Skip to content

Lab 02 — Endpoint Security

Endpoints are where users interact with:

Email
Applications
Corporate Data
Cloud Services
Credentials
Business Systems

That makes endpoints one of the most important security layers in an enterprise.

In the previous lab, you worked with:

Active Directory
Users
Groups
Authentication
Privilege

Now you will move to the device itself.

Your security question becomes:

Is This Endpoint
Secure Enough
to Access Corporate Resources?

Lab: Endpoint Security
Level: Beginner → Intermediate
Estimated Time: 150–210 minutes
Environment: Authorized Windows 10/11 or Windows Server lab system
Primary Role: Endpoint Security Engineer
Supporting Roles: Windows Administrator, SOC Analyst, Microsoft Security Engineer, Incident Responder, IAM Engineer

Your organization has deployed a Windows workstation for an employee.

Before allowing the device to access sensitive corporate applications, the security team wants it reviewed.

You have been asked to assess:

Device Identity
Operating System
Users
Local Administrators
Security Updates
Microsoft Defender
Windows Firewall
Disk Encryption
Applications
Services
Network Exposure
Security Logs
Device Compliance

Your goal is to determine:

What Is Secure?
What Is Misconfigured?
What Is Missing?
What Is Over-Privileged?
What Should Be Fixed First?

By completing this lab, you should be able to:

  • Identify Windows endpoint information
  • Review device identity
  • Review local users
  • Review local administrators
  • Understand least privilege
  • Review Microsoft Defender Antivirus
  • Review Windows Firewall
  • Review BitLocker status
  • Review operating-system updates
  • Review installed applications
  • Review running services
  • Review listening network ports
  • Review security-related Windows events
  • Understand endpoint compliance
  • Understand device-management relationships
  • Identify common endpoint-security gaps
  • Create remediation recommendations
  • Produce a professional endpoint-security report

Think:

IDENTITY
DEVICE
CONFIGURATION
PRIVILEGE
APPLICATIONS
NETWORK
SECURITY CONTROLS
LOGGING
MONITORING
USER
|
v
+----------------+
| Windows Device |
+--------+-------+
|
+-------------+-------------+
| | |
v v v
Identity Security Applications
| Controls |
| | |
+-------------+--------------+
|
v
Corporate Data
|
v
Cloud / Enterprise
Resources

Create a workspace in PowerShell:

Terminal window
New-Item -ItemType Directory -Path C:\EndpointSecurityLab -Force

Create subdirectories:

Terminal window
New-Item -ItemType Directory -Path C:\EndpointSecurityLab\Baseline -Force
New-Item -ItemType Directory -Path C:\EndpointSecurityLab\Evidence -Force
New-Item -ItemType Directory -Path C:\EndpointSecurityLab\Findings -Force
New-Item -ItemType Directory -Path C:\EndpointSecurityLab\Reports -Force

Your structure becomes:

C:\EndpointSecurityLab
├── Baseline
├── Evidence
├── Findings
└── Reports

Start with:

Terminal window
hostname

Then:

Terminal window
Get-ComputerInfo

For a focused view:

Terminal window
Get-ComputerInfo |
Select-Object CsName,WindowsProductName,WindowsVersion,OsBuildNumber,OsArchitecture

Record:

Hostname
Operating System
Version
Build
Architecture

You cannot secure an endpoint properly without knowing:

What Device Is This?
Which OS?
Which Version?
Who Owns It?
What Is Its Business Role?

Save device information:

Terminal window
Get-ComputerInfo |
Out-File C:\EndpointSecurityLab\Baseline\ComputerInfo.txt

Capture time:

Terminal window
Get-Date |
Out-File C:\EndpointSecurityLab\Baseline\AssessmentTime.txt

You need:

BEFORE

to compare with:

AFTER

if remediation is later performed.

Part 04 — Determine Device Ownership and Purpose

Section titled “Part 04 — Determine Device Ownership and Purpose”

Document:

Device Owner:
Department:
Business Function:
Corporate / Personal:
Managed / Unmanaged:
Production / Lab:
Data Sensitivity:

A finance laptop and a public kiosk should not automatically receive identical security requirements.

Use:

ASSET ROLE
+
DATA SENSITIVITY
+
THREAT MODEL

Run:

Terminal window
whoami

Then:

Terminal window
whoami /groups

This helps identify:

Current User
Group Membership
Security Context

Run:

Terminal window
Get-LocalUser

Review:

Name
Enabled
Description
Last Logon

where available.

For each account ask:

Who Owns It?
Why Does It Exist?
Is It Enabled?
Does It Need Interactive Login?
Does It Have Administrative Access?

Part 07 — Identify Disabled and Unused Accounts

Section titled “Part 07 — Identify Disabled and Unused Accounts”

Run:

Terminal window
Get-LocalUser |
Select-Object Name,Enabled,LastLogon

Potential issues include:

Unused Enabled Accounts
Old Support Accounts
Shared Accounts
Default Accounts Improperly Used
Finding:
Unused Local Account Remains Enabled
Observation:
A local account remains enabled despite
having no current documented business use.
Risk:
Unused identities increase the number of
credentials that may be abused.
Recommendation:
Validate account ownership and disable or
remove unused access through the approved
endpoint lifecycle process.

Run:

Terminal window
Get-LocalGroupMember -Group "Administrators"

Document:

Member
Source
Account Type
Business Requirement

A local administrator may be able to:

Install Software
Create Accounts
Change Security Settings
Disable Controls
Access Sensitive Data

Prefer:

Standard User
Approved Elevation
Required Administrative Task

instead of:

Every User
Permanent Local Administrator

For each administrator ask:

Does This Identity Need Local Admin?
Is It Permanent?
Can Elevation Be Temporary?
Is Administrative Activity Logged?
Is Access Reviewed?
Finding:
Excessive Local Administrator Membership
Observation:
A standard business user has permanent
membership in the local Administrators
group without a documented requirement.
Risk:
Malware, credential compromise, or user
error may gain elevated control of the
endpoint.
Recommendation:
Remove unnecessary permanent local
administrator rights and use controlled
elevation for approved administrative
tasks.

Run:

Terminal window
dsregcmd /status

Review relevant areas such as:

Domain Join
Microsoft Entra Join
Device Identity
Tenant Information

A device may be:

Workgroup
Active Directory Domain Joined
Microsoft Entra Joined
Hybrid Joined

Device identity can influence:

Management
Authentication
Compliance
Conditional Access
Policy

Run:

Terminal window
Get-CimInstance Win32_ComputerSystem |
Select-Object Name,Domain,PartOfDomain

Record:

Domain:
Domain Joined:
Workgroup:

Part 12 — Review Operating-System Support

Section titled “Part 12 — Review Operating-System Support”

Confirm the system is running:

Supported Windows Version
Supported Build
Approved Enterprise Edition

Unsupported systems may lack:

Security Updates
Vendor Support
Modern Security Features

Inspect update history using the approved Windows Update interface or management platform.

PowerShell environments may also expose relevant update information.

A simple installed-hotfix review can begin with:

Terminal window
Get-HotFix |
Sort-Object InstalledOn -Descending

Get-HotFix is not a complete vulnerability-assessment tool.

It provides one piece of evidence.

Ask:

When Was the Device Last Updated?
Are Updates Centrally Managed?
Are Security Updates Delayed?
Did Any Update Fail?
Is a Reboot Pending?
UPDATE RELEASED
TEST
PILOT
DEPLOY
MONITOR
VALIDATE
Finding:
Endpoint Security Updates Delayed
Observation:
The endpoint remains behind the approved
security-update baseline.
Risk:
Known vulnerabilities may remain exposed
beyond the organization's remediation
window.
Recommendation:
Apply applicable security updates through
the approved update-management process and
validate device health after deployment.

Microsoft Defender Antivirus provides endpoint malware protection capabilities on supported Windows systems.

Review:

Terminal window
Get-MpComputerStatus

Focus on relevant fields such as:

AntivirusEnabled
RealTimeProtectionEnabled
AntispywareEnabled
BehaviorMonitorEnabled
AntivirusSignatureLastUpdated
Terminal window
Get-MpComputerStatus |
Out-File C:\EndpointSecurityLab\Evidence\DefenderStatus.txt
Is Antivirus Enabled?
Is Real-Time Protection Enabled?
Are Security Intelligence Updates Current?
Is Behavior Monitoring Enabled?
Is the Device Reporting Healthy?

Part 15 — Understand Antivirus Limitations

Section titled “Part 15 — Understand Antivirus Limitations”

Do not think:

Antivirus Enabled
=
Endpoint Secure

Endpoint security also requires:

Patching
Least Privilege
Firewall
Encryption
Application Security
EDR
Monitoring
USER SECURITY
+
IDENTITY SECURITY
+
PATCHING
+
ANTIVIRUS
+
FIREWALL
+
EDR
+
MONITORING

In an authorized lab:

Terminal window
Get-MpPreference

This can expose a large configuration set.

Focus on relevant security settings rather than copying the entire output blindly.

Do not modify Defender exclusions without understanding their purpose.

Review approved exclusions where required.

Broad exclusions can weaken endpoint protection.

Examples requiring scrutiny include exclusions covering:

Entire Drives
User Profile Trees
Temporary Directories
Broad Application Paths
Finding:
Overly Broad Endpoint Protection Exclusion
Observation:
Endpoint protection excludes a location
broader than required by the documented
application requirement.
Risk:
Malicious content within the excluded
location may receive reduced inspection.
Recommendation:
Reduce exclusions to the minimum supported
scope and periodically review their
business requirement.

Part 18 — Endpoint Detection and Response

Section titled “Part 18 — Endpoint Detection and Response”

Antivirus primarily focuses on prevention and detection.

EDR expands visibility into behaviors such as:

Processes
Files
Network Connections
Identity Activity
Persistence
Security Alerts
ALERT
DEVICE
USER
PROCESS
PARENT
FILE
NETWORK
TIMELINE

Check firewall profile status:

Terminal window
Get-NetFirewallProfile

Focus on:

Domain
Private
Public

Record whether each profile is:

Enabled
Disabled
Terminal window
Get-NetFirewallProfile |
Out-File C:\EndpointSecurityLab\Evidence\FirewallProfiles.txt
NETWORK
WINDOWS FIREWALL
APPLICATION / SERVICE

Windows commonly uses:

Domain Profile
Private Profile
Public Profile

The applicable profile depends on the network context.

Ask:

Is the Firewall Enabled
for Every Required Profile?
Finding:
Windows Firewall Disabled
Observation:
One or more required Windows Firewall
profiles are disabled.
Risk:
The endpoint may accept network traffic
without the host-level filtering required
by the security baseline.
Recommendation:
Enable the approved firewall profiles,
validate necessary application rules, and
centrally manage exceptions where possible.

List enabled inbound rules:

Terminal window
Get-NetFirewallRule |
Where-Object {$_.Enabled -eq "True" -and $_.Direction -eq "Inbound"} |
Select-Object DisplayName,Action,Profile
Why Does This Rule Exist?
Which Application Needs It?
Which Profile?
Allow or Block?
Is Its Scope Too Broad?

Run:

Terminal window
Get-NetTCPConnection -State Listen

Review:

Local Address
Local Port
Owning Process

Example:

Terminal window
Get-NetTCPConnection -State Listen |
Select-Object LocalAddress,LocalPort,OwningProcess

Then for a PID:

Terminal window
Get-Process -Id <PID>
PORT
PID
PROCESS
SERVICE
BUSINESS REQUIREMENT

A listening port is not automatically externally reachable.

Reachability also depends on:

Firewall
Network Path
Application Binding
Cloud / Network Controls

Run:

Terminal window
Get-NetTCPConnection |
Where-Object {$_.State -eq "Established"}

Look for:

Unexpected Destinations
Unexpected Processes
Long-Lived Connections
Unknown Applications

Do not classify an unfamiliar connection as malicious solely because you do not recognize the IP address.

Correlate:

Process
Application
Destination
Business Requirement
Security Telemetry

BitLocker helps protect data at rest.

Review:

Terminal window
Get-BitLockerVolume

Focus on:

MountPoint
VolumeStatus
ProtectionStatus
EncryptionPercentage

A lost or stolen device should not automatically expose corporate data.

DEVICE LOST
DISK ENCRYPTED
DATA REMAINS PROTECTED

Encryption requires recoverability.

Organizations should manage:

Recovery Keys
Authorized Recovery
Key Escrow
Access Controls
Audit
Finding:
Endpoint Disk Encryption Not Enabled
Observation:
The system volume containing corporate
data is not protected by the organization's
required full-disk encryption control.
Risk:
Physical loss or theft of the device may
expose locally stored information.
Recommendation:
Enable approved disk encryption and ensure
recovery information is securely managed
through the organization's endpoint
management process.

Where relevant:

Terminal window
Get-Tpm

Review:

TpmPresent
TpmReady
TpmEnabled

TPM technology can support security capabilities such as:

BitLocker
Windows Hello
Device Trust
Key Protection

Part 27 — Review Windows Security Services

Section titled “Part 27 — Review Windows Security Services”

Inspect relevant services:

Terminal window
Get-Service |
Where-Object {$_.Status -eq "Running"}

Do not assume every running service is required.

What Is the Service?
Who Installed It?
Does the Device Need It?
Does It Listen on the Network?
Does It Run with High Privilege?

List installed applications using approved inventory sources.

Use:

Enterprise Inventory
Intune
Software Management
Windows Settings
Approved PowerShell Queries

Avoid relying on only one registry location as a complete inventory.

Is the Application Approved?
Is It Required?
Is It Current?
Who Installed It?
Does It Introduce Network Exposure?
Does It Require Administrative Rights?

Every unnecessary application adds:

Code
Dependencies
Attack Surface
Maintenance
Potential Vulnerabilities
Finding:
Unnecessary Endpoint Software
Observation:
Software not required for the endpoint's
documented business role remains installed.
Risk:
Unnecessary software increases endpoint
attack surface and maintenance burden.
Recommendation:
Validate application ownership and remove
unused software through the approved
software-management process.

Review approved startup mechanisms.

One simple view is:

Terminal window
Get-CimInstance Win32_StartupCommand

Assess:

Application
Location
User
Business Purpose

Unexpected startup execution may represent:

Legitimate Software
Management Agent
User Utility
Misconfiguration
Potential Persistence

Context matters.

List tasks:

Terminal window
Get-ScheduledTask

For security review, focus on:

Unknown Tasks
High-Privilege Tasks
Custom Scripts
Unexpected Executables
Who Created It?
Which Account Runs It?
What Does It Execute?
When?
Is the Target Script Protected?

Run:

Terminal window
Get-Process

Sort by CPU:

Terminal window
Get-Process |
Sort-Object CPU -Descending |
Select-Object -First 20
What Is the Process?
Who Owns It?
Where Is the Executable?
What Started It?
Does It Use the Network?
Is It Expected?

Part 33 — Review Windows Defender Firewall and Services Together

Section titled “Part 33 — Review Windows Defender Firewall and Services Together”

A good endpoint assessment correlates:

RUNNING SERVICE
+
LISTENING PORT
+
FIREWALL RULE
=
NETWORK EXPOSURE

Windows Event Viewer contains important security evidence.

Useful log categories include:

Security
System
Application
Microsoft Defender
PowerShell
EVENT
TIME
USER
PROCESS
DEVICE
ACTION

An authorized PowerShell example:

Terminal window
Get-WinEvent -LogName Security -MaxEvents 50

Do not dump excessive event logs into a report.

Focus on events relevant to the assessment.

Security teams often care about categories such as:

Successful Logons
Failed Logons
Account Changes
Privilege Use
Process Creation
Policy Changes

Learn:

What Happened

before memorizing:

Event ID

Event IDs are useful, but context matters more.

Part 37 — Review PowerShell Logging Concept

Section titled “Part 37 — Review PowerShell Logging Concept”

PowerShell is a powerful administrative platform.

Security teams may use PowerShell logging to support:

Administrative Monitoring
Threat Detection
Incident Investigation

Ask:

Can We Determine
What Administrative Scripts
Were Executed?

according to your organization’s logging standard.

Run:

Terminal window
auditpol /get /category:*

This shows audit-policy configuration.

Review whether the environment captures required events.

Potential categories include:

Account Logon
Account Management
Logon/Logoff
Privilege Use
Policy Change
Process Tracking
System Events

Understand:

Logging
=
Events Are Recorded

while:

Monitoring
=
Events Are Reviewed
and Used for Detection

A device can generate excellent logs that nobody ever looks at.

Part 40 — Centralized Security Monitoring

Section titled “Part 40 — Centralized Security Monitoring”

A mature endpoint design may follow:

WINDOWS ENDPOINT
SECURITY TELEMETRY
CENTRAL PLATFORM
SIEM / XDR
ALERT
SOC

Managed endpoints may be evaluated against a compliance policy.

Possible requirements include:

Supported OS
Encryption
Security Controls
Password Requirements
Threat State
DEVICE STATE
COMPLIANCE POLICY
COMPLIANT
or
NONCOMPLIANT

Part 42 — Compliance and Conditional Access

Section titled “Part 42 — Compliance and Conditional Access”

Combine:

USER IDENTITY
+
DEVICE COMPLIANCE
+
APPLICATION
+
RISK
ACCESS DECISION
User Password Correct
MFA Successful
Device Noncompliant
Sensitive App Access Restricted

This is a Zero Trust-style security model.

Create an approved baseline covering:

OS Version
Patching
Local Administrators
Antivirus
Firewall
Encryption
Applications
Audit Policy
Logging
Device Compliance
Control Expected State
Supported OS Yes
Updates Current
Standard user No permanent admin
Defender Enabled
Firewall Enabled
BitLocker Protected
Logging Enabled
Compliance Compliant

Part 44 — Compare Baseline to Actual State

Section titled “Part 44 — Compare Baseline to Actual State”

Create:

Control Expected Actual Result
Defender Enabled Enabled Pass
Firewall Enabled Disabled Fail
BitLocker Enabled Disabled Fail
Local Admin Restricted Broad Fail
Updates Current Current Pass

Do not treat every gap equally.

Consider:

Exposure
Privilege
Data Sensitivity
Likelihood
Business Impact
Compensating Controls
User Has Local Admin
+
Device Handles Sensitive Data
+
No EDR
Higher Risk

Scenario:

Corporate Laptop Is Lost

Investigate:

Device Ownership
Encryption
User
Last Check-In
Recent Sign-In Activity
Corporate Data
Device Management State

Then follow approved procedures for:

Access Restriction
Remote Actions
Credential Response
Incident Documentation

Scenario:

Endpoint Security Generates
Malware Alert

Use:

ALERT
DEVICE
USER
FILE
PROCESS
PARENT
NETWORK
TIMELINE

Do not immediately assume every antivirus detection means a complete system compromise.

Scenario:

Firewall Disabled

Ask:

Who Disabled It?
When?
Why?
Was It Central Policy?
Was It Troubleshooting?
Did Exposure Increase?

Scenario:

Employee Requests
Permanent Administrator Rights
for One Application

Instead of immediately granting it, ask:

Which Application?
Which Function Requires Elevation?
Can the Application Be Reconfigured?
Can Temporary Elevation Be Used?
Can a Smaller Permission Be Granted?

Scenario:

Device Is Noncompliant
because Encryption Is Disabled

Workflow:

IDENTIFY CONTROL
VALIDATE STATE
REMEDIATE
SYNC DEVICE
RECHECK COMPLIANCE
VALIDATE ACCESS

Do not stop at:

Configured

Validate:

Effective

Example:

Firewall Enabled

is good.

But also ask:

Are the Rules Appropriate?

In an authorized disposable lab, validate that prohibited behavior is actually blocked.

Examples:

Standard User
Cannot Perform Admin Task
Unapproved Inbound Access
Is Blocked
Noncompliant Device
Is Restricted Where Policy Requires

Document:

Hostname
Owner
Operating System
Build
Join State
Management State
Compliance
Security Status
Item Value
Hostname
Owner
OS
Build
Domain/Entra State
Managed
Compliant
Last Reviewed
Identity Type Local Admin Required Action
User-A Employee No No None
Admin-A Admin Yes Yes Review
OldSupport Local Yes No Disable/Review

Part 55 — Create a Security Control Matrix

Section titled “Part 55 — Create a Security Control Matrix”
Control State Expected Finding
Defender Enabled Enabled None
Firewall Enabled Enabled None
Encryption Disabled Enabled Yes
Updates Current Current None
Logging Review Enabled Review
Application Required Approved Current Owner
Browser Yes Yes Yes IT
Office Yes Yes Yes IT
Unknown App Review Review Review Unknown

Part 57 — Create Network Exposure Matrix

Section titled “Part 57 — Create Network Exposure Matrix”
Port Process Required Firewall Action
Review Process Yes/No Allowed/Blocked Review

Part 58 — Finding: Excessive Local Admin

Section titled “Part 58 — Finding: Excessive Local Admin”
Finding:
Permanent Local Administrative Privilege
Observation:
A standard business user possesses
permanent local administrator access.
Risk:
Compromise of the user context may provide
elevated control of the endpoint and its
security configuration.
Recommendation:
Remove unnecessary permanent privilege and
provide controlled elevation for approved
administrative tasks.
Finding:
Host Firewall Protection Disabled
Observation:
A required Windows Firewall profile is not
enabled.
Risk:
The endpoint may accept unnecessary network
traffic and rely entirely on upstream
network controls.
Recommendation:
Restore the approved firewall profile and
validate required application exceptions.
Finding:
Full-Disk Encryption Not Enforced
Observation:
The system volume is not protected using
the organization's required disk-encryption
control.
Risk:
Loss or theft of the device may expose
locally stored corporate information.
Recommendation:
Enable approved full-disk encryption and
securely manage recovery information.

Part 61 — Finding: Security Telemetry Gap

Section titled “Part 61 — Finding: Security Telemetry Gap”
Finding:
Insufficient Endpoint Security Visibility
Observation:
The endpoint does not provide the security
telemetry required by the organization's
monitoring standard.
Risk:
Suspicious endpoint activity may be
difficult to detect, investigate, or
correlate with broader incidents.
Recommendation:
Enable approved endpoint telemetry and
forward required security events to the
central monitoring platform.
Finding:
Unsupported Operating System
Observation:
The endpoint runs an operating-system
version outside the organization's
supported security lifecycle.
Risk:
The device may not reliably receive
required security updates or modern
security capabilities.
Recommendation:
Upgrade or replace the device with a
supported operating-system release.

Your report should contain:

Document:

Endpoint Assessed
Business Role
Overall Security Posture
Highest-Risk Findings
Priority Recommendations

Include:

Hostname
Operating System
Build
Owner
Device Role
Join State

Document:

Local Users
Local Administrators
Unused Accounts
Privileged Access

Document:

OS Update State
Recent Security Updates
Observed Gaps

Document:

Antivirus
Real-Time Protection
Security Intelligence
EDR / Security Telemetry

Document:

Profile Status
Relevant Rules
Observed Exposure

Document:

BitLocker State
Protection Status
Recovery Process

Document:

Approved Applications
Unknown Applications
Unsupported Applications
Business Owners

Document:

Running Services
Listening Ports
Relevant Processes
Unexpected Connections

Document:

Security Events
Audit Policy
Centralized Monitoring
Visibility Gaps

Document:

Compliance State
Failed Controls
Remediation Requirements

For each:

ID
Title
Severity
Observation
Evidence
Risk
Recommendation
Owner
  • Identified hostname
  • Identified OS
  • Identified build
  • Identified owner
  • Identified business role
  • Reviewed device join state
  • Reviewed current user
  • Reviewed local accounts
  • Reviewed disabled accounts
  • Reviewed local administrators
  • Reviewed least privilege
  • Reviewed update status
  • Reviewed installed hotfix evidence
  • Reviewed update-management approach
  • Checked for outdated OS
  • Reviewed antivirus state
  • Reviewed real-time protection
  • Reviewed security intelligence
  • Reviewed relevant exclusions
  • Understood EDR role
  • Reviewed firewall profiles
  • Reviewed enabled inbound rules
  • Reviewed listening ports
  • Mapped ports to processes
  • Reviewed required exposure
  • Reviewed BitLocker
  • Reviewed protection status
  • Reviewed recovery process
  • Reviewed TPM where appropriate
  • Reviewed installed applications
  • Reviewed application ownership
  • Identified unnecessary software
  • Reviewed unsupported software
  • Reviewed startup applications
  • Reviewed running services
  • Identified high-privilege services
  • Correlated services with listeners
  • Reviewed scheduled tasks
  • Reviewed process inventory
  • Investigated unusual processes
  • Correlated processes with connections
  • Distinguished unknown from malicious
  • Reviewed Security log
  • Reviewed audit policy
  • Understood PowerShell logging
  • Reviewed centralized monitoring
  • Identified visibility gaps
  • Understood compliance state
  • Compared device to baseline
  • Identified failed controls
  • Created remediation recommendations
  • Created endpoint inventory
  • Created local access matrix
  • Created security control matrix
  • Created application inventory
  • Created exposure matrix
  • Documented findings
  • Produced final report

Avoid:

Giving Every User Local Admin
Disabling Firewall for Troubleshooting
Ignoring Disk Encryption
Ignoring Update Failures
Assuming Antivirus Is Enough
Creating Broad Defender Exclusions
Ignoring Unknown Applications
Ignoring Stale Accounts
Ignoring Startup Tasks
Ignoring Outbound Connections
Ignoring Security Logs
Assuming Enrolled Means Secure
Assuming Compliant Means Impossible to Compromise
Antivirus
Firewall
Patching
Central Device Management
Encryption
Compliance
Application Management
Least Privilege
EDR
Conditional Access
Central Logging
Automated Remediation
Security Baseline
Identity + Device + Risk
Continuous Evaluation
Controlled Privilege
Automated Compliance
Advanced Detection

This lab directly supports:

Endpoint Administrator
Endpoint Security Engineer
Windows Administrator
SOC Analyst
Microsoft Security Engineer
Incident Responder
Cloud Security Engineer
Security Consultant

Why are local administrator rights risky?

Because administrator-level compromise may allow:

Security Control Changes
Software Installation
Credential Access
Persistence
Data Access

Is Microsoft Defender Antivirus enough to secure a Windows endpoint?

No.

A strong endpoint requires multiple controls:

Patching
Least Privilege
Firewall
Encryption
EDR
Logging
Monitoring

Why is BitLocker important?

It helps protect data at rest when a device or drive is lost or stolen.

How would you investigate an unknown listening port?

Use:

PORT
PID
PROCESS
SERVICE
BUSINESS REQUIREMENT
FIREWALL EXPOSURE

What is the difference between endpoint management and endpoint security?

Endpoint management focuses on:

Lifecycle
Configuration
Applications
Updates
Compliance

Endpoint security focuses more specifically on:

Protection
Detection
Privilege
Exposure
Response

They strongly overlap.

  1. What is endpoint security?
  2. Why are endpoints important attack surfaces?
  3. What is endpoint management?
  4. What is a managed endpoint?
  5. What is device identity?
  6. How do you identify local users?
  7. Why are stale local accounts risky?
  8. How do you review local administrators?
  9. What is least privilege?
  10. Why should users normally avoid permanent local admin?
  11. What is Microsoft Defender Antivirus?
  12. What is real-time protection?
  13. Why must malware intelligence remain updated?
  14. What is EDR?
  15. How does EDR differ from antivirus?
  16. What is Windows Firewall?
  17. What are firewall profiles?
  18. Why should host firewalls remain enabled?
  19. How do you identify listening ports?
  20. How do you map a port to a process?
  21. What is BitLocker?
  22. Why is recovery-key management important?
  23. What is TPM?
  24. Why are security updates important?
  25. What is patch management?
  26. Why use phased update deployment?
  27. Why should installed software be inventoried?
  28. Why are unnecessary applications risky?
  29. Why should scheduled tasks be reviewed?
  30. What is configuration drift?
  31. What is an endpoint security baseline?
  32. What is device compliance?
  33. How does compliance relate to Conditional Access?
  34. What is Windows audit policy?
  35. Why is centralized logging important?
  36. How would you handle a lost laptop?
  37. How would you investigate a malware alert?
  38. How would you assess an endpoint with its firewall disabled?
  39. What controls would you prioritize on a corporate endpoint?
  40. How would you perform an endpoint-security assessment?

When assessing a Windows endpoint, ask:

WHAT DEVICE IS THIS?
WHO USES IT?
WHO IS ADMIN?
IS IT PATCHED?
IS ANTIVIRUS ACTIVE?
IS EDR AVAILABLE?
IS FIREWALL ENABLED?
IS DATA ENCRYPTED?
WHAT SOFTWARE EXISTS?
WHAT SERVICES RUN?
WHAT PORTS ARE OPEN?
WHAT IS BEING LOGGED?
IS IT COMPLIANT?

You have now assessed endpoint security across:

Device Identity
Users
Local Administrators
Patching
Microsoft Defender
Firewall
BitLocker
Applications
Processes
Services
Networking
Logging
Compliance

The most important lesson is:

Endpoint Security
Is Not One Product

It is the combination of:

IDENTITY
+
CONFIGURATION
+
LEAST PRIVILEGE
+
PATCHING
+
PROTECTION
+
NETWORK SECURITY
+
ENCRYPTION
+
MONITORING

➡️ Lab 03 — Identity Security

In the next lab, you will move from securing the device to securing cloud identity.

You will work through:

Microsoft Entra ID
User Inventory
Groups
Authentication Methods
MFA
Conditional Access
Administrative Roles
Privileged Identity
Guest Access
Enterprise Applications
Sign-In Logs
Identity Risk
Security Findings

Your Microsoft lab sequence continues:

Lab 01 — Active Directory
Lab 02 — Endpoint Security
Lab 03 — Identity Security
Lab 04 — Microsoft 365 Security
Lab 05 — Windows Security
Runbook 01 — Active Directory Assessment
Runbook 02 — Microsoft 365 Security Review
Runbook 03 — Windows Security Assessment