TRAINING / EDD

  • Defensive security
  • Intermediate

Enterprise Defense in Depth.

Assess an enterprise attack surface, implement layered security controls, and examine how those controls hold up against adversary activity.

Duration
5 days
Level
Intermediate
Delivery
In-person / Remote
Completion
Accredible certificate

Enterprise hardening

Course overview.

Enterprise Defense in Depth examines how layers of security affect an enterprise's attack surface. Students work through the purpose, implementation, and validation of controls rather than treating hardening as a checklist.

The course covers enterprise security controls and Windows domain security, including Active Directory, Group Policy, administrative tiering, local administrator password management, and PowerShell logging. Exercises connect configuration choices to adversary activity and the evidence available to defenders.

Who it is for

  • Security engineers
  • Windows and Active Directory administrators
  • Defenders responsible for enterprise hardening

Tools and concepts

  • Active Directory
  • Group Policy
  • Windows LAPS
  • PowerShell logging
  • Enterprise security controls

Learning outcomes

What your team will practice.

  • Evaluate an enterprise environment using defense-in-depth principles.

  • Select and apply controls in response to observed enterprise risks.

  • Use directory structure and policy to strengthen enterprise security boundaries.

  • Apply administrative tiering and local administrator password controls.

  • Use PowerShell logging to examine activity and assess the visibility provided by controls.

Curriculum

Inside the course.

Topics covered across five days of instructor-led training.

01

Layered defense and attack surface

Evaluate an enterprise environment using defense-in-depth principles.

  • Enterprise attack surfaces
  • Layered security principles
  • Security control impact analysis
02

Enterprise security controls

Select and apply controls in response to observed enterprise risks.

  • Control placement and purpose
  • Attack techniques and control behavior
  • Evaluating control effectiveness
03

Active Directory and Group Policy

Use directory structure and policy to strengthen enterprise security boundaries.

  • Active Directory fundamentals
  • Group Policy configuration
  • Directory administration boundaries
04

Privileged access hardening

Apply administrative tiering and local administrator password controls.

  • Active Directory tiering
  • Windows LAPS
  • Reducing exposure of privileged access
05

Logging and control validation

Use PowerShell logging to examine activity and assess the visibility provided by controls.

  • PowerShell logging
  • Interpreting recorded activity
  • Reviewing control impact

Preparation

Before your team attends.

Prerequisites

  • Working knowledge of Windows administration and networking.
  • Familiarity with Active Directory and enterprise security operations.

What to bring

  • A laptop, charger, and a modern web browser.
  • Internet access suitable for connecting to the training environment.

What is included

  • Instructor-led demonstrations and guided lab exercises.
  • Course reference materials.
  • An Accredible certificate of completion.

Workforce alignment

NICE Framework alignment.

Course objectives align with selected parts of the NICE Framework, version 2.2.0. This is a curriculum alignment, not full work-role qualification or NIST endorsement.

  • Systems AdministrationIO-WRL-005
  • Systems Security AnalysisIO-WRL-006
  • Vulnerability AnalysisPD-WRL-007
View curriculum alignment

Product-specific configuration examples support broader NICE control and administration objectives; they are not separate framework certifications.

  1. Layered defense and attack surface

    Evaluate an enterprise environment using defense-in-depth principles.

    Related work roles: Systems Security Analysis (IO-WRL-006); Vulnerability Analysis (PD-WRL-007)

    tasks
    • T0262Employ approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, security robustness)
    • T1619Perform risk and vulnerability assessments
    knowledge
    • K0791Knowledge of defense-in-depth principles and practices
    • K1212Knowledge of security controls
    skills
    • S0667Skill in assessing security controls

    The objective combines defense-in-depth reasoning with assessment of an enterprise's controls and exposure.

  2. Enterprise security controls

    Select and apply controls in response to observed enterprise risks.

    Related work roles: Systems Security Analysis (IO-WRL-006); Vulnerability Analysis (PD-WRL-007)

    tasks
    • T1919Implement system security controls
    • T0309Assess the effectiveness of security controls
    knowledge
    • K1212Knowledge of security controls
    • K0791Knowledge of defense-in-depth principles and practices
    skills
    • S0097Skill in applying security controls
    • S0667Skill in assessing security controls

    Students apply controls and evaluate their behavior, which directly supports implementation and assessment tasks.

  3. Active Directory and Group Policy

    Use directory structure and policy to strengthen enterprise security boundaries.

    Related work roles: Systems Administration (IO-WRL-005); Systems Security Analysis (IO-WRL-006)

    tasks
    • T1130Develop group policies and access control lists
    knowledge
    • K0685Knowledge of access control principles and practices
    • K1212Knowledge of security controls
    skills
    • S0097Skill in applying security controls

    Group Policy exercises support access-control and system-control implementation.

  4. Privileged access hardening

    Apply administrative tiering and local administrator password controls.

    Related work roles: Systems Administration (IO-WRL-005)

    tasks
    • T1919Implement system security controls
    knowledge
    • K0685Knowledge of access control principles and practices
    • K0686Knowledge of authentication and authorization tools and techniques
    skills
    • S0097Skill in applying security controls

    Tiering and password controls practice security-control implementation; the mapping does not imply full identity-program coverage.

  5. Logging and control validation

    Use PowerShell logging to examine activity and assess the visibility provided by controls.

    Related work roles: Systems Security Analysis (IO-WRL-006); Vulnerability Analysis (PD-WRL-007)

    tasks
    • T0309Assess the effectiveness of security controls
    knowledge
    • K0897Knowledge of logging tools and technologies
    • K1212Knowledge of security controls
    skills
    • S0866Skill in performing log file analysis
    • S0667Skill in assessing security controls

    Log analysis supplies evidence for assessing security-control effectiveness.

NIST NICE Framework source data

Bring EDD to your team.

Tell us your team size, preferred dates, and delivery format. Include EDD in your inquiry.