Endpoint Security Engineering
Master Endpoint Security Engineering
Design, deploy and harden an endpoint estate. Onboarding and device health, compliance and Conditional Access, attack surface reduction, antivirus engineering, device and application control, EDR configuration, and the same controls across servers and non-Windows platforms. Detection, hunting and response are covered in SEC411 Endpoint Security Operations.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations
What Endpoint Security Engineering teaches: engineer layered endpoint defense across a Windows, macOS, Linux, and mobile fleet using Defender for Endpoint, Intune, ASR, and EDR to stop advanced attacks. The defense stack you'll build, the baselines and detections you walk away with, and how the course is structured. Start here.
Show 12 lessonsHide lessons
- 0.1ES0.1 Why Traditional AV FailsPreview
- 0.2ES0.2 Modern Attack Chains on EndpointsPreview
- 0.3ES0.3 The Endpoint Security StackPreview
- 0.4ES0.4 Key MetricsPreview
- 0.5ES0.5 The Microsoft Ecosystem ViewPreview
- 0.6ES0.6 The NE Endpoint LandscapePreview
- 0.7ES0.7 The Deployment SequencePreview
- 0.8ES0.8 The Blast Radius ProblemPreview
- 0.9ES0.9 Endpoint Security Maturity ModelPreview
- 0.10ES0.10 The Attacker PerspectivePreview
- 0.11ES0.11 See It Done: The AssessmentPreview
- 0.12Module SummaryPreview
The mechanisms underneath the controls. Process and token model, credential storage, registry persistence, the event providers a sensor consumes, and the Linux and macOS equivalents, read as the things a control is a bet about.
Show 12 lessonsHide lessons
- 1.1ES1.1 Windows Process Model for Security Practitioners
- 1.2ES1.2 LSASS and Credential Storage
- 1.3ES1.3 Windows Registry as an Attack Surface
- 1.4ES1.4 Event Tracing for Windows
- 1.5ES1.5 Windows Security Subsystem Architecture
- 1.6ES1.6 Linux Kernel and eBPF for Security
- 1.7ES1.7 Linux Authentication and the Privilege Model
- 1.8ES1.8 macOS Security Architecture
- 1.9ES1.9 What Attackers Actually Target
- 1.10ES1.10 From Internals to Controls
- 1.11ES1.11 See It Done: Three Assessments, Two Made It Worse
- 1.12Module Summary and Knowledge Check
Phase 2: Protection Engineering
What the sensor is, where the data goes and for how long, the five onboarding routes and what each one costs, and the difference between a device that is onboarded and a device that is reporting.
Show 12 lessonsHide lessons
- 2.1ES2.1 MDE Sensor Architecture
- 2.2ES2.2 Cloud-Side Processing and Data Flow
- 2.3ES2.3 Licensing Tiers: Operational Reality
- 2.4ES2.4 Onboarding Methods Compared
- 2.5ES2.5 Intune-Based Onboarding at Scale
- 2.6ES2.6 Server and Linux Onboarding
- 2.7ES2.7 Onboarding Validation and Troubleshooting
- 2.8ES2.8 Device Health Monitoring
- 2.9ES2.9 Device Groups, Tags, and RBAC
- 2.10ES2.10 Mobile and Non-Traditional Endpoints
- 2.11ES2.11 See It Done: Eight Weeks, Ninety-Six Per Cent, and a Gap
- 2.12Module Summary and Knowledge Check
Getting a configuration onto a device and knowing it took. Rollout sequencing, the settings conflicts that decide who wins, compliance as an input to access, and the difference between a policy that applied and a device that changed.
Show 12 lessonsHide lessons
- 3.1ES3.1 The Rollout Sequence
- 3.2ES3.2 Tamper Protection and Controlled Configuration
- 3.3ES3.3 Settings Conflicts: GPO, Intune, and the Defender CSP
- 3.4ES3.4 Compliance Policies That Enforce
- 3.5ES3.5 The Windows Compliance Baseline
- 3.6ES3.6 Compliance on macOS, iOS and Android
- 3.7ES3.7 Enforcing Compliance Through Conditional Access
- 3.8ES3.8 Security Baselines and the Policies That Overlap Them
- 3.9ES3.9 Remediating Non-Compliant Devices
- 3.10ES3.10 Measuring What the Controls Cost
- 3.11ES3.11 See It Done: Sixteen Weeks and a Date Nobody Planned For
- 3.12Module Summary and Knowledge Check
The rules individually rather than as a catalog, an audit-first deployment with exit criteria, exclusions written from evidence, and the difference between a rule that is enabled and a rule that is enforcing.
Show 12 lessonsHide lessons
- 4.1ES4.1 What ASR Rules Actually Block
- 4.2ES4.2 The Audit-First Deployment
- 4.3ES4.3 Writing an Exclusion From Audit Data
- 4.4ES4.4 The Standard Protection Set
- 4.5ES4.5 The Rules That Needed the Audit
- 4.6ES4.6 The Rules Most Estates Never Enable
- 4.7ES4.7 The Mode You Set and the Mode You Get
- 4.8ES4.8 Standing Arrangements for Line-of-Business Software
- 4.9ES4.9 Controlled Folder Access
- 4.10ES4.10 Keeping the Posture True
- 4.11ES4.11 See It Done: Five Steps and Three Decisions
- 4.12Module Summary and Knowledge Check
What a Defender antivirus estate is actually doing, as opposed to what its settings say. Prerequisite chains, silent controls, exclusions that exempt more than they name, and the difference between enabled and healthy.
Show 12 lessonsHide lessons
- 5.1ES5.1 Configured, and Doing Nothing
- 5.2ES5.2 The Cloud Is a Network Dependency
- 5.3ES5.3 Which Engine Caught It
- 5.4ES5.4 The Rule That Tells Nobody
- 5.5ES5.5 The Layer for Everything That Is Not Edge
- 5.6ES5.6 A Schedule Is a Request
- 5.7ES5.7 The Exclusion List Is a Target
- 5.8ES5.8 The Category Defined by Judgment
- 5.9ES5.9 Enabled Is Not Healthy
- 5.10ES5.10 Servers Are Not Large Workstations
- 5.11ES5.11 See It Done: One Afternoon, Six Controls
- 5.12Module Summary
The distance between a control that is enabled and a control that is enforcing. Device families nobody watched, policies that governed the wrong category of code, and modes whose names describe their lists rather than their effects.
Show 12 lessonsHide lessons
- 6.1ES6.1 One Switch, Every Device Family
- 6.2ES6.2 A Printer That Writes to Disk
- 6.3ES6.3 Not a Security Feature, in So Many Words
- 6.4ES6.4 Two Defaults That Are Not What You Assume
- 6.5ES6.5 Trust That Depends On How A File Arrived
- 6.6ES6.6 Changing How A Process Behaves
- 6.7ES6.7 A Filter That Reads A Name Off The Wire
- 6.8ES6.8 It Has To Classify Before It Can Decide
- 6.9ES6.9 Four Innocent Reasons A Query Returns Nothing
- 6.10ES6.10 Writing The Policy Itself
- 6.11ES6.11 One Intrusion, Ten Controls
- 6.12Module Summary
The response settings that decide what happens without you and what you can do by hand: automation levels per device group, live response and its dependencies, three containment actions, indicator precedence, alert tuning, and the telemetry underneath all of it.
Show 12 lessonsHide lessons
- 7.1ES7.1 EDR Beyond Default
- 7.2ES7.2 Automatic Remediation
- 7.3ES7.3 Choosing the Automation Level
- 7.4ES7.4 Live Response Configuration
- 7.5ES7.5 Live Response Scripting
- 7.6ES7.6 Device Isolation and Containment
- 7.7ES7.7 Indicator Management
- 7.8ES7.8 Alert Tuning and Suppression
- 7.9ES7.9 Threat Analytics
- 7.10ES7.10 EDR Telemetry Optimization
- 7.11ES7.11 See It Done: The Response
- 7.12Module Summary
Phase 3: Cross-Platform
Extend the endpoint security architecture to servers, Linux, macOS, and VDI. Role-specific configurations for DCs, SQL, IIS, and file servers. Defender for Linux with eBPF. Sysmon for Linux. Cross-platform hunting queries.
Show 12 lessonsHide lessons
- 8.1ES8.1 Server Security Architecture
- 8.2ES8.2 Domain Controller Protection
- 8.3ES8.3 SQL, IIS and File Server Protection
- 8.4ES8.4 CIS Benchmarks and Server Hardening
- 8.5ES8.5 Defender for Linux Deployment
- 8.6ES8.6 eBPF-Based Detection on Linux
- 8.7ES8.7 Sysmon for Linux
- 8.8ES8.8 macOS Endpoint Security
- 8.9ES8.9 Unified Hunting Across Platforms
- 8.10ES8.10 VDI and Multi-Session Environments
- 8.11ES8.11 See It Done: Four Platforms, One Intrusion
- 8.12Module Summary
Phase 4: The Project
One estate, nine phases, and a document somebody can be held to. Everything from ES0 to ES8 applied to Northgate as a single engineering project, from the assessment nobody has done to the architecture record that outlives the people who wrote it.
Show 12 lessonsHide lessons
- 9.1ES9.1 Capstone Briefing
- 9.2ES9.2 Phase 1: Assessment and Planning
- 9.3ES9.3 Phase 2: Onboarding and Device Health
- 9.4ES9.4 Phase 3: Compliance and Conditional Access
- 9.5ES9.5 Phase 4: Attack Surface Reduction
- 9.6ES9.6 Phase 5: Antivirus and Behavioral Protection
- 9.7ES9.7 Phase 6: Device, Application and Exploit Control
- 9.8ES9.8 Phase 7: EDR Configuration and Automated Response
- 9.9ES9.9 Phase 8: Servers, Linux and Cross-Platform
- 9.10ES9.10 Phase 9: Vulnerability Management
- 9.11ES9.11 Validation, Governance and the Architecture Document
- 9.12Module Summary
Phase 0: Course Resources
Subject-area sheets for endpoint work: the query, where the control lives in the portal, what the fields mean, and what the answer does not prove.
Seven procedures an endpoint engineer repeats: deploying a control from audit to enforce, onboarding a population, triaging an alert, and collecting from a live host.
Show 4 lessonsHide lessons
A complete endpoint lab: tenant, licensing, virtual machines, onboarding, safe test activity, and the checks that prove it works.
Show 5 lessonsHide lessons
Worked endpoint investigations end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.
Show 3 lessonsHide lessons
Seven endpoint events with a procedure each: prerequisites, a pre-flight that validates the sources, a numbered sequence, tiered disposition and a worked handoff.
Show 3 lessonsHide lessons
Where to practice the endpoint work in this course against real data and real machines.
Every command, query, configuration file and check from the Endpoint Security course, consolidated for the working moment rather than for learning.
Show 1 lessonHide lessons
Course Completion
Endpoint Security Engineering end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Endpoint Security Engineering course is built specifically for Security Engineers and Administrators who configure, tune, and maintain Microsoft Defender for Endpoint, Intune security policies, and endpoint hardening. You'll gain hands-on expertise to:
By the end, you'll have the practical skills and confidence to own your organization's endpoint security program, reducing risk, minimizing breaches, and keeping endpoints secure at scale across hybrid and cloud environments.
How this course works
This course builds an endpoint security capability in the order it has to be built, because each layer depends on the one under it. The loop repeats through every control it deploys.
1. Understand what the operating system is doing. Endpoint controls intercept OS behavior. Configuring them without knowing what they intercept produces settings nobody can explain.
2. Deploy so the telemetry is trustworthy. Onboarding, device health and compliance first. A control on a device that stopped reporting is a control you believe you have.
3. Configure for what it must stop, then measure the cost. Attack surface reduction, application control and device control each block something legitimate. Knowing what, before enforcement, is the whole job.
4. Detect what the controls let through. No preventive layer is complete, so each phase measures what its control lets through rather than assuming it holds.
5. Practice the response before you need it. Triage, containment and artifact collection, on the same endpoints you configured.
The course closes on a complete endpoint security architecture assembled from every layer built along the way.
What this course assumes
No minimum experience and no prerequisite course. OS internals, the Defender architecture and every control surface are introduced from the beginning.
What makes it go faster: a tenant with Defender for Endpoint and a device to onboard. Not required, and every configuration is shown with the portal path and the policy behind it.
What this course does not cover: endpoint detection engineering, hunting, alert triage and forensic readiness, which are SEC411 Endpoint Security Operations; and deep Windows forensics, malware reverse engineering and network security. This is engineering and operating the endpoint layer.
Who this course is for
You're a Security Engineer or Administrator responsible for configuring, tuning, and maintaining Microsoft Defender for Endpoint, Intune security policies, and endpoint hardening. This course is built for you if you want to:
In short: if you're ready to become the go-to expert who keeps endpoints secure at scale and significantly reduces breach risk, this course is for you.
What you'll learn
By the end of this Endpoint Security Engineering course you will be able to:
Key course takeaways
Lab Pack - the configurations and the data to work them against
Separate from the toolkit, deliberately. The toolkit is read-only code you take to a real estate. This is material to learn against.
Configurations: An attack surface reduction deployment with a per-rule position for the audit-then-promote sequence, and a Sysmon baseline tuned to complement the endpoint sensor rather than duplicate it.
Data: An audit event set, so the promotion decision in ES4.3 can be worked without a live tenant. Reading evidence whose answer you can check is the point.
KQL: What a rule would have blocked by application and population, the four device health cells as counts rather than a percentage, and running mode with signature age across the estate.
Templates: The architecture document the capstone produces, section by section against the modules.
Test before using in your environment. These configurations are tuned for the course environment. Deploy every one in audit mode first, measure what it would have blocked against your own estate, and validate under your own change process before enforcing anything.
Toolkit - the readbacks, to take with you
Separate from the lab pack, deliberately. The lab pack is evidence and configuration to learn against. This is code you take to a real estate, and the two carry different risk.
ESIR, a PowerShell module. Eight functions, one per verification question the course asks: whether the antivirus engine is acting rather than merely enabled, which of the four links behind the cloud protection switch are set, what is excluded and whether the automatic layer was switched off, which attack surface rules are configured against which are acting, the effective application control mode per collection, what the device control default enforcement permits, the exploit mitigations in force, and all of it as one row per machine for a fleet sweep.
Three shell scripts for the platforms that are not PowerShell. The Linux reader takes the supplementary events subsystem first, because that is the field distinguishing a host collecting everything from one on the netlink fallback collecting process events alone. The macOS reader takes full disk access by command, because a permission granted through a management profile is not displayed in the operating system's own privacy pane and checking there returns a false negative on a working Mac. The third reads whether the mandatory integrity layer four of your macOS controls rest on still holds.
Read-only, by design. There is no Set- verb anywhere in it and no script writes, installs or remediates. A readback that can also change a setting is a readback nobody will let you run on a production server. Each function also reports what it could not establish alongside what it could: it will tell you the engine is passive and refuse to call that unprotected, because only the first of those is a reading.
Test before using in your environment. These are written against the command lines this course teaches and are built for the lab: run them first against a machine whose answer you already know, satisfy yourself they report what you expect, and validate them under your own change process before they go anywhere near live work.
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Study Guide - Endpoint Security Engineering
The course as a book. Ten chapters following the modules, every section of the course inside them, and under each one what it teaches, the settings and commands that do the work and the figures that show it. 195 pages.
It is generated from the published course rather than written alongside it, so it cannot drift from what you are being taught. Yours to print, annotate and keep, including after a subscription lapses.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches endpoint security from first principles. Familiarity with the Microsoft 365 admin center and Intune will help you move faster through the early modules, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with at least 8 GB of RAM. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with Defender for Endpoint and Intune for hands-on configuration. The lab pack provides synthetic data if you cannot use a live environment.
How will the course benefit your career?
Endpoints remain the most common initial access vector in breaches. Organizations need engineers who can tune Defender for Endpoint beyond defaults, promote ASR rules to block mode with confidence, and defend every exception the estate carries. This course gives you those skills.
The demand for endpoint security engineers continues to grow as organizations move from basic MDE onboarding to fully tuned, multi-platform endpoint security programs.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy configurations, policies, and scripts in your production environment. You may not redistribute course content or share account credentials.
Endpoint security configurations: All Intune policies, ASR configs, device control policies and Sysmon configs are provided as-is. Test every configuration in audit mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.