Choose your language
Microsoft Defender training
More than 2 million learners worldwide

Microsoft Defender training

4.1

Master the full Microsoft Defender ecosystem and build the hands-on skills enterprises need to detect, investigate, and respond to modern threats. This training covers every major Defender product — from Endpoint and Identity to Cloud Apps and Sentinel integration. Whether you are hardening infrastructure or leading a SOC team, you will leave with practical, job-ready expertise.

Dedika for businesses

What you will learn:

This course takes you through every core component of the Microsoft Defender product family, from endpoint protection and identity threat detection to cloud security posture management and SIEM integration with Microsoft Sentinel. You will configure attack surface reduction rules, investigate multi-stage incidents, and automate responses using SOAR playbooks. You will also learn to protect email environments with Defender for Office 365, control SaaS app risk with Defender for Cloud Apps, and enforce Zero Trust principles across your organisation. Advanced modules cover KQL-based threat hunting, PowerShell and API automation, and building a Defender deployment maturity roadmap. By the end, you will have the technical depth to operate and optimise Microsoft Defender at an enterprise scale.

How you study in practice Microsoft Defender training

How you practise Microsoft Defender training

For companies looking to train their teams

With Dedika for Businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 36 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Introduction to Microsoft Defender

  • Lesson 1 • Navigating the Microsoft Defender Portal

    Orients students to the unified Defender portal interface and key navigation paths. Enables efficient daily use of dashboards and investigation tools.

  • Lesson 2 • Core Defender Architecture

    Explains the shared architectural principles across Defender products. Connects agent-based and agentless models to deployment decisions.

  • Lesson 3 • Threat Intelligence Foundations

    Introduces Microsoft threat intelligence signals that power Defender detections. Grounds students in how global signal data translates to local alerts.

  • Lesson 4 • Microsoft Security Ecosystem Overview

    Maps the Microsoft security portfolio and positions Defender within it. Establishes context for all subsequent product-specific learning.

Chapter 2See details

Microsoft Defender for Endpoint

  • Lesson 1 • Attack Surface Reduction Rules

    Explains ASR rules that block common attack vectors before execution. Students configure and tune rules to balance security and productivity.

  • Lesson 2 • Endpoint Vulnerability Management

    Introduces the built-in vulnerability management module for asset exposure tracking. Students prioritize and remediate software vulnerabilities using risk scoring.

  • Lesson 3 • Onboarding Endpoints to Defender

    Covers supported platforms and onboarding methods for Windows, macOS, Linux, and mobile. Prepares students to deploy sensors at scale.

  • Lesson 4 • Automated Investigation and Remediation

    Covers AIR workflows that automatically investigate and remediate threats. Students learn to review, approve, and override automated actions.

  • Lesson 5 • Endpoint Detection and Response

    Teaches how EDR detects behavioural anomalies and surfaces alerts. Students learn to triage and investigate endpoint incidents end to end.

Chapter 3See details

Microsoft Defender for Identity

  • Lesson 1 • Identity Threat Detection Concepts

    Establishes how attackers exploit identity infrastructure and how Defender for Identity counters these tactics. Grounds students in AD attack patterns.

  • Lesson 2 • Protecting Privileged Accounts

    Focuses on monitoring and hardening high-value accounts using Defender for Identity insights. Students apply sensitive account tagging and honeytoken strategies.

  • Lesson 3 • Investigating Identity Alerts

    Teaches alert triage and investigation using the identity alert queue and entity pages. Students trace attack paths from initial access to lateral movement.

  • Lesson 4 • Deploying Defender for Identity Sensors

    Covers sensor installation on domain controllers and AD FS servers. Students configure directory service accounts and validate sensor health.

Chapter 4See details

Microsoft Defender for Office 365

  • Lesson 1 • Email Threat Landscape

    Surveys modern email attack techniques including phishing, spear-phishing, and BEC. Provides context for every protection policy covered in this chapter.

  • Lesson 2 • Attack Simulation Training

    Configures and runs simulated phishing campaigns to measure and improve user resilience. Students analyse simulation results and assign targeted training.

  • Lesson 3 • Safe Attachments and Safe Links

    Teaches detonation-based attachment scanning and URL rewriting for link protection. Students configure policies for users, SharePoint, and Teams.

  • Lesson 4 • Anti-Phishing and Anti-Spoofing Policies

    Covers configuration of anti-phishing policies including impersonation and spoof intelligence settings. Students tune policies to reduce false positives.

  • Lesson 5 • Threat Explorer and Email Investigation

    Uses Threat Explorer to hunt for malicious emails and trace delivery paths. Students perform soft-delete and hard-delete remediation actions.

Chapter 5See details

Microsoft Defender for Cloud Apps

  • Lesson 1 • App Connectors and API Integration

    Covers native API connectors that provide deep visibility into sanctioned SaaS apps. Students connect major platforms and validate data ingestion.

  • Lesson 2 • Access and Session Policies

    Teaches Conditional Access App Control for real-time session monitoring and control. Students create policies that block downloads or watermark sensitive files.

  • Lesson 3 • Cloud App Discovery and Shadow IT

    Explains how traffic logs and endpoint signals reveal unsanctioned app usage. Students generate discovery reports and assess app risk scores.

  • Lesson 4 • Cloud App Threat Detection

    Configures anomaly detection and activity policies to surface suspicious cloud behaviour. Students investigate alerts and correlate them with identity signals.

Chapter 6See details

Microsoft Defender for Cloud

  • Lesson 1 • Defender Plans for Workload Protection

    Covers workload-specific Defender plans for servers, containers, databases, and storage. Students enable plans and understand their detection capabilities.

  • Lesson 2 • Security Alerts and Threat Detection

    Teaches how Defender for Cloud generates and enriches security alerts for cloud workloads. Students triage alerts and map them to MITRE ATT&CK tactics.

  • Lesson 3 • Cloud Security Posture Management

    Introduces Secure Score and security recommendations for Azure, AWS, and GCP workloads. Students prioritise and remediate misconfigurations to improve posture.

  • Lesson 4 • DevSecOps and Supply Chain Security

    Integrates security scanning into CI/CD pipelines using Defender for DevOps. Students remediate code, container image, and infrastructure-as-code findings.

Chapter 7See details

Microsoft Sentinel Integration with Defender

  • Lesson 1 • Incident Management in Sentinel

    Covers Sentinel incident lifecycle from creation through closure using Defender-sourced alerts. Students assign, investigate, and document incidents systematically.

  • Lesson 2 • SOAR Playbooks for Defender Alerts

    Designs Logic Apps-based playbooks that automate responses to Defender alerts in Sentinel. Students trigger, test, and monitor playbook execution.

  • Lesson 3 • Threat Hunting with KQL

    Applies KQL hunting queries against Defender telemetry to proactively find hidden threats. Students build, save, and share hunting queries as bookmarks.

  • Lesson 4 • Analytics Rules and Detection Engineering

    Builds scheduled and near-real-time analytics rules using KQL to detect threats across Defender data. Students tune rules to reduce alert fatigue.

  • Lesson 5 • Connecting Defender Data to Sentinel

    Configures Microsoft Defender data connectors in Sentinel to ingest alerts and raw events. Students validate data flow and understand ingestion cost implications.

Chapter 8See details

Advanced Defender Operations and Strategy

  • Lesson 1 • Microsoft Defender XDR Incident Correlation

    Explains how Defender XDR correlates alerts across products into unified incidents. Students investigate multi-stage attacks spanning endpoint, identity, and email.

  • Lesson 2 • Security Metrics and Reporting

    Builds executive and operational reports using Defender portal data and Power BI. Students define KPIs that demonstrate security programme effectiveness.

  • Lesson 3 • Defender Configuration and Policy Governance

    Covers centralised policy management, configuration baselines, and drift detection across Defender products. Students enforce consistent security settings at scale.

  • Lesson 4 • Advanced Hunting Across Defender XDR

    Uses the unified Advanced Hunting interface to query all Defender data sources with KQL. Students build complex multi-table queries for proactive threat detection.

  • Lesson 5 • Defender Deployment Maturity Model

    Introduces a phased maturity framework for expanding and optimising Defender coverage over time. Students assess current state and plan targeted improvements.

Certification

Your valid completion certificate

This course is for you:

  • IT administrators: ready to expand their role into proactive security operations.

  • Junior SOC analysts: looking to build structured, cross-product investigation skills.

  • Cloud engineers: responsible for securing hybrid and multi-cloud Microsoft workloads.

  • Security consultants: advising enterprise clients on Microsoft Defender strategy and deployment.

  • Career changers: transitioning from general IT support into cybersecurity with Microsoft tools.

  • Compliance officers: needing technical fluency to align Defender controls with regulatory requirements.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQs

Who is Dedika?

Is the certificate valid in Pakistan?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course