Endpoint Security Engineering

Master Endpoint Security Engineering

Design, deploy and harden an endpoint estate. Onboarding and device health, compliance and Conditional Access, attack surface reduction, antivirus engineering, device and application control, EDR configuration, and the same controls across servers and non-Windows platforms. Detection, hunting and response are covered in SEC411 Endpoint Security Operations.

Included with Specialist, from $29/month, or $289/year and save 25%. Preview the first module free, no account needed.
Practice included: scored investigation scenarios, plus the Practice Hub.
View Pricing Download Lab Pack Download Toolkit Take End of Course Exam → 34 CPE Credits

What you'll be able to do

✓Deploy, configure, and optimize Microsoft Defender for Endpoint across Windows, macOS, Linux, and mobile devices
✓Design and enforce effective Intune security policies, compliance rules, and attack surface reduction (ASR) controls
✓Implement comprehensive endpoint hardening, exploit protection, and next-generation antivirus strategies
✓Investigate and respond to endpoint threats using advanced hunting, live response, and automated remediation
✓Tune Defender for Endpoint and Intune to reduce noise while maximizing real threat detection and prevention
✓Build and maintain a resilient, scalable endpoint security program that works in hybrid and cloud-first environments
ARC402 | Specialist tier | 10 modules across 4 phases | 30–34 hours at your own pace | 34 CPE credits | No prerequisite

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Phase 1: Foundations

Module 0Course OrientationCourse Preview

What Endpoint Security Engineering teaches: engineer layered endpoint defense across a Windows, macOS, Linux, and mobile fleet using Defender for Endpoint, Intune, ASR, and EDR to stop advanced attacks. The defense stack you'll build, the baselines and detections you walk away with, and how the course is structured. Start here.

Show 12 lessonsHide lessons
  1. 0.1ES0.1 Why Traditional AV FailsPreview
  2. 0.2ES0.2 Modern Attack Chains on EndpointsPreview
  3. 0.3ES0.3 The Endpoint Security StackPreview
  4. 0.4ES0.4 Key MetricsPreview
  5. 0.5ES0.5 The Microsoft Ecosystem ViewPreview
  6. 0.6ES0.6 The NE Endpoint LandscapePreview
  7. 0.7ES0.7 The Deployment SequencePreview
  8. 0.8ES0.8 The Blast Radius ProblemPreview
  9. 0.9ES0.9 Endpoint Security Maturity ModelPreview
  10. 0.10ES0.10 The Attacker PerspectivePreview
  11. 0.11ES0.11 See It Done: The AssessmentPreview
  12. 0.12Module SummaryPreview

Phase 2: Protection Engineering

Module 7ES7, EDR Configuration & Automated Response

The response settings that decide what happens without you and what you can do by hand: automation levels per device group, live response and its dependencies, three containment actions, indicator precedence, alert tuning, and the telemetry underneath all of it.

Show 12 lessonsHide lessons
  1. 7.1ES7.1 EDR Beyond Default
  2. 7.2ES7.2 Automatic Remediation
  3. 7.3ES7.3 Choosing the Automation Level
  4. 7.4ES7.4 Live Response Configuration
  5. 7.5ES7.5 Live Response Scripting
  6. 7.6ES7.6 Device Isolation and Containment
  7. 7.7ES7.7 Indicator Management
  8. 7.8ES7.8 Alert Tuning and Suppression
  9. 7.9ES7.9 Threat Analytics
  10. 7.10ES7.10 EDR Telemetry Optimization
  11. 7.11ES7.11 See It Done: The Response
  12. 7.12Module Summary

Phase 0: Course Resources

ResourcesCheatsheets

Subject-area sheets for endpoint work: the query, where the control lives in the portal, what the fields mean, and what the answer does not prove.

Show 6 lessonsHide lessons
  1. 1Onboarding and Device Health
  2. 2Attack Surface Reduction Rules
  3. 3Antivirus and Behavioral Protection
  4. 4Device, Application and Exploit Control
  5. 5EDR Configuration and Automated Response
  6. 6Servers, Linux and Cross-Platform
ResourcesCookbooks

Seven procedures an endpoint engineer repeats: deploying a control from audit to enforce, onboarding a population, triaging an alert, and collecting from a live host.

Show 4 lessonsHide lessons
  1. 1Deploying a Protection Control
  2. 2Onboarding a Device Population
  3. 3Building an Exclusion Set
  4. 4Deploying Application Control
ResourcesLab Setup

A complete endpoint lab: tenant, licensing, virtual machines, onboarding, safe test activity, and the checks that prove it works.

Show 5 lessonsHide lessons
  1. 1Tenant and Licensing
  2. 2Building the Endpoints
  3. 3Onboarding and Telemetry
  4. 4Generating Test Activity
  5. 5Verify and Limits
ResourcesWalkthroughs

Worked endpoint investigations end to end, including the wrong turns, the queries that looked right and were not, and what would have changed each answer.

Show 3 lessonsHide lessons
  1. 1The Rule That Was Never Enforcing
  2. 2The Device That Was Not Reporting
  3. 3The Exclusion That Hid It
ResourcesPlaybooks

Seven endpoint events with a procedure each: prerequisites, a pre-flight that validates the sources, a numbered sequence, tiered disposition and a worked handoff.

Show 3 lessonsHide lessons
  1. 1A Device Stopped Reporting
  2. 2A Control Started Blocking at Volume
  3. 3An Unmanaged Device Appeared
ResourcesPlayground

Where to practice the endpoint work in this course against real data and real machines.

ResourcesOperational Reference

Every command, query, configuration file and check from the Endpoint Security course, consolidated for the working moment rather than for learning.

Show 1 lessonHide lessons
  1. 1Server and Linux Onboarding

Course Completion

CompletionCourse Exam

Endpoint Security Engineering end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.

Show 1 lessonHide lessons
  1. 1Course Completion. Endpoint Security Engineering

Course overview

The Endpoint Security Engineering course is built specifically for Security Engineers and Administrators who configure, tune, and maintain Microsoft Defender for Endpoint, Intune security policies, and endpoint hardening. You'll gain hands-on expertise to:

✓ Deploy, configure, and optimize Microsoft Defender for Endpoint for maximum protection and visibility
✓ Design and enforce secure Intune policies for device compliance, configuration, and attack surface reduction
✓ Implement endpoint hardening, exploit protection, and next-generation antivirus strategies
✓ Configure EDR response actions and automation levels, and know where automation is the wrong answer

By the end, you'll have the practical skills and confidence to own your organization's endpoint security program, reducing risk, minimizing breaches, and keeping endpoints secure at scale across hybrid and cloud environments.

How this course works

This course builds an endpoint security capability in the order it has to be built, because each layer depends on the one under it. The loop repeats through every control it deploys.

1. Understand what the operating system is doing. Endpoint controls intercept OS behavior. Configuring them without knowing what they intercept produces settings nobody can explain.

2. Deploy so the telemetry is trustworthy. Onboarding, device health and compliance first. A control on a device that stopped reporting is a control you believe you have.

3. Configure for what it must stop, then measure the cost. Attack surface reduction, application control and device control each block something legitimate. Knowing what, before enforcement, is the whole job.

4. Detect what the controls let through. No preventive layer is complete, so each phase measures what its control lets through rather than assuming it holds.

5. Practice the response before you need it. Triage, containment and artifact collection, on the same endpoints you configured.

The course closes on a complete endpoint security architecture assembled from every layer built along the way.

What this course assumes

No minimum experience and no prerequisite course. OS internals, the Defender architecture and every control surface are introduced from the beginning.

What makes it go faster: a tenant with Defender for Endpoint and a device to onboard. Not required, and every configuration is shown with the portal path and the policy behind it.

What this course does not cover: endpoint detection engineering, hunting, alert triage and forensic readiness, which are SEC411 Endpoint Security Operations; and deep Windows forensics, malware reverse engineering and network security. This is engineering and operating the endpoint layer.

Who this course is for

You're a Security Engineer or Administrator responsible for configuring, tuning, and maintaining Microsoft Defender for Endpoint, Intune security policies, and endpoint hardening. This course is built for you if you want to:

✓ Move from basic setup to advanced configuration and optimization of enterprise endpoint security
✓ Master Defender for Endpoint and Intune to effectively block modern endpoint threats
✓ Gain deep skills in attack surface reduction, device hardening and cross-platform coverage
✓ Own your organization's endpoint security posture with confidence and measurable results

In short: if you're ready to become the go-to expert who keeps endpoints secure at scale and significantly reduces breach risk, this course is for you.

What you'll learn

By the end of this Endpoint Security Engineering course you will be able to:

✓ Deploy and fully configure Microsoft Defender for Endpoint with optimal security settings
✓ Create, manage, and tune Intune policies for device compliance, configuration profiles, and attack surface reduction
✓ Implement endpoint hardening techniques including exploit protection, application control, and secure boot
✓ Extend every control to servers, Linux and macOS, with the platform limits named
✓ Measure what each control costs before enforcing it, and defend every exception you grant
✓ Measure, monitor, and continuously improve endpoint security posture across the organization

Key course takeaways

✓ Build and maintain a production-grade endpoint security program using Microsoft Defender for Endpoint and Intune
✓ Master advanced configuration and tuning of Defender for Endpoint to stop sophisticated attacks
✓ Deploy effective attack surface reduction rules, device hardening, and policy enforcement at scale
✓ Configure the response actions an incident will use, and test them before one arrives
✓ Significantly reduce endpoint risk while lowering operational overhead and alert noise
✓ Become the endpoint security expert organizations rely on to protect their most exposed attack surface

Lab Pack - the configurations and the data to work them against

Separate from the toolkit, deliberately. The toolkit is read-only code you take to a real estate. This is material to learn against.

Configurations: An attack surface reduction deployment with a per-rule position for the audit-then-promote sequence, and a Sysmon baseline tuned to complement the endpoint sensor rather than duplicate it.

Data: An audit event set, so the promotion decision in ES4.3 can be worked without a live tenant. Reading evidence whose answer you can check is the point.

KQL: What a rule would have blocked by application and population, the four device health cells as counts rather than a percentage, and running mode with signature age across the estate.

Templates: The architecture document the capstone produces, section by section against the modules.

Test before using in your environment. These configurations are tuned for the course environment. Deploy every one in audit mode first, measure what it would have blocked against your own estate, and validate under your own change process before enforcing anything.

Endpoint Security Engineering Lab Pack
ASR config · Sysmon baseline · audit data set · 3 KQL packs · architecture template
Download Lab Pack (.zip)

Toolkit - the readbacks, to take with you

Separate from the lab pack, deliberately. The lab pack is evidence and configuration to learn against. This is code you take to a real estate, and the two carry different risk.

ESIR, a PowerShell module. Eight functions, one per verification question the course asks: whether the antivirus engine is acting rather than merely enabled, which of the four links behind the cloud protection switch are set, what is excluded and whether the automatic layer was switched off, which attack surface rules are configured against which are acting, the effective application control mode per collection, what the device control default enforcement permits, the exploit mitigations in force, and all of it as one row per machine for a fleet sweep.

Three shell scripts for the platforms that are not PowerShell. The Linux reader takes the supplementary events subsystem first, because that is the field distinguishing a host collecting everything from one on the netlink fallback collecting process events alone. The macOS reader takes full disk access by command, because a permission granted through a management profile is not displayed in the operating system's own privacy pane and checking there returns a false negative on a working Mac. The third reads whether the mandatory integrity layer four of your macOS controls rest on still holds.

Read-only, by design. There is no Set- verb anywhere in it and no script writes, installs or remediates. A readback that can also change a setting is a readback nobody will let you run on a production server. Each function also reports what it could not establish alongside what it could: it will tell you the engine is passive and refuse to call that unprotected, because only the first of those is a reading.

Test before using in your environment. These are written against the command lines this course teaches and are built for the lab: run them first against a machine whose answer you already know, satisfy yourself they report what you expect, and validate them under your own change process before they go anywhere near live work.

ARC402 Endpoint Security Toolkit
8 PowerShell functions · 3 shell readers · Windows, Linux and macOS · Apache 2.0
Download Toolkit (.zip)

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs each take one control that was deployed and was not working, from the reading that found it to the fix: a rule that was never enforcing, a device that was not reporting, and an exclusion that hid the thing it was supposed to let through.
✓ Cookbooks take a repeatable job each and give you the sequence: deploying a protection control, onboarding a device population, building an exclusion set, and deploying application control.
✓ Playbooks for the three things that will actually page you: a device stopped reporting, a control started blocking at volume, and an unmanaged device appeared.
✓ Cheatsheets grouped by control rather than by product, one per phase of the course, for the point at which you know what you are doing and need the exact setting, command or table.
✓ A lab setup guide covering tenant and licensing, building the endpoints, onboarding and telemetry, generating test activity, and what the environment cannot show you.
✓ An operational reference for the settings and commands the course leans on most, kept as a lookup rather than as teaching.
✓ A playground that says where to practice this work against real data: the Incident Lab for scenarios against a full corpus, the SOC Simulator, and the Playbook Suite for what happens once a control fires. Each one says why it is worth working rather than only linking to it.

Study Guide - Endpoint Security Engineering

The course as a book. Ten chapters following the modules, every section of the course inside them, and under each one what it teaches, the settings and commands that do the work and the figures that show it. 195 pages.

It is generated from the published course rather than written alongside it, so it cannot drift from what you are being taught. Yours to print, annotate and keep, including after a subscription lapses.

ARC402 Study Guide
195 pages · 10 chapters · 110 sections · 808 topics · 260 figures
Download Study Guide (.pdf)

Things you need to know

What are the prerequisites for this course?

There are no prerequisites. The course teaches endpoint security from first principles. Familiarity with the Microsoft 365 admin center and Intune will help you move faster through the early modules, but neither is required. Every concept is explained at first use.

What are the device requirements?

A device with at least 8 GB of RAM. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with Defender for Endpoint and Intune for hands-on configuration. The lab pack provides synthetic data if you cannot use a live environment.

How will the course benefit your career?

Endpoints remain the most common initial access vector in breaches. Organizations need engineers who can tune Defender for Endpoint beyond defaults, promote ASR rules to block mode with confidence, and defend every exception the estate carries. This course gives you those skills.

The demand for endpoint security engineers continues to grow as organizations move from basic MDE onboarding to fully tuned, multi-platform endpoint security programs.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may deploy configurations, policies, and scripts in your production environment. You may not redistribute course content or share account credentials.

Endpoint security configurations: All Intune policies, ASR configs, device control policies and Sysmon configs are provided as-is. Test every configuration in audit mode before enforcement. Ridgeline Cyber Defence is not responsible for operational impact from deployed configurations.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.