TrainingCloud & infrastructure / Microsoft Windows ServerCT-BBSECW
CT-BBSECWCloudTeam course
BlackBelt – Securing Windows 10/11, Server 2019-2025 and your Directory Services
An intensive hands-on training led by MVP Sami Laiho, focused on securing Windows clients, Windows Server, and Active Directory/Entra ID. The course covers the principle of least privilege, application allowlisting, directory tiering, Privileged Access Workstations, and the latest security requirements for Windows 10/11 and Server 2019-2025. Sessions include realistic attack demonstrations and proven defensive techniques.
- Duration
- 4 days
- Level
- Advanced
- Provider
- In-house courses
- Topic
- Cloud & infrastructure / Microsoft Windows Server
Course outline
- Day 1: Introduction to IT security, real Windows hacking techniques, security subsystem fundamentals, security baselines, BitLocker, and Virtual TPM
- Day 2: USB device control, mitigating Pass-The-Hash and Mimikatz, LAPS, RDP with MFA, Windows Hello, phishing-resistant MFA, Secure Kernel and Credential Guard
- Day 3: Directory tiering (AD/Entra ID), levels of admin accounts, Privileged Access Workstation, UAC, PIM, PAM, principle of least privilege
- Day 4: Secure server management, protecting DHCP/DNS/AD DCs, Windows Firewall and IPsec, Zero Trust Networking, allowlisting (AppLocker/WDAC/3rd party), realistic security scenarios
Skills you will gain
- Analyzing real-world Windows attack techniques and defensive countermeasures
- Implementing and hardening BitLocker, including protection against realistic attacks
- Configuring Virtual TPM and controlling USB devices
- Mitigating Pass-The-Hash attacks and Mimikatz-based techniques
- Implementing LAPS, phishing-resistant MFA, and Windows Hello
- Implementing Credential Guard and Secure Kernel (VSM) technologies
- Implementing directory tiering (AD/Entra ID) to eliminate lateral movement of admin accounts
- Building Privileged Access Workstations (PAW) and applying PIM/PAM
- Implementing the principle of least privilege and removing unnecessary admin rights
- Securing infrastructure services (DHCP, DNS, domain controllers)
- Configuring Windows Firewall, IPsec, and Zero Trust Networking
- Implementing application allowlisting (AppLocker/WDAC/third-party solutions)
Who should attend
- Administrators and security professionals responsible for Windows and Active Directory environments
- Organizations preparing their infrastructure for NIS2 or similar regulatory compliance
- Professionals who want to secure their environment without sacrificing user productivity and usability
Prerequisites
- Basic knowledge of Windows administration
- Basic knowledge of Active Directory
- Basic knowledge of network infrastructure
Upcoming dates
These sessions run online with LLPA partners. Times are shown in Polish time, and the language of delivery is listed for each date.
| Date | Times (Polish time) | Language | Status | Price | Action |
|---|---|---|---|---|---|
| 09:00–17:00 | English | Scheduled | 14200 PLN | Request a quote |
14200 PLN
Ask about dates