
Microsoft Defender training
Master the full Microsoft Defender ecosystem and build the hands-on skills enterprises need to detect, investigate, and respond to modern threats. This training covers every major Defender product — from Endpoint and Identity to Cloud Apps and Sentinel integration. Whether you're hardening infrastructure or leading a SOC team, you'll leave with practical, job-ready expertise.
What you will learn:
This course takes you through every core component of the Microsoft Defender product family, from endpoint protection and identity threat detection to cloud security posture management and SIEM integration with Microsoft Sentinel. You will configure attack surface reduction rules, investigate multi-stage incidents, and automate responses using SOAR playbooks. You will also learn to protect email environments with Defender for Office 365, control SaaS app risk with Defender for Cloud Apps, and enforce Zero Trust principles across your organization. Advanced modules cover KQL-based threat hunting, PowerShell and API automation, and building a Defender deployment maturity roadmap. By the end, you will have the technical depth to operate and optimize Microsoft Defender at an enterprise scale.
How you study in a practical way Microsoft Defender training
How you practice Microsoft Defender training
For companies who want to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 36 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsIntroduction to Microsoft Defender
Introduction to Microsoft Defender
Lesson 1 • Navigating the Microsoft Defender Portal
Orients students to the unified Defender portal interface and key navigation paths. Enables efficient daily use of dashboards and investigation tools.
Lesson 2 • Core Defender Architecture
Explains the shared architectural principles across Defender products. Connects agent-based and agentless models to deployment decisions.
Lesson 3 • Threat Intelligence Foundations
Introduces Microsoft threat intelligence signals that power Defender detections. Grounds students in how global signal data translates to local alerts.
Lesson 4 • Microsoft Security Ecosystem Overview
Maps the Microsoft security portfolio and positions Defender within it. Establishes context for all subsequent product-specific learning.
Chapter 2HideHide detailsSee detailsMicrosoft Defender for Endpoint
Microsoft Defender for Endpoint
Lesson 1 • Attack Surface Reduction Rules
Explains ASR rules that block common attack vectors before execution. Students configure and tune rules to balance security and productivity.
Lesson 2 • Endpoint Vulnerability Management
Introduces the built-in vulnerability management module for asset exposure tracking. Students prioritize and remediate software vulnerabilities using risk scoring.
Lesson 3 • Onboarding Endpoints to Defender
Covers supported platforms and onboarding methods for Windows, macOS, Linux, and mobile. Prepares students to deploy sensors at scale.
Lesson 4 • Automated Investigation and Remediation
Covers AIR workflows that automatically investigate and remediate threats. Students learn to review, approve, and override automated actions.
Lesson 5 • Endpoint Detection and Response
Teaches how EDR detects behavioral anomalies and surfaces alerts. Students learn to triage and investigate endpoint incidents end to end.
Chapter 3HideHide detailsSee detailsMicrosoft Defender for Identity
Microsoft Defender for Identity
Lesson 1 • Identity Threat Detection Concepts
Establishes how attackers exploit identity infrastructure and how Defender for Identity counters these tactics. Grounds students in AD attack patterns.
Lesson 2 • Protecting Privileged Accounts
Focuses on monitoring and hardening high-value accounts using Defender for Identity insights. Students apply sensitive account tagging and honeytoken strategies.
Lesson 3 • Investigating Identity Alerts
Teaches alert triage and investigation using the identity alert queue and entity pages. Students trace attack paths from initial access to lateral movement.
Lesson 4 • Deploying Defender for Identity Sensors
Covers sensor installation on domain controllers and AD FS servers. Students configure directory service accounts and validate sensor health.
Chapter 4HideHide detailsSee detailsMicrosoft Defender for Office 365
Microsoft Defender for Office 365
Lesson 1 • Email Threat Landscape
Surveys modern email attack techniques including phishing, spear-phishing, and BEC. Provides context for every protection policy covered in this chapter.
Lesson 2 • Attack Simulation Training
Configures and runs simulated phishing campaigns to measure and improve user resilience. Students analyze simulation results and assign targeted training.
Lesson 3 • Safe Attachments and Safe Links
Teaches detonation-based attachment scanning and URL rewriting for link protection. Students configure policies for users, SharePoint, and Teams.
Lesson 4 • Anti-Phishing and Anti-Spoofing Policies
Covers configuration of anti-phishing policies including impersonation and spoof intelligence settings. Students tune policies to reduce false positives.
Lesson 5 • Threat Explorer and Email Investigation
Uses Threat Explorer to hunt for malicious emails and trace delivery paths. Students perform soft-delete and hard-delete remediation actions.
Chapter 5HideHide detailsSee detailsMicrosoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
Lesson 1 • App Connectors and API Integration
Covers native API connectors that provide deep visibility into sanctioned SaaS apps. Students connect major platforms and validate data ingestion.
Lesson 2 • Access and Session Policies
Teaches Conditional Access App Control for real-time session monitoring and control. Students create policies that block downloads or watermark sensitive files.
Lesson 3 • Cloud App Discovery and Shadow IT
Explains how traffic logs and endpoint signals reveal unsanctioned app usage. Students generate discovery reports and assess app risk scores.
Lesson 4 • Cloud App Threat Detection
Configures anomaly detection and activity policies to surface suspicious cloud behavior. Students investigate alerts and correlate them with identity signals.
Chapter 6HideHide detailsSee detailsMicrosoft Defender for Cloud
Microsoft Defender for Cloud
Lesson 1 • Defender Plans for Workload Protection
Covers workload-specific Defender plans for servers, containers, databases, and storage. Students enable plans and understand their detection capabilities.
Lesson 2 • Security Alerts and Threat Detection
Teaches how Defender for Cloud generates and enriches security alerts for cloud workloads. Students triage alerts and map them to MITRE ATT&CK tactics.
Lesson 3 • Cloud Security Posture Management
Introduces Secure Score and security recommendations for Azure, AWS, and GCP workloads. Students prioritize and remediate misconfigurations to improve posture.
Lesson 4 • DevSecOps and Supply Chain Security
Integrates security scanning into CI/CD pipelines using Defender for DevOps. Students remediate code, container image, and infrastructure-as-code findings.
Chapter 7HideHide detailsSee detailsMicrosoft Sentinel Integration with Defender
Microsoft Sentinel Integration with Defender
Lesson 1 • Incident Management in Sentinel
Covers Sentinel incident lifecycle from creation through closure using Defender-sourced alerts. Students assign, investigate, and document incidents systematically.
Lesson 2 • SOAR Playbooks for Defender Alerts
Designs Logic Apps-based playbooks that automate responses to Defender alerts in Sentinel. Students trigger, test, and monitor playbook execution.
Lesson 3 • Threat Hunting with KQL
Applies KQL hunting queries against Defender telemetry to proactively find hidden threats. Students build, save, and share hunting queries as bookmarks.
Lesson 4 • Analytics Rules and Detection Engineering
Builds scheduled and near-real-time analytics rules using KQL to detect threats across Defender data. Students tune rules to reduce alert fatigue.
Lesson 5 • Connecting Defender Data to Sentinel
Configures Microsoft Defender data connectors in Sentinel to ingest alerts and raw events. Students validate data flow and understand ingestion cost implications.
Chapter 8HideHide detailsSee detailsAdvanced Defender Operations and Strategy
Advanced Defender Operations and Strategy
Lesson 1 • Microsoft Defender XDR Incident Correlation
Explains how Defender XDR correlates alerts across products into unified incidents. Students investigate multi-stage attacks spanning endpoint, identity, and email.
Lesson 2 • Security Metrics and Reporting
Builds executive and operational reports using Defender portal data and Power BI. Students define KPIs that demonstrate security program effectiveness.
Lesson 3 • Defender Configuration and Policy Governance
Covers centralized policy management, configuration baselines, and drift detection across Defender products. Students enforce consistent security settings at scale.
Lesson 4 • Advanced Hunting Across Defender XDR
Uses the unified Advanced Hunting interface to query all Defender data sources with KQL. Students build complex multi-table queries for proactive threat detection.
Lesson 5 • Defender Deployment Maturity Model
Introduces a phased maturity framework for expanding and optimizing Defender coverage over time. Students assess current state and plan targeted improvements.
Your valid completion certificate
This course is for you:
IT administrators: ready to expand their role into proactive security operations.
Junior SOC analysts: looking to build structured, cross-product investigation skills.
Cloud engineers: responsible for securing hybrid and multi-cloud Microsoft workloads.
Security consultants: advising enterprise clients on Microsoft Defender strategy and deployment.
Career changers: transitioning from general IT support into cybersecurity with Microsoft tools.
Compliance officers: needing technical fluency to align Defender controls with regulatory requirements.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in the Philippines?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















