Windows Server – Security Management in Practice (BZP2)
Cybersecurity, ICT Security
This course focuses on practical procedures for protecting servers, accounts and data using modern features available in Windows Server. Participants will learn how to configure environments correctly so they can withstand common attacks and security incidents.
The training is based on practical lab exercises in which participants verify the effectiveness of their configuration using simulation tools and test attacks. By the end, they will be able to manage servers to ensure maximum protection of credentials, services, applications, data and network traffic.
THIS TRAINING COURSE WILL HELP YOU:
- Understand current threats and attack detection methods in Windows Server
- Secure credentials and privileged access
- Restrict administrative privileges using JEA and PAM
- Configure protection against malware, ransomware and unsafe applications
- Implement advanced auditing and log management
- Deploy practical mechanisms for protecting network traffic, including firewalls, IPsec, SMB and DNS
WHO SHOULD ATTEND?
- Windows Server administrators
- Security specialists managing Microsoft servers and services
- IT professionals responsible for protecting enterprise infrastructure
- DevOps and cloud engineers working with hybrid environments
COURSE LOCATION AND AVAILABLE DATES
9–11 Dec 2026
704 €
CZECH
Praha + online (optional)
22–24 Feb 2027
704 €
CZECH
19–21 Apr 2027
704 €
CZECH
Need this course in English?
Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.
For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.
Request training in English
Course content:
Hide details
-
Windows Security Model, Identities and Authentication
-
Windows architecture and key security subsystem components
-
Processes, DLLs and services from a security perspective
-
Process and service identities, memory management, and diagnostic and debugging options
-
Logon session, access token, SID and security principals
-
User and service accounts
-
Built-in identities SYSTEM, Local Service, Network Service and IIS AppPoolIdentity
-
Local and domain groups, user rights and the principle of least privilege
-
Credential storage in Windows and the risks of compromise
-
NTLM and Kerberos – principles, differences, use cases and security implications
-
Overview of certificate-based authentication and its relationship to Active Directory
-
Practical use of Sysinternals tools for system and security analysis
-
Active Directory and Privileged Access Security
-
Active Directory security model
-
Permission delegation and separation of administrative roles
-
Group Policy, Security Policy, account policies and password policies
-
Central enforcement of security settings
-
Delegating management of servers, workstations and Active Directory objects
-
Administrative levels and the tiering principle
-
Just Enough Administration (JEA)
-
Principles of Privileged Access Management (PAM)
-
Windows LAPS and protection of local administrator accounts
-
Protection of service accounts
-
sMSA, gMSA and dMSA capabilities in Windows Server
-
Domain and forest trusts, trust accounts and selective authentication
-
Security risks in complex Active Directory environments
-
NTFS and share permissions
-
Access-Based Enumeration (ABE)
-
Relationship between permissions, groups and user rights
-
Windows Server Security Baseline and OSConfig
-
Attacks Against Windows and Active Directory
-
Attacks against NTLM authentication
-
Pass-the-Hash and ways to limit its impact
-
Attacks against Kerberos authentication
-
Pass-the-Ticket, Kerberoasting and related techniques
-
Offline credential extraction and abuse
-
Golden Ticket and other attacks against Active Directory
-
Shadow Credentials and abuse of the msDS-KeyCredentialLink attribute
-
Persistence techniques in Active Directory
-
Overview of certificate authentication abuse in Active Directory
-
User Account Control (UAC)
-
Privilege escalation and common techniques for bypassing security mechanisms
-
Credential protection with Credential Guard
-
LSASS process protection
-
Restricting credential delegation between systems
-
Windows Server Hardening and Service Protection
-
Practical principles of Windows Server hardening
-
Windows Server Security Baseline
-
Applying CIS recommendations in Windows
-
Protection against malware and ransomware
-
Windows Defender Application Control (WDAC)
-
AppLocker and control of permitted applications
-
Windows Firewall and centralized management with Group Policy
-
SMB security
-
Restricting legacy and insecure protocols
-
SMB signing and encryption
-
DNS and name resolution in Windows
-
DNS versus NetBIOS and other legacy mechanisms
-
Common attacks against name services
-
DNSSEC and options for protecting DNS infrastructure
-
Communication and Data Protection
-
Segmenting and securing network communications with IPsec
-
IPsec principles, authentication and Security Associations
-
Deploying IPsec with Group Policy
-
BitLocker – protecting system and data drives
-
Centralized BitLocker management
-
Storing and recovering recovery keys
-
Differences between BitLocker and EFS in terms of use and management
-
IPv6 fundamentals in Windows
-
IPv6 security specifics
-
Common attacks and vulnerabilities related to IPv6
-
Auditing, Monitoring and Intrusion Detection
-
MITRE ATT&CK as a framework for mapping attack techniques and defensive measures
-
Advanced Audit Policy
-
Auditing logons and authentication
-
Auditing permission changes and resource access
-
Auditing and monitoring RDP access
-
Monitoring administrator activity
-
Windows Event Logs and practical log management principles
-
Searching for intrusions in data from different sources
-
Detecting lateral movement
-
Detecting abuse of system tools and binaries
-
LOLBins / Living off the Land
-
Sysmon – deployment, configuration and use in detecting suspicious activity
-
Detecting attack tools and techniques used to compromise Windows and Active Directory
-
Honeypots and deception techniques
-
Practical validation of hardening effectiveness through simulated attacks and lab scenarios
-
Prerequisites:
-
Working knowledge of the Windows operating system. Basic understanding of TCP/IP network security.
-
Schedule:
-
3 days (9:00-17:00)
-
Price per person:
-
704.00 € ( 851.84 € incl. 21% VAT)
Training and learning environment
What does the environment for in-person IT courses look like?We hold training courses in our own classrooms equipped with modern computer equipment for each participant and a large projection screen. Each workstation is fitted with a powerful computer for seamless practical exercises, and the environment supports a calm, friendly atmosphere during training.
Do I need to bring my own laptop to the classroom IT course?Our training rooms are fully equipped, so you do not need to bring your own laptop. A modern computer with all necessary hardware and software is ready for you at your workstation.
Will you receive an official certificate after completing an IT course?Yes, upon successful completion of the training course, you will receive an official ICT Pro certificate confirming your participation and acquired technical skills. You can use it to verify your qualifications or add it to your professional profile.
Where can you find our training center in Brno?The premises of the ICT Pro training center are located on the 1st floor of the COMGUARD building at Sochorova 38 in Brno. Positioned on the border of Žabovřesky and Komín, the location is easily accessible by both car and public transport.
Where can you find our training center in Prague?The premises of the ICT Pro training center are located on the 1st floor of the Opatov Park building at Líbalova 1, Prague 11 – Chodov. The location provides a comfortable environment for your education with convenient access.
What facilities and refreshments are available to you during training breaks?Our training centers feature a fully equipped kitchenette for a comfortable break during your courses. The facilities include a coffee machine, microwave, kettle, and a wide selection of drinks and snacks.
What beverage refreshments are available during your course?A beverage station with a coffee machine, teas, syrups, and water is at your disposal throughout the entire training session. You can enjoy a coffee or another drink of your choice anytime during breaks.
What light refreshments are provided for you during the courses?During course breaks, participants can enjoy light sweet snacks, pastries, and fruit syrups to mix their own drinks. Fresh water dispenser and plates are also available for your convenience.
Should I bring my own snacks to ICT Pro training?There is no need to. A wide selection of savory snacks, sweet biscuits, and snack bars is available for you during breaks. Boost your energy for all-day focus right inside the training center premises.
Can you spend training breaks in the fresh air?Yes, an outdoor terrace is available at our training center. During breaks between learning sessions, you can relax in the fresh air in a pleasant green environment.
Where can you relax during course breaks?Our training center features a spacious outdoor terrace with seating options. During breaks between learning sessions, you can step outside to relax and recharge in the fresh air.