<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="30282" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/masterclass-saddd-l2" lastchanged="2026-01-13T18:59:02+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Master Class: Securing Active Directory Deep Dive LEVEL 2</title><productcode>SADDD-L2</productcode><vendorcode>MT</vendorcode><vendorname>Master Class</vendorname><fullproductcode>MT-SADDD-L2</fullproductcode><version>1.0</version><objective>&lt;p&gt;In this master class course LEVEL 2, the topic of Active Directory security is once again immensely deepened.&lt;/p&gt;
&lt;p&gt;Want to make your crown jewels even more secure?&lt;/p&gt;
&lt;p&gt;Is your environment critical or are you in the &amp;quot;SupplyChain&amp;quot;?&lt;/p&gt;
&lt;p&gt;Or are you even bound to secrecy?&lt;/p&gt;
&lt;p&gt;No problem: We will show you how to secure your environment extremely.&lt;/p&gt;
&lt;p&gt;After more than 100 trainings in this area, this course was created as a worthy successor to the well-known and highly booked MasterClass Active Directory Security.&lt;/p&gt;
&lt;p&gt;That&amp;#039;s why: Understand, harden and monitor so you can sleep better.&lt;/p&gt;</objective><essentials>&lt;p&gt;At least 5 years of experience with Active Directory and client systems&lt;/p&gt;
&lt;p&gt;Prior attendance of the &lt;span class=&quot;cms-link-marked&quot;&gt;&lt;a class=&quot;fl-href-prod&quot; href=&quot;/swisscom/en/course/masterclass-saddd-l1&quot;&gt;&lt;svg role=&quot;img&quot; aria-hidden=&quot;true&quot; focusable=&quot;false&quot; data-nosnippet class=&quot;cms-linkmark&quot;&gt;&lt;use xlink:href=&quot;/css/img/icnset-linkmarks.svg#linkmark&quot;&gt;&lt;/use&gt;&lt;/svg&gt;Master Class: Securing Active Directory Deep Dive &lt;span class=&quot;fl-prod-pcode&quot;&gt;(SADDD-L1)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt; course is REQUIRED AND must be verified.&lt;/p&gt;</essentials><audience>&lt;p&gt;This course is designed for experienced system administrators, consultants and Active Directory designers. After this seminar, you will be able to design, implement and consult on Active Directory in a highly secure manner.&lt;/p&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Review of best practices from the MasterClass Securing Active Directory FastPass.&lt;/li&gt;&lt;li&gt;LAPS for domain controllers - does NOT work - but it does!&lt;br/&gt; We show you how to secure the DSRM password rolling and encrypted incl. password history!&lt;/li&gt;&lt;li&gt;DSRM-User: From emergency administrator to domain admin:&lt;br/&gt;What a simple registry hack can do and what you should do about it...&lt;/li&gt;&lt;li&gt;Unified Write Filter - a completely unknown solution for Windows 10/11 clients: Kiosk mode for professionals and for Privileged Admin Workstation - PAWs with &amp;quot;sheriff cards&amp;quot;)&lt;/li&gt;&lt;li&gt;Multi-tenant Active Directory - how to hide organizational units (Ous) for administrators who should not see them: Object List&lt;br/&gt;No one dares to do it - how to show you how to do it and how the pros do it!&lt;/li&gt;&lt;li&gt;MBAM &amp;amp; Bitlocker: Bitlocker on Steroids&lt;br/&gt;Microsoft BitLocker Administration and Monitoring 2.5 - even if the extended support ends in 2026 - MBAM is absolutely worth a look!&lt;/li&gt;&lt;li&gt;Hiding TIER-0 admins via Powershell&lt;br/&gt;What I can&amp;#039;t see, I can&amp;#039;t attack....&lt;br/&gt;How to hide your crown jewels...&lt;/li&gt;&lt;li&gt;Bloodhound: Hunting for Privileges&lt;br/&gt;Install and use Bloodhound - let&amp;#039;s hunt for privileges!&lt;/li&gt;&lt;li&gt;PAM feature with Server 2016: JEA &amp;amp; JIT&lt;br/&gt;Just enough Administration with JustInTime Administration&lt;br/&gt;With Server 2016 came - for most undiscovered - the PAM feature:&lt;br/&gt;Privileged Access Management for Users: Time-to-Live for Administrators who manage the Tickets&lt;/li&gt;&lt;li&gt;When it should be less:&lt;br/&gt;Authentication Silos &amp;amp; Authentication Policies&lt;br/&gt;Who, How, Where, and When...&lt;/li&gt;&lt;li&gt;Build, maintain and administer tier models en detail&lt;br/&gt;Tier and ESAE model in practice.&lt;/li&gt;&lt;li&gt;Windows Defender for Identity&lt;/li&gt;&lt;li&gt;Lithnet Active Directory Password Protection&lt;/li&gt;&lt;li&gt;DNS-SEC - Run DNS in a highly secure way&lt;br/&gt;Trust-Anchors&lt;br/&gt;DNS over https ( DoH )&lt;/li&gt;&lt;li&gt;SMB encryption AES 256&lt;br/&gt;Operate SMB highly secure&lt;/li&gt;&lt;li&gt;UNC Hardening&lt;/li&gt;&lt;li&gt;From DNS-Admin to DomainAdmin&lt;br/&gt;How to go from small to big...&lt;/li&gt;&lt;li&gt;LocalAccountTokenFilterPolicy&lt;/li&gt;&lt;li&gt;LDAP-S, signing and channel binding&lt;br/&gt;What exactly is it about and why LDAP-S is not LDAP-signing...&lt;/li&gt;&lt;li&gt;LDAP-S and SSL V2, V3 and TLS V1 - what then now&lt;br/&gt;LDAP-S en detail&lt;/li&gt;&lt;li&gt;&amp;quot;Notes from the field - our experience from 10 years of hardening Active Directory
&lt;ul&gt;
&lt;li&gt;LAPS&lt;/li&gt;&lt;li&gt;Protected Users&lt;/li&gt;&lt;li&gt;KRBTGT Reset&lt;/li&gt;&lt;li&gt;PingCastle&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Questions from the participants&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Your Trainer&lt;/h4&gt;&lt;p&gt;The Advanced Master Class was developed by Andy Wendel and is delivered by himself and his experienced team.&lt;/p&gt;
&lt;p&gt;Andy Wendel is a Senior Data Center and Cloud Architect and Certified Security Master Specialization Advanced Windows Security. He was and is trained by the internationally renowned security experts &lt;a class=&quot;cms-href-ext&quot; href=&quot;http://cqure.pl/paula-januszkiewicz/&quot; data-cms-evt-click=&quot;Outbound Links;click;http://cqure.pl/paula-januszkiewicz/&quot;&gt;Paula Januszkiewicz&lt;/a&gt; and &lt;a class=&quot;cms-href-ext&quot; href=&quot;https://www.samilaiho.com/?/&quot; data-cms-evt-click=&quot;Outbound Links;click;https://www.samilaiho.com/?/&quot;&gt;Sami Laiho&lt;/a&gt;. This certification is renewed every year. Andy Wendel has been working as an IT trainer and consultant since the late 1990s and is also a Certified Microsoft Learning Consultant (MCLC). Worldwide, Microsoft has only awarded 56 Certified Learning Consultants.&lt;/p&gt;</contents><objective_plain>In this master class course LEVEL 2, the topic of Active Directory security is once again immensely deepened.

Want to make your crown jewels even more secure?

Is your environment critical or are you in the &quot;SupplyChain&quot;?

Or are you even bound to secrecy?

No problem: We will show you how to secure your environment extremely.

After more than 100 trainings in this area, this course was created as a worthy successor to the well-known and highly booked MasterClass Active Directory Security.

That's why: Understand, harden and monitor so you can sleep better.</objective_plain><essentials_plain>At least 5 years of experience with Active Directory and client systems

Prior attendance of the Master Class: Securing Active Directory Deep Dive (SADDD-L1) course is REQUIRED AND must be verified.</essentials_plain><audience_plain>This course is designed for experienced system administrators, consultants and Active Directory designers. After this seminar, you will be able to design, implement and consult on Active Directory in a highly secure manner.</audience_plain><contents_plain>- Review of best practices from the MasterClass Securing Active Directory FastPass.
- LAPS for domain controllers - does NOT work - but it does!
 We show you how to secure the DSRM password rolling and encrypted incl. password history!
- DSRM-User: From emergency administrator to domain admin:
What a simple registry hack can do and what you should do about it...
- Unified Write Filter - a completely unknown solution for Windows 10/11 clients: Kiosk mode for professionals and for Privileged Admin Workstation - PAWs with &quot;sheriff cards&quot;)
- Multi-tenant Active Directory - how to hide organizational units (Ous) for administrators who should not see them: Object List
No one dares to do it - how to show you how to do it and how the pros do it!
- MBAM &amp; Bitlocker: Bitlocker on Steroids
Microsoft BitLocker Administration and Monitoring 2.5 - even if the extended support ends in 2026 - MBAM is absolutely worth a look!
- Hiding TIER-0 admins via Powershell
What I can't see, I can't attack....
How to hide your crown jewels...
- Bloodhound: Hunting for Privileges
Install and use Bloodhound - let's hunt for privileges!
- PAM feature with Server 2016: JEA &amp; JIT
Just enough Administration with JustInTime Administration
With Server 2016 came - for most undiscovered - the PAM feature:
Privileged Access Management for Users: Time-to-Live for Administrators who manage the Tickets
- When it should be less:
Authentication Silos &amp; Authentication Policies
Who, How, Where, and When...
- Build, maintain and administer tier models en detail
Tier and ESAE model in practice.
- Windows Defender for Identity
- Lithnet Active Directory Password Protection
- DNS-SEC - Run DNS in a highly secure way
Trust-Anchors
DNS over https ( DoH )
- SMB encryption AES 256
Operate SMB highly secure
- UNC Hardening
- From DNS-Admin to DomainAdmin
How to go from small to big...
- LocalAccountTokenFilterPolicy
- LDAP-S, signing and channel binding
What exactly is it about and why LDAP-S is not LDAP-signing...
- LDAP-S and SSL V2, V3 and TLS V1 - what then now
LDAP-S en detail
- &quot;Notes from the field - our experience from 10 years of hardening Active Directory

- LAPS
- Protected Users
- KRBTGT Reset
- PingCastle
- Questions from the participants
Your Trainer

The Advanced Master Class was developed by Andy Wendel and is delivered by himself and his experienced team.

Andy Wendel is a Senior Data Center and Cloud Architect and Certified Security Master Specialization Advanced Windows Security. He was and is trained by the internationally renowned security experts Paula Januszkiewicz (http://cqure.pl/paula-januszkiewicz/) and Sami Laiho (https://www.samilaiho.com/?/). This certification is renewed every year. Andy Wendel has been working as an IT trainer and consultant since the late 1990s and is also a Certified Microsoft Learning Consultant (MCLC). Worldwide, Microsoft has only awarded 56 Certified Learning Consultants.</contents_plain><duration unit="d" days="3">3 days</duration><pricelist><price country="IT" currency="EUR">3800.00</price><price country="NL" currency="EUR">3800.00</price><price country="PL" currency="EUR">3800.00</price><price country="US" currency="USD">4135.00</price><price country="IN" currency="USD">599.00</price><price country="GB" currency="GBP">3160.00</price><price country="CA" currency="CAD">5710.00</price><price country="DE" currency="EUR">3890.00</price><price country="CH" currency="CHF">3890.00</price><price country="AT" currency="EUR">3890.00</price><price country="SE" currency="EUR">3890.00</price><price country="SI" currency="EUR">3890.00</price></pricelist><miles/></course>