close

close

Thank you for your enquiry!

One of our training experts will be in touch shortly to go over your training requirements.

close

close

Press esc to close

close close

Back to course information

Thank you for your enquiry!

One of our training experts will be in touch shortly to go overy your training requirements.

close close

Thank you for your enquiry!

One of our training experts will be in touch shortly to go over your training requirements.

Course Information

Securing Windows Server Course Outline | M20744

Module 1: Attacks, breach detection, and Sysinternals tools

This module introduces delegates to the concepts and ideas of security in Microsoft specific environments. Delegates are introduced to the “assume breach” philosophy and encourages them to consider the different types of attacks that can occur. Additionally, delegates are taught about key resources, how they detect and respond to an incident, and how an organisation’s needs and requirements determine the overall security policy.

Lessons:

  • Understanding attacks
  • Detecting security breaches
  • Examining activity with the Sysinternals tools

Lab: Basic breach detection and incident response strategies

  • Identifying attack types
  • Exploring Sysinternals tools

Module 2: Protecting credentials and privileged access

This module explores computer and service accounts, user accounts and rights, credentials, the Local Administrator Password Solution, and Privileged Access Workstations. Delegates will learn about configuring user rights and security options, protecting credentials by using Credential Guard, implementing Privileged Access Workstations, and managing and deploying Local Administrator Password Solution to manage local administrator account passwords.

Lessons:

  • Understanding user rights
  • Computer and service accounts
  • Protecting credentials
  • Privileged Access Workstations and jump servers
  • Local administrator password solution

Lab: Implementing user rights, security options, and group managed service accounts

  • Configuring user rights and account-security options
  • Delegating privileges
  • Creating group Managed Service Accounts
  • Locating problematic accounts

Lab: Configuring and deploying LAPs

  • Installing and configuring LAPs
  • Deploying and testing LAPs

Module 3: Limiting administrator rights with Just Enough Administration

In this module, delegates will learn how to deploy and configure Just Enough Administration (JEA), which is a technology that allows delegates to apply role-based access control (RBAC) principles through Windows PowerShell remote sessions.

Lessons:

  • Understanding JEA
  • Verifying and deploying JEA

Lab: Limiting administrator privileges with JEA

  • Creating a role-capability file
  • Creating a session-configuration file
  • Creating a JEA endpoint
  • Connecting and testing a JEA endpoint
  • Deploying a JEA configuration to another computer

Module 4: Privileged access management and administrative forests

This module explores Enhanced Security Administrative Environment (ESAE) forests, Microsoft Identity Manager (MIM), and Just In Time (JIT) Administration, or Privileged Access Management (PAM).

Lessons:

  • ESAE forests
  • Overview of Microsoft Identity Manager
  • Overview of JIT administration and PAM

Lab: Limiting administrator privileges with PAM

  • Layered approach to security
  • Configuring trust relationships and shadow principals
  • Requesting privileged access
  • Managing PAM roles

Module 5: Mitigating malware and threats

In this module, delegates will learn how to use tools such as Windows AppLocker, Windows Defender, Microsoft Device Guard, Windows Defender Application Guard, and Windows Defender Exploit Guard.

Lessons:

  • Configuring and managing Windows Defender
  • Restricting software
  • Configuring and using the Device Guard feature

Lab: Securing applications with Windows Defender, AppLocker, and Device Guard Rules

  • Configuring Windows Defender
  • Configuring AppLocker
  • Configuring Device Guard

Module 6: Analysing activity with advanced auditing and log analytics

This module broadly covers the concepts and techniques of general auditing, and then focusing on how to configure advanced auditing, Windows PowerShell auditing, and logging.

Lessons:

  • Overview of auditing
  • Advanced auditing
  • Windows PowerShell auditing and logging

Lab: Configuring advanced auditing

  • Configuring the auditing of file system access
  • Auditing domain sign-ins
  • Managing advanced audit policy configuration
  • Windows PowerShell logging and auditing

Module 7: Deploying and configuring Advanced Threat Analytics and Microsoft Operations Management Suite

This module provides delegates with the opportunity to explore the Microsoft Advanced Threat Analytics tool and the Microsoft Operations Management suite (OMS). Delegates will learn how to use them to monitor and analyse the security of a Windows Server deployment. Microsoft Azure Security Centre will also be covered, which allows users to manage and monitor the security configuration of workloads both on-premises and in the cloud.

Lessons:

  • Deploying and configuring ATA
  • Deploying and configuring Microsoft Operations Management Suite
  • Deploying and configuring Azure Security Centre

Lab: Deploying ATA, Microsoft Operations Management Suite, and Azure Security Centre

  • Preparing and deploying ATA
  • Preparing and deploying Microsoft Operations Management Suite
  • Deploying and configuring Azure Security Centre

Module 8: Secure Virtualisation Infrastructure

Delegates will learn how to configure Guarded Fabric VMs, including the requirements for shielded and encryption-supported VMs.

Lessons:

  • Guarded fabric
  • Shielded and encryption-supported virtual machines

Lab: Guarded fabric with Admin-trusted attestation and shielded VMs

  • Deploying a guarded fabric with admin-trusted attestation
  • Deploying a shielded VM

Module 9: Securing application development and server-workload infrastructure

This module provides delegates with an understanding of the SCT, which is a free, downloadable set of tools that can be used to create and apply security settings. Delegates will also learn about improving platform security by reducing the size and scope of application and compute resources by containerising workloads.

Lessons:

  • Using SCT
  • Understanding containers

Lab: Using SCT

  • Configuring a security baseline for Windows Server 2016
  • Deploying the security baseline for Windows Server 2016

Lab: Deploying and configuring containers

  • Deploying and managing a Windows container

Module 10: Planning and protecting data

In this module, delegates will learn how to configure Encrypting File System (EFS) and BitLocker drive encryption to protect data at rest. This module will also cover how to extend protection into the cloud by using Azure Information Protection.

Lessons:

  • Planning and implementing encryption
  • Planning and implementing BitLocker
  • Protecting data by using Azure Information Protection

Lab: Protecting data by using encryption and BitLocker

  • Encrypting and recovering access to encrypted files
  • Using BitLocker to protect data

Module 11: Optimising and securing file services

This module provides delegates with an understanding of file optimisation services through configuring File Server Resource Manager (FSRM) and Distributed File System (DFS). Delegates also will learn how to manage access to shared files by configuring Dynamic Access Control (DAC).

Lessons:

  • File Server Resource Manager
  • Implementing classification and file management tasks
  • Dynamic Access Control

Lab: Quotas and file screening

  • Configuring File Server Resource Manager quotas
  • Configuring file screening and storage reports

Lab: Implementing Dynamic Access Control

  • Preparing for implementing Dynamic Access Control
  • Implementing Dynamic Access Control
  • Validating and remediating Dynamic Access Control

Module 12: Securing network traffic with firewalls and encryption

In this module, delegates will learn how you to use Windows Firewall as an integral part of an organisation’s protection strategy. It covers the use of Internet Protocol security (IPsec) to encrypt network traffic and to establish security zones on your network. Delegates will also gain an understanding about the Datacenter Firewall feature that can be used to help protect on-premises virtual environments.

Lessons:

  • Understanding network-related security threats
  • Understanding Windows Firewall with Advanced Security
  • Configuring IPsec
  • Datacenter Firewall

Lab: Configuring Windows Firewall with Advanced Security

  • Creating and testing inbound rules
  • Creating and testing outbound rules
  • Creating and testing connection security rules

Module 13: Securing network traffic

This module covers a selection of the Windows Server 2016 technologies that can be used to help mitigate network-security threats. It explains how you can configure DNSSEC to help protect network traffic, and use Microsoft Message Analyser to monitor network traffic. Delegates will also learn how to secure Server Message Block (SMB) traffic.

Lessons:

  • Configuring advanced DNS settings
  • Examining network traffic with Message Analyser
  • Securing and analysing SMB traffic

Lab: Securing DNS

  • Configuring and testing DNSSEC
  • Configuring DNS policies and RRL

Lab: Microsoft Message Analyser and SMB encryption

  • Installing and using the Message Analyser
  • Configuring and verifying SMB encryption on SMB shares

Show moredowndown

Who should attend this Microsoft Windows Server Training Course?

This course is for IT professionals who require the ability to use Windows Server 2016. Delegates will typically have experience in domain-based activities, managing access, and using cloud services.

Students who are seeking certification in the 70-744 Securing Windows server exam, will also benefit from this course.

Prerequisites

Students are expected to have a minimum of two years’ experience in the IT field and should have:

  • Completed courses 740, 741, and 742, or the equivalent
  • A comprehensive understanding of networking fundamentals, including TCP/IP, User Datagram Protocol (UDP), and Domain Name System (DNS)
  • A comprehensive understanding of Active Directory Domain Services (AD DS) principles
  • A comprehensive understanding of Microsoft Hyper-V virtualisation fundamentals
  • An understanding of Windows Server security principles

Securing Windows Server Course Overview | M20744

This five-day course is designed to teach IT professionals about infrastructure security enhancements. Focus is firstly placed on identifying past network breaches to highlight vulnerabilities and raise awareness. This will ultimately help to teach delegates how to protect their IT infrastructures and ensure administrators have controlled access.

Delegates will learn how to use auditing to identify security issues, alongside the Advanced Threat Analysis feature of Windows Server 2016. The course will also cover the nature of malware threats and how to deal with them, securing a virtualisation platform, and deployment options. Delegates will also have the opportunity to learn about using encryption and dynamic access control.

Show moredowndown

Securing Windows Server Exam Information | M20744

 

 

What's included in this Microsoft Windows Server Course?

  • Delegate pack consisting of course notes and exercises
  • Manual
  • Experienced Instructor
  • Refreshments

Show moredowndown

Why choose us

Ways to take this course

Our easy to use Virtual platform allows you to sit the course from home with a live instructor. You will follow the same schedule as the classroom course, and will be able to interact with the trainer and other delegates.

Our fully interactive online training platform is compatible across all devices and can be accessed from anywhere, at any time. All our online courses come with a standard 90 days access that can be extended upon request. Our expert trainers are constantly on hand to help you with any questions which may arise.

This is our most popular style of learning. We run courses in 1200 locations, across 200 countries in one of our hand-picked training venues, providing the all important ‘human touch’ which may be missed in other learning styles.

best_trainers

Highly experienced trainers

All our trainers are highly qualified, have 10+ years of real-world experience and will provide you with an engaging learning experience.

venues

State of the art training venues

We only use the highest standard of learning facilities to make sure your experience is as comfortable and distraction-free as possible

small_classes

Small class sizes

We limit our class sizes to promote better discussion and ensuring everyone has a personalized experience

value_for_money

Great value for money

Get more bang for your buck! If you find your chosen course cheaper elsewhere, we’ll match it!

This is the same great training as our classroom learning but carried out at your own business premises. This is the perfect option for larger scale training requirements and means less time away from the office.

tailored_learning_experience

Tailored learning experience

Our courses can be adapted to meet your individual project or business requirements regardless of scope.

budget

Maximise your training budget

Cut unnecessary costs and focus your entire budget on what really matters, the training.

team_building

Team building opportunity

This gives your team a great opportunity to come together, bond, and discuss, which you may not get in a standard classroom setting.

monitor_progress

Monitor employees progress

Keep track of your employees’ progression and performance in your own workspace.

What our customers are saying

Frequently asked questions

FAQ's

Please arrive at the venue at 8:45am.
Students are expected to have a minimum of two years’ experience in the IT field and should have: Completed courses 740, 741, and 742, or the equivalent A comprehensive understanding of networking fundamentals, including TCP/IP, User Datagram Protocol (UDP), and Domain Name System (DNS) A comprehensive understanding of Active Directory Domain Services (AD DS) principles A comprehensive understanding of Microsoft Hyper-V virtualisation fundamentals An understanding of Windows Server security principles
This course is for IT professionals who require the ability to use Windows Server 2016. Delegates will typically have experience in domain-based activities, managing access, and using cloud services. Students who are seeking certification in the 70-744 Securing Windows server exam, will also benefit from this course.
We are able to provide support via phone & email prior to attending, during and after the course.
Delegate pack consisting of course notes and exercises, Manual, Experienced Instructor, and Refreshments
This course is 5 day(s)
Once your booking has been placed and confirmed, you will receive an email which contains your course location, course overview, pre-course reading material (if required), course agenda and payment receipts
The price for Securing Windows Server M20744 certification in the United Kingdom starts from £2495
The Knowledge Academy is the Leading global training provider in the world for Securing Windows Server M20744.

Why choose us

icon

Best price in the industry

You won't find better value in the marketplace. If you do find a lower price, we will beat it.

icon

Trusted & Approved

The Knowledge Academy is a Microsoft Silver Partner, hence we are fully accredited

icon

Many delivery methods

Flexible delivery methods are available depending on your learning style.

icon

High quality resources

Resources are included for a comprehensive learning experience.

barclays Logo
deloitte Logo
Thames Water Logo

"Really good course and well organised. Trainer was great with a sense of humour - his experience allowed a free flowing course, structured to help you gain as much information & relevant experience whilst helping prepare you for the exam"

Joshua Davies, Thames Water

santander logo
bmw Logo
Google Logo

Looking for more information on Microsoft Windows Server Training?

backBack to course information

Get a custom course package

We may not have any package deals available including this course. If you enquire or give us a call on 01344203999 and speak to our training experts, we should be able to help you with your requirements.