Wide-ranging Defender XDR administration via guided simulations
Strengths
Simulation-led practice
The curriculum includes specific simulation items to demonstrate tasks like creating DLP policies and managing endpoint device groups.

Learn how to expertly administer Microsoft Defender XDR (formerly Microsoft 365 Defender) with hands on experience!
InstructorJohn Christopher | 500,000+ enrollments




Coupon

The curriculum includes specific simulation items to demonstrate tasks like creating DLP policies and managing endpoint device groups.
Editorial course preview
These 3 complementary views highlight concrete, legible examples from the course presentation.
This screenshot displays the Microsoft Defender portal interface, highlighting the Policies & rules section in the left-hand navigation menu to guide users through administrative tasks.
This view demonstrates configuring an alert policy by selecting specific trigger conditions, such as activating alerts every time an activity matches the defined rule.
The New Alert Policy setup screen shows the activity condition set to detected malware, with the Next button highlighted to proceed.
Instruction covers various areas including Office 365, Cloud Apps, Identity (Entra ID), and Cloud workload protection.
The course provides instruction on using Kusto Query Language (KQL) for threat identification and unified audit logging.
A lecture explicitly notes that the Defender for Endpoint lab is now deprecated; one signal from before the displayed update suggests difficulty keeping pace with Microsoft's rapid changes, though the update label does not prove a correction has been made.
The curriculum aligns with the target of IT professionals by covering essential setup and various security modules.