Loading...
Please wait a moment
Founded by passionate advocates of learning and innovation, Learni set out to make professional training accessible to everyone, everywhere in the world. Our team works in the largest cities such as Paris, Lyon, Marseille, and internationally, to support talents and organizations in their skills development.
Which format do you prefer?
30 free minutes with a training advisor — no commitment.
Loading available slots...
Explore the evolving role of artificial intelligence in crafting tailored educational journeys, with projections for groundbreaking advancements by April 2026.
Master influence and persuasion skills for 2026 with proven strategies, emerging tech, and practical exercises tailored for professional growth in a dynamic world.
Professional Training training in Dallas in July 2026 with Learni. Certified, expert trainers, eligible for employer funding. Free quote.
Discover step-by-step methods to master bookkeeping and accounting fundamentals in April 2026. Explore online courses, tools, practice tips, and future trends like AI integration for aspiring professionals.
The Training Microsoft Defender for Endpoint - Detect and Respond to Advanced Threats training is delivered in-person or remotely (blended-learning, e-learning, virtual classroom, remote in-person). At Learni, a Qualiopi-certified training organization, each program is designed to maximize skills acquisition, regardless of the training mode chosen.
The trainer alternates between demonstrative, interrogative, and active methods (through practical exercises and/or real-world scenarios). This pedagogical approach ensures concrete and directly applicable learning in the workplace.
To ensure the quality of the Training Microsoft Defender for Endpoint - Detect and Respond to Advanced Threats training, Learni provides the following teaching resources:
For in-house training at a location external to Learni, the client ensures and commits to having all necessary teaching materials (IT equipment, internet connection...) for the proper conduct of the training action in accordance with the prerequisites indicated in the communicated training program.
The assessment of skills acquired during the Training Microsoft Defender for Endpoint - Detect and Respond to Advanced Threats training is carried out through:
Learni is committed to the accessibility of its professional training programs. All our training programs are accessible to people with disabilities. Our teams are available to adapt teaching methods to your specific needs. Do not hesitate to contact us for any accommodation request.
Learni training programs are available for inter-company and intra-company settings, both in-person and remote. Registration is possible up to 48 business hours before the start of training. Our programs are eligible for OPCO, Pôle emploi, and FNE-Formation funding. Contact us to discuss your training project and funding possibilities.
Mass installation and onboarding of agents on Windows, Linux, and macOS endpoints, fine-tuned policy configuration via the Defender portal, use of PowerShell for automation scripts, connectivity tests and simulation of enterprise cluster deployments, creation of device groups for segmented management, resolution of complex hybrid Azure AD integration cases, production of a complete readiness report to validate the initial posture.
Activation and tuning of ASR rules to prevent LOLBins techniques, deployment of enhanced tamper protection against malicious manipulations, integration with Defender for Cloud Apps for zero-trust protection, practical exercises on blocking unsigned executables and abusive PowerShell scripts, real-time log analysis to refine business exclusions, ransomware attack simulations and development of enterprise-adapted prevention baselines, generation of custom dashboards for proactive monitoring.
In-depth exploration of EDR signals via KQL in Advanced Hunting, decoding of telemetry events to identify zero-day IOCs, use of Machine Learning to score behavioral anomalies, practical cases of investigation on simulated APT attacks, construction of custom queries for recurrent pro-hunting, correlation of multi-endpoint alerts into unified incidents, production of forensic timelines and export to SIEM tools like Splunk, optimization of false positives for maximum SOC efficiency.
Execution of Live Response sessions for immediate containment on compromised endpoints, advanced scripting for artifact collection and remediation execution, configuration of automation rules for SOAR-like responses, one-click network and USB isolation during live incidents, exercises on rollback of malicious processes and persistence purge, integration with Microsoft Sentinel for extended playbooks, simulation of a major incident with chain of command, drafting of certifying IR procedures for the security team.
Deployment of Threat Analytics and Attack Simulations to validate MITRE ATT&CK maturity, tuning of API connectors to third-party SIEM and Microsoft Purview, performance optimization for 10k+ endpoints, generation of GDPR/NIST compliance reports via Vulnerability Management, workshops on custom analytics rules for sector-specific threats, review of the ongoing project with global audit, post-training action plan for continuous resilience, delivery of ready-to-use templates and playbooks.
Target audience
CISOs, SOC analysts, IT security administrators, and DevSecOps engineers seeking expert skill development
Prerequisites
Advanced experience in EDR/XDR, mastery of Microsoft 365 Defender, and PowerShell scripting
Loading...
Please wait a moment





























