<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.de/css/xml-course.xsl"?><course productid="35312" language="en" source="https://portal.flane.de/sap_esi/en/xml-course/masterclass-mde" lastchanged="2026-03-18T11:01:01+01:00" parent="https://portal.flane.de/sap_esi/en/xml-courses"><title>Master Class: Microsoft Defender for Endpoint</title><productcode>MDE</productcode><vendorcode>MT</vendorcode><vendorname>Master Class</vendorname><fullproductcode>MT-MDE</fullproductcode><version>1.0</version><audience>&lt;p&gt;SecOps team members, device administrators and all interested responsible.&lt;/p&gt;</audience><contents>&lt;h5&gt;Microsoft Defender XDR&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Overview of MS Defender XDR&lt;/li&gt;&lt;li&gt;MDE overview and licensing&lt;/li&gt;&lt;li&gt;MDE vs. Microsoft Intune&lt;/li&gt;&lt;li&gt;Zero Trust and MDE&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Microsoft Defender for Endpoint&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;MDE architecture&lt;/li&gt;&lt;li&gt;MDE portal&lt;/li&gt;&lt;li&gt;MDE activation&lt;/li&gt;&lt;li&gt;MDE roles and permissions&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Onboarding/Offboarding&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Windows devices via local script, MS Intune and Group policies&lt;/li&gt;&lt;li&gt;MacOS devices via local script and MS Intune&lt;/li&gt;&lt;li&gt;Linux and Windows Server via Azure Arc&lt;/li&gt;&lt;li&gt;Troubleshoot onboarding issues&lt;/li&gt;&lt;li&gt;Offboard devices&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Endpoint protection &amp;ndash; Attack surface reduction&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Service to Service connection to Microsoft Intune&lt;/li&gt;&lt;li&gt;Attack surface reduction rules&lt;/li&gt;&lt;li&gt;Controlled folder access&lt;/li&gt;&lt;li&gt;Device control&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Endpoint protection &amp;ndash; Next-generation protection&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Cloud protection&lt;/li&gt;&lt;li&gt;Behavior monitoring&lt;/li&gt;&lt;li&gt;Real-time protection&lt;/li&gt;&lt;li&gt;EDR in block mode&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Endpoint detection and response&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Alerts and Incidents management&lt;/li&gt;&lt;li&gt;Automated investigation and response (AIR)&lt;/li&gt;&lt;li&gt;Remediation actions&lt;/li&gt;&lt;li&gt;Device investigation&lt;/li&gt;&lt;li&gt;Device response actions&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Additional configurations&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Advanced features&lt;/li&gt;&lt;li&gt;Indicators&lt;/li&gt;&lt;li&gt;Web content filtering&lt;/li&gt;&lt;li&gt;Vulnerability Management&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Advanced Hunting&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;KQL primer&lt;/li&gt;&lt;li&gt;Important MDE queries&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Endpoint DLP (if time permits)&lt;/h5&gt;</contents><audience_plain>SecOps team members, device administrators and all interested responsible.</audience_plain><contents_plain>Microsoft Defender XDR


- Overview of MS Defender XDR
- MDE overview and licensing
- MDE vs. Microsoft Intune
- Zero Trust and MDE
Microsoft Defender for Endpoint


- MDE architecture
- MDE portal
- MDE activation
- MDE roles and permissions
Onboarding/Offboarding


- Windows devices via local script, MS Intune and Group policies
- MacOS devices via local script and MS Intune
- Linux and Windows Server via Azure Arc
- Troubleshoot onboarding issues
- Offboard devices
Endpoint protection – Attack surface reduction


- Service to Service connection to Microsoft Intune
- Attack surface reduction rules
- Controlled folder access
- Device control
Endpoint protection – Next-generation protection


- Cloud protection
- Behavior monitoring
- Real-time protection
- EDR in block mode
Endpoint detection and response


- Alerts and Incidents management
- Automated investigation and response (AIR)
- Remediation actions
- Device investigation
- Device response actions
Additional configurations


- Advanced features
- Indicators
- Web content filtering
- Vulnerability Management
Advanced Hunting


- KQL primer
- Important MDE queries
Endpoint DLP (if time permits)</contents_plain><duration unit="d" days="4">4 days</duration><pricelist><price country="DE" currency="EUR">3995.00</price><price country="AT" currency="EUR">3995.00</price><price country="SE" currency="EUR">3995.00</price><price country="GB" currency="GBP">3325.00</price><price country="SI" currency="EUR">3995.00</price><price country="CH" currency="CHF">3995.00</price></pricelist><miles/></course>