<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35393" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/microsoft-sc-5004" lastchanged="2026-07-20T14:44:33+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Defend against cyberthreats with Microsoft Defender XDR</title><productcode>SC-5004</productcode><vendorcode>MS</vendorcode><vendorname>Microsoft</vendorname><fullproductcode>MS-SC-5004</fullproductcode><version>1.0</version><essentials>&lt;ul&gt;
&lt;li&gt;Experience using the Microsoft Defender portal&lt;/li&gt;&lt;li&gt;Basic understanding of Microsoft Defender for Endpoint&lt;/li&gt;&lt;li&gt;Basic understanding of Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Experience using Kusto Query Language (KQL) in Microsoft Sentinel&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;You&amp;#039;ll need to have access to a Microsoft 365 E5 Tenant with a Microsoft Defender for Endpoint P2 license to perform the exercises.&lt;/p&gt;</essentials><contents>&lt;h4&gt;Mitigate incidents using Microsoft Defender&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Use the Microsoft Defender portal&lt;/li&gt;&lt;li&gt;Manage incidents&lt;/li&gt;&lt;li&gt;Investigate incidents&lt;/li&gt;&lt;li&gt;Manage and investigate alerts&lt;/li&gt;&lt;li&gt;Manage automated investigations&lt;/li&gt;&lt;li&gt;Use the action center&lt;/li&gt;&lt;li&gt;Explore advanced hunting&lt;/li&gt;&lt;li&gt;Investigate Microsoft Entra sign-in logs&lt;/li&gt;&lt;li&gt;Understand Microsoft Secure Score&lt;/li&gt;&lt;li&gt;Analyze threat analytics with the Security Copilot Threat Intelligence Briefing Agent&lt;/li&gt;&lt;li&gt;Analyze reports&lt;/li&gt;&lt;li&gt;Configure the Microsoft Defender portal&lt;/li&gt;&lt;li&gt;Module assessment&lt;/li&gt;&lt;li&gt;Summary and resources&lt;/li&gt;&lt;/ul&gt;
&lt;h4&gt;Deploy the Microsoft Defender for Endpoint environment&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Create your environment&lt;/li&gt;&lt;li&gt;Understand operating systems compatibility and features&lt;/li&gt;&lt;li&gt;Onboard devices&lt;/li&gt;&lt;li&gt;Manage access&lt;/li&gt;&lt;li&gt;Create and manage roles for role-based access control&lt;/li&gt;&lt;li&gt;Configure device groups&lt;/li&gt;&lt;li&gt;Configure environment advanced features&lt;/li&gt;&lt;li&gt;Module assessment&lt;/li&gt;&lt;li&gt;Summary and resources&lt;/li&gt;&lt;/ul&gt;
&lt;h4&gt;Configure for alerts and detections in Microsoft Defender for Endpoint&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Configure advanced features&lt;/li&gt;&lt;li&gt;Configure alert notifications&lt;/li&gt;&lt;li&gt;Manage alert suppression&lt;/li&gt;&lt;li&gt;Manage indicators&lt;/li&gt;&lt;li&gt;Module assessment&lt;/li&gt;&lt;li&gt;Summary and resources&lt;/li&gt;&lt;/ul&gt;
&lt;h4&gt;Configure and manage automation using Microsoft Defender for Endpoint&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Configure advanced features&lt;/li&gt;&lt;li&gt;Manage automation upload and folder settings&lt;/li&gt;&lt;li&gt;Configure automated investigation and remediation capabilities&lt;/li&gt;&lt;li&gt;Block at risk devices&lt;/li&gt;&lt;li&gt;Module assessment&lt;/li&gt;&lt;li&gt;Summary and resources&lt;/li&gt;&lt;/ul&gt;
&lt;h4&gt;Perform device investigations in Microsoft Defender for Endpoint&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Use the device inventory list&lt;/li&gt;&lt;li&gt;Investigate the device&lt;/li&gt;&lt;li&gt;Use behavioral blocking&lt;/li&gt;&lt;li&gt;Detect devices with device discovery&lt;/li&gt;&lt;li&gt;Module assessment&lt;/li&gt;&lt;li&gt;Summary and resources&lt;/li&gt;&lt;/ul&gt;
&lt;h4&gt;Defend against Cyberthreats with Microsoft Defender XDR lab exercises&lt;/h4&gt;&lt;ul&gt;
&lt;li&gt;Introduction&lt;/li&gt;&lt;li&gt;Configure the Microsoft Defender XDR environment&lt;/li&gt;&lt;li&gt;Deploy Microsoft Defender for Endpoint&lt;/li&gt;&lt;li&gt;Mitigate Attacks with Microsoft Defender for Endpoint&lt;/li&gt;&lt;li&gt;Summary&lt;/li&gt;&lt;/ul&gt;</contents><essentials_plain>- Experience using the Microsoft Defender portal
- Basic understanding of Microsoft Defender for Endpoint
- Basic understanding of Microsoft Sentinel
- Experience using Kusto Query Language (KQL) in Microsoft Sentinel
You'll need to have access to a Microsoft 365 E5 Tenant with a Microsoft Defender for Endpoint P2 license to perform the exercises.</essentials_plain><contents_plain>Mitigate incidents using Microsoft Defender


- Introduction
- Use the Microsoft Defender portal
- Manage incidents
- Investigate incidents
- Manage and investigate alerts
- Manage automated investigations
- Use the action center
- Explore advanced hunting
- Investigate Microsoft Entra sign-in logs
- Understand Microsoft Secure Score
- Analyze threat analytics with the Security Copilot Threat Intelligence Briefing Agent
- Analyze reports
- Configure the Microsoft Defender portal
- Module assessment
- Summary and resources

Deploy the Microsoft Defender for Endpoint environment


- Introduction
- Create your environment
- Understand operating systems compatibility and features
- Onboard devices
- Manage access
- Create and manage roles for role-based access control
- Configure device groups
- Configure environment advanced features
- Module assessment
- Summary and resources

Configure for alerts and detections in Microsoft Defender for Endpoint


- Introduction
- Configure advanced features
- Configure alert notifications
- Manage alert suppression
- Manage indicators
- Module assessment
- Summary and resources

Configure and manage automation using Microsoft Defender for Endpoint


- Introduction
- Configure advanced features
- Manage automation upload and folder settings
- Configure automated investigation and remediation capabilities
- Block at risk devices
- Module assessment
- Summary and resources

Perform device investigations in Microsoft Defender for Endpoint


- Introduction
- Use the device inventory list
- Investigate the device
- Use behavioral blocking
- Detect devices with device discovery
- Module assessment
- Summary and resources

Defend against Cyberthreats with Microsoft Defender XDR lab exercises


- Introduction
- Configure the Microsoft Defender XDR environment
- Deploy Microsoft Defender for Endpoint
- Mitigate Attacks with Microsoft Defender for Endpoint
- Summary</contents_plain><duration unit="d" days="1">1 day</duration><pricelist><price country="DE" currency="EUR">690.00</price><price country="US" currency="USD">675.00</price><price country="CA" currency="CAD">675.00</price><price country="GB" currency="GBP">940.00</price><price country="D2" currency="EUR">690.00</price><price country="AT" currency="EUR">690.00</price><price country="IT" currency="EUR">490.00</price><price country="NL" currency="EUR">690.00</price><price country="SI" currency="EUR">690.00</price><price country="CH" currency="CHF">690.00</price><price country="FR" currency="EUR">950.00</price></pricelist><miles/></course>