
TRAINING / EDD
- Defensive security
- Intermediate
Enterprise Defense in Depth.
Assess an enterprise attack surface, implement layered security controls, and examine how those controls hold up against adversary activity.
- Duration
- 5 days
- Level
- Intermediate
- Delivery
- In-person / Remote
- Completion
- Accredible certificate
Enterprise hardening
Course overview.
Enterprise Defense in Depth examines how layers of security affect an enterprise's attack surface. Students work through the purpose, implementation, and validation of controls rather than treating hardening as a checklist.
The course covers enterprise security controls and Windows domain security, including Active Directory, Group Policy, administrative tiering, local administrator password management, and PowerShell logging. Exercises connect configuration choices to adversary activity and the evidence available to defenders.
Who it is for
- Security engineers
- Windows and Active Directory administrators
- Defenders responsible for enterprise hardening
Tools and concepts
- Active Directory
- Group Policy
- Windows LAPS
- PowerShell logging
- Enterprise security controls
Learning outcomes
What your team will practice.
Evaluate an enterprise environment using defense-in-depth principles.
Select and apply controls in response to observed enterprise risks.
Use directory structure and policy to strengthen enterprise security boundaries.
Apply administrative tiering and local administrator password controls.
Use PowerShell logging to examine activity and assess the visibility provided by controls.
Curriculum
Inside the course.
Topics covered across five days of instructor-led training.
01Layered defense and attack surface
Evaluate an enterprise environment using defense-in-depth principles.
- Enterprise attack surfaces
- Layered security principles
- Security control impact analysis
02Enterprise security controls
Select and apply controls in response to observed enterprise risks.
- Control placement and purpose
- Attack techniques and control behavior
- Evaluating control effectiveness
03Active Directory and Group Policy
Use directory structure and policy to strengthen enterprise security boundaries.
- Active Directory fundamentals
- Group Policy configuration
- Directory administration boundaries
04Privileged access hardening
Apply administrative tiering and local administrator password controls.
- Active Directory tiering
- Windows LAPS
- Reducing exposure of privileged access
05Logging and control validation
Use PowerShell logging to examine activity and assess the visibility provided by controls.
- PowerShell logging
- Interpreting recorded activity
- Reviewing control impact
Preparation
Before your team attends.
Prerequisites
- Working knowledge of Windows administration and networking.
- Familiarity with Active Directory and enterprise security operations.
What to bring
- A laptop, charger, and a modern web browser.
- Internet access suitable for connecting to the training environment.
What is included
- Instructor-led demonstrations and guided lab exercises.
- Course reference materials.
- An Accredible certificate of completion.
Workforce alignment
NICE Framework alignment.
Course objectives align with selected parts of the NICE Framework, version 2.2.0. This is a curriculum alignment, not full work-role qualification or NIST endorsement.
- Systems AdministrationIO-WRL-005
- Systems Security AnalysisIO-WRL-006
- Vulnerability AnalysisPD-WRL-007
View curriculum alignment
Product-specific configuration examples support broader NICE control and administration objectives; they are not separate framework certifications.
Layered defense and attack surface
Evaluate an enterprise environment using defense-in-depth principles.
Related work roles: Systems Security Analysis (IO-WRL-006); Vulnerability Analysis (PD-WRL-007)
- tasks
- T0262Employ approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, security robustness)
- T1619Perform risk and vulnerability assessments
- knowledge
- K0791Knowledge of defense-in-depth principles and practices
- K1212Knowledge of security controls
- skills
- S0667Skill in assessing security controls
The objective combines defense-in-depth reasoning with assessment of an enterprise's controls and exposure.
Enterprise security controls
Select and apply controls in response to observed enterprise risks.
Related work roles: Systems Security Analysis (IO-WRL-006); Vulnerability Analysis (PD-WRL-007)
- tasks
- T1919Implement system security controls
- T0309Assess the effectiveness of security controls
- knowledge
- K1212Knowledge of security controls
- K0791Knowledge of defense-in-depth principles and practices
- skills
- S0097Skill in applying security controls
- S0667Skill in assessing security controls
Students apply controls and evaluate their behavior, which directly supports implementation and assessment tasks.
Active Directory and Group Policy
Use directory structure and policy to strengthen enterprise security boundaries.
Related work roles: Systems Administration (IO-WRL-005); Systems Security Analysis (IO-WRL-006)
- tasks
- T1130Develop group policies and access control lists
- knowledge
- K0685Knowledge of access control principles and practices
- K1212Knowledge of security controls
- skills
- S0097Skill in applying security controls
Group Policy exercises support access-control and system-control implementation.
Privileged access hardening
Apply administrative tiering and local administrator password controls.
Related work roles: Systems Administration (IO-WRL-005)
- tasks
- T1919Implement system security controls
- knowledge
- K0685Knowledge of access control principles and practices
- K0686Knowledge of authentication and authorization tools and techniques
- skills
- S0097Skill in applying security controls
Tiering and password controls practice security-control implementation; the mapping does not imply full identity-program coverage.
Logging and control validation
Use PowerShell logging to examine activity and assess the visibility provided by controls.
Related work roles: Systems Security Analysis (IO-WRL-006); Vulnerability Analysis (PD-WRL-007)
- tasks
- T0309Assess the effectiveness of security controls
- knowledge
- K0897Knowledge of logging tools and technologies
- K1212Knowledge of security controls
- skills
- S0866Skill in performing log file analysis
- S0667Skill in assessing security controls
Log analysis supplies evidence for assessing security-control effectiveness.
Bring EDD to your team.
Tell us your team size, preferred dates, and delivery format. Include EDD in your inquiry.
