Windows Server – Security Management in Practice (BZP2)

Cybersecurity, ICT Security

This course focuses on practical procedures for protecting servers, accounts and data using modern features available in Windows Server. Participants will learn how to configure environments correctly so they can withstand common attacks and security incidents.

The training is based on practical lab exercises in which participants verify the effectiveness of their configuration using simulation tools and test attacks. By the end, they will be able to manage servers to ensure maximum protection of credentials, services, applications, data and network traffic.

THIS TRAINING COURSE WILL HELP YOU:

  • Understand current threats and attack detection methods in Windows Server
  • Secure credentials and privileged access
  • Restrict administrative privileges using JEA and PAM
  • Configure protection against malware, ransomware and unsafe applications
  • Implement advanced auditing and log management
  • Deploy practical mechanisms for protecting network traffic, including firewalls, IPsec, SMB and DNS

WHO SHOULD ATTEND?

  • Windows Server administrators
  • Security specialists managing Microsoft servers and services
  • IT professionals responsible for protecting enterprise infrastructure
  • DevOps and cloud engineers working with hybrid environments

COURSE LOCATION AND AVAILABLE DATES



Choose whether to attend in person in our classroom or join online. You can select your preferred format during registration. Learn more about hybrid training.

Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English

Course content:

Hide details
  • Windows Security Model, Identities and Authentication
    1. Windows architecture and key security subsystem components
    2. Processes, DLLs and services from a security perspective
    3. Process and service identities, memory management, and diagnostic and debugging options
    4. Logon session, access token, SID and security principals
    5. User and service accounts
    6. Built-in identities SYSTEM, Local Service, Network Service and IIS AppPoolIdentity
    7. Local and domain groups, user rights and the principle of least privilege
    8. Credential storage in Windows and the risks of compromise
    9. NTLM and Kerberos – principles, differences, use cases and security implications
    10. Overview of certificate-based authentication and its relationship to Active Directory
    11. Practical use of Sysinternals tools for system and security analysis
  • Active Directory and Privileged Access Security
    1. Active Directory security model
    2. Permission delegation and separation of administrative roles
    3. Group Policy, Security Policy, account policies and password policies
    4. Central enforcement of security settings
    5. Delegating management of servers, workstations and Active Directory objects
    6. Administrative levels and the tiering principle
    7. Just Enough Administration (JEA)
    8. Principles of Privileged Access Management (PAM)
    9. Windows LAPS and protection of local administrator accounts
    10. Protection of service accounts
    11. sMSA, gMSA and dMSA capabilities in Windows Server
    12. Domain and forest trusts, trust accounts and selective authentication
    13. Security risks in complex Active Directory environments
    14. NTFS and share permissions
    15. Access-Based Enumeration (ABE)
    16. Relationship between permissions, groups and user rights
    17. Windows Server Security Baseline and OSConfig
  • Attacks Against Windows and Active Directory
    1. Attacks against NTLM authentication
    2. Pass-the-Hash and ways to limit its impact
    3. Attacks against Kerberos authentication
    4. Pass-the-Ticket, Kerberoasting and related techniques
    5. Offline credential extraction and abuse
    6. Golden Ticket and other attacks against Active Directory
    7. Shadow Credentials and abuse of the msDS-KeyCredentialLink attribute
    8. Persistence techniques in Active Directory
    9. Overview of certificate authentication abuse in Active Directory
    10. User Account Control (UAC)
    11. Privilege escalation and common techniques for bypassing security mechanisms
    12. Credential protection with Credential Guard
    13. LSASS process protection
    14. Restricting credential delegation between systems
  • Windows Server Hardening and Service Protection
    1. Practical principles of Windows Server hardening
    2. Windows Server Security Baseline
    3. Applying CIS recommendations in Windows
    4. Protection against malware and ransomware
    5. Windows Defender Application Control (WDAC)
    6. AppLocker and control of permitted applications
    7. Windows Firewall and centralized management with Group Policy
    8. SMB security
    9. Restricting legacy and insecure protocols
    10. SMB signing and encryption
    11. DNS and name resolution in Windows
    12. DNS versus NetBIOS and other legacy mechanisms
    13. Common attacks against name services
    14. DNSSEC and options for protecting DNS infrastructure
  • Communication and Data Protection
    1. Segmenting and securing network communications with IPsec
    2. IPsec principles, authentication and Security Associations
    3. Deploying IPsec with Group Policy
    4. BitLocker – protecting system and data drives
    5. Centralized BitLocker management
    6. Storing and recovering recovery keys
    7. Differences between BitLocker and EFS in terms of use and management
    8. IPv6 fundamentals in Windows
    9. IPv6 security specifics
    10. Common attacks and vulnerabilities related to IPv6
  • Auditing, Monitoring and Intrusion Detection
    1. MITRE ATT&CK as a framework for mapping attack techniques and defensive measures
    2. Advanced Audit Policy
    3. Auditing logons and authentication
    4. Auditing permission changes and resource access
    5. Auditing and monitoring RDP access
    6. Monitoring administrator activity
    7. Windows Event Logs and practical log management principles
    8. Searching for intrusions in data from different sources
    9. Detecting lateral movement
    10. Detecting abuse of system tools and binaries
    11. LOLBins / Living off the Land
    12. Sysmon – deployment, configuration and use in detecting suspicious activity
    13. Detecting attack tools and techniques used to compromise Windows and Active Directory
    14. Honeypots and deception techniques
    15. Practical validation of hardening effectiveness through simulated attacks and lab scenarios
Prerequisites:
Working knowledge of the Windows operating system. Basic understanding of TCP/IP network security.
Schedule:
3 days (9:00-17:00)
Price per person:
704.00 € ( 851.84 € incl. 21% VAT)

Training and learning environment