Securing Windows Server 2016, Part 2 of 5: Administrative Access
Interactive

Securing Windows Server 2016, Part 2 of 5: Administrative Access

Biz Library
Updated Feb 04, 2020

This course is all about managing administrative access and a new feature JEA or Just Enough Administration. which is a least privilege model. Then it will cover anti malware and patch management, configuring and managing windows defender, Device Guard and App Locker. Finally it will close out with WSUS and updating central management of patches. This course contains the following lessons:


Lesson 1:

  • Introduction to JEA
  • JEA Components
  • Session Configuration Files
  • Demo: Session Configuration File
  • Role Capability Files
  • Demo: Configure JEA
  • Demo: DNSops File
  • JEA Endpoints
  • Demo: JEA Endpoint
  • Connecting to JEA Endpoints
  • Deploying JEA Endpoints.

Lesson 2:

  • ESAE Forests
  • Administrative Tiers
  • ESAE Best Practices
  • The Clean Source Principle
  • Implementing the Clean Source Principle.

Lesson 3:

  • Overview of MIM
  • MIM Requirements
  • MIM Service Accounts.

Lesson 4:

  • Overview of JIT Administration
  • Privileged Access Management
  • PAM Components
  • Creating an Administrative Forest
  • Configuring Trust Relationships
  • Shadow Principals
  • Configuring the MIM Web Portal
  • Managing and Configuring PAM Roles.

Lesson 5:

  • Understanding Malware
  • Malware Sources
  • Mitigation Methods
  • Windows Defender
  • Demo: Configure Windows Defender
  • Demo: Scan with Windows Defender.

Lesson 6:

  • Controlling Applications
  • Software Restriction Policies
  • Security Levels
  • AppLocker
  • AppLocker
  • Support for AppLocker
  • Creating Default Rules
  • Demo: AppLocker
  • Demo: Create Rules.

Lesson 7:

  • Overview of Device Guard
  • Device Guard Features
  • Configuring Device Guard
  • Device Guard Policies
  • Deploying Code Integrity Policies
  • Control Flow Guard.

Lesson 8:

  • Overview of WSUS
  • Deployment Options
  • Server Requirements
  • Configuring Clients
  • Administering WSUS
  • Approving Updates
  • Demo: Install WSUS
  • Demo: Navigate WSUS
  • Demo: WSUS Options.