cloud
*Microsoft Defender for Servers
*Microsoft Defender for DevOps
*Microsoft Defender External Attack Surface Management (EASM)

Basic concepts of the Microsoft Defender Suite and Services

*The Microsoft 365 Defender Suite
*Using the Defender and Purview admin centers

Microsoft Defender for Office 365

*What is Microsoft Defender for Office 365?
*Implementing policies for uses in Email, SharePoint, OneDrive, and Teams
*Dealing with threats using Defender for Office 365
*Performing a campaign email attack simulation in Microsoft Defender

Microsoft Defender for Cloud Apps and Data Loss Prevention (DLP)

*Understanding the concepts of Microsoft Defender for Cloud Apps
*Investigating security risks in Defender for Cloud Apps
*Concepts of data loss prevention in Microsoft Defender
*Alerts with data loss prevention policies (DLP)
*Data loss prevention (DLP) policy alert investigation

Microsoft Defender for Endpoint and Defender Vulnerability Management

*Understanding Microsoft Defender for Endpoint concepts
*Deploy a Windows 11 VM endpoint
*Attack surface reduction (ASR) support with Intune
*Working with device onboarding regarding Defender for Endpoint
*Something to be aware of about extra features
*Endpoint advanced features, alerts and incidents
*Endpoint vulnerabilities
*Device attack surface reduction (ASR)
*Device groups with Defender for Endpoint
*Microsoft Defender Vulnerability Management risk identification
*Endpoint threat indicators
*Device discovery of unmanaged devices

Microsoft Defender for Identity

*Microsoft Entra ID security risk mitigation
*Concepts of using Microsoft Entra Identity Protection
*Microsoft Entra Identity Protection security risk mitigation
*Microsoft Entra Identity Protection risks in regards to Microsoft Defender
*Microsoft Defender for Identity concepts
*Using Defender for Identity to mitigate threats with AD DS

Microsoft Defender for Cloud full management and configurations

*Settings config in Microsoft Defender for Cloud
*Roles in Microsoft Defender for Cloud
*Cloud workload protection
*Automation of onboarding Azure resource
*Azure Arc connections
*Multi-cloud connections
*Email notifications in Microsoft Defender for Cloud
*Using alert suppression rules
*Workflow automation configuration in Defender for Cloud
*Using sample alerts and incidents
*Using Microsoft Defender for Cloud recommendations
*Security alerts and incidents in Microsoft Defender for Cloud
*Using threat intelligence reports with Microsoft Defender for Cloud

Dealing with insider risks in Microsoft 365

*Concepts of insider risk policies
*Insider risk policy generation
*Insider risk policy alert investigation

Audit and search capabilities in Microsoft Defender and Microsoft Purview

*Licensing of unified audit logging
*Permissions for unified auditing
*Threat hunting with unified audit logging
*Threat hunting with Content Searches

Conclusion

*Cleaning up your lab environment
*Getting a Udemy certificate
*BONUS Where do I go from here?
Рекомендации по теме
Комментарии
Автор

Get access to all my courses for a discount here:

examlabpractice
Автор

Wow.... I will encourage the new IT folks to listen to the begning IT concepts explained in the video... ❤ best video

Hometube
Автор

an hour into this video and I can say your teaching style is very easy to grasp and helpful! thank you and keep doing what you're doing

ericzliu
Автор

God blessed you for this wonderful gift I had zaro knowledge but now I am so knowledgeable after this video am so happy thank you

kikibah
Автор

This is a major help if you are taking the SC-300 exam but good to know if you do just about anything with in Entra ID! Awesome video will be watching this one a few times for sure.

kitfo
Автор

Awesome training sessions. Thanks John.

gustavoadolfoguzmancapera
Автор

J Christopher i dont hv words i wanted to appriciate you for such video. I am working as soc analyst still your video helped me to clear my basics ...

BashirShaikh-zlzh
Автор

Amazing content, thank you for everything.

megmucklebones
Автор

Thank for video. Currently i work as soc analyst and my daily task is analyze with microsoft defender

nasyaramadhana
Автор

Amazing video explaining the basics in #IT is very important so new students can join and understand in a better way. Your method of teaching is wonderful kudos for your help 🙏☺️🖥️🥇🚀

amarilnto
Автор

thank you for your video, very useful training video.

Neng.Sunate
Автор

Nice Sharing..!!

But had an question regarding "Azure registry container images should have vulnerabilities resolved (powered by Microsoft Defender Vulnerability Management)" - lets say suppose for this azure recommendation i want to turn off scanning of old images images and only with the latest tag should be scanned and rest all should be ignored - How can i do it soo ?? Need to Improve my Azure secure score

dannyroy
Автор

Does your udemy course linked in the description depend on using the deprecated evaluation lab feature?

TheCnstgrad
Автор

Do you need an E5 license to perform the lab? I have an E3 and do not see it.

spmffl
Автор

What else can we use as evaluations and tutorials have been deprecated as of 18/01/2023

zt
Автор

Anyone know how I can generate alerts in the new defender (XDR), not sure how to complete this training without looking at incidents

antwan
Автор

i am unable to install defender agent getting error on all windows 2012R2 servers 2012 R2 - MpAsDesc.dll 310

klbmgte
Автор

The evaluation lab is deprecated, any idea of a workaround?

antwan
Автор

Thanks for this training however, it seems like intro sound is way too loud - had a jump scare haha.

tsnazzle