Securing Windows Server 2016


Course Description

This five-day, instructor-led course teaches IT professionals how they can enhance the security of the IT infrastructure that they administer. This course begins by emphasizing the importance of assuming that network breaches have occurred
already, and then teaches you how to protect administrative credentials and rights to help ensure that administrators can perform only the tasks that they need to, when they need to.

This course explains how you can use auditing and the Advanced Threat Analysis feature in Windows Server 2016 to identify security issues. You will also learn how to mitigate malware threats, secure your virtualization platform, and use deployment options such as Nano server and containers to enhance security. The course also explains how you can help protect access to files by using encryption and dynamic access control, and how you can enhance your network’s security.

Who Should Attend

This course is for IT professionals who need to securely administer Windows Server 2016 networks. These professionals typically work with networks that are configured as Windows Server domain-based environments, with managed access to the Internet and cloud services. Students who seek certification in the 70-744 Securing Windows server exam also will benefit from this course.

Course Information


Length: 5 day

Format: Lecture and Lab

Delivery Method: Virtual / Onsite

Max. Capacity: 16



Learning Objectives

  • Secure Windows Server
  • Protect credentials and implement privileged access workstations
  • Limit administrator rights with Just Enough Administration
  • Manage privileged access
  • Mitigate malware and threats
  • Analyze activity with advanced auditing and log analytics
  • Deploy and configure Advanced Threat Analytics and Microsoft Operations Management Suite
  • Configure Guarded Fabric virtual machines (VMs)
  • Use the Security Compliance Toolkit (SCT) and containers to improve security
  • Plan and protect data
  • Optimize and secure file services
  • Secure network traffic with firewalls and encryption
  • Secure network traffic by using DNSSEC and Message Analyzer

Labs

  • Basic breach detection and incident response strategies
  • Implementing user rights, security options, and group managed service accounts
  • Configuring and deploying LAPs
  • Limiting administrator privileges with JEA
  • Limiting administrator privileges with PAM
  • Securing applications with Windows Defender, AppLocker, and Device Guard Rules
  • Configuring advanced auditing
  • Deploying ATA, Microsoft Operations Management Suite, and Azure Security Center
  • Guarded fabric with Admin-trusted attestation and shielded VMs
  • Using SCT
  • Deploying and configuring containers
  • Protecting data by using encryption and BitLocker
  • Quotas and file screening
  • Implementing Dynamic Access Control
  • Configuring Windows Firewall with Advanced Security
  • Securing DNS
  • Microsoft Message Analyzer and SMB encryption



UPCOMING TRAINING SESSIONS VIEW CALENDAR
DATES LOCATION DAYS  
Dec 16, 2019 WebEx - Central Time Zone 5 DAY COURSE