Incident Response Using Microsoft Defender
Incident Response Using Microsoft Defender – Analyzing an Endpoint Incident in an Entra ID Environment
Instructor: Christian Eisenkopf
Duration: 1 Day – January 26, 2027
In this one-day workshop, participants will analyze an incident in a small company in a realistic Entra ID environment: the malware infection of an endpoint in the accounting department. The malware used is closely aligned with real, actually observed malware. Should such an incident occur in a company, acting swiftly and in a structured way is what determines how far an attacker can move and how quickly normal operation can be restored.
A particular feature of the workshop is the exercise environment itself: It is not a simulation with artificially installed sample data but a real environment that has been set up completely, allowing the incident to take place for real, with real traces, alerts and logs. This way, participants can work under the same conditions as during a real incident and in a familiar environment as well. We will provide the entire environment; you do not need to bring a laptop.
First, we will give a basic introduction to incident response and the required processes. This will be followed by a concise, practical introduction to the Microsoft Defender portal. In the main, practical section, participants then work through the incident in real time: from the first alarms to attack chain reconstruction and jointly developed initial response.
After this workshop, you will know how to:
- Identify and classify a security incident in the Microsoft Defender portal and in Microsoft Sentinel
- Use real telemetry and logs to reconstruct the attack chain of an endpoint incident
- Assess the consequences for the affected endpoint and the Entra ID tenant
- Carry out immediate actions like device isolation and identity-related measures in Entra ID
Requirements:
Basic knowledge of IT and Entra ID/Microsoft 365; experience with the Microsoft Defender portal or Microsoft Sentinel is an advantage but not required
Target group:
Everyone who wants to experience a realistic incident themselves: CISOs and IT security executives who want to form their own opinion, colleagues who do not yet have much experience with Microsoft portals and would like to gain practical experience, and those interested in IT security who want to experience how a real incident is analyzed in a realistic environment.
This traning will be held in German.
Price: € 1.100
Date
January 26, 2027
Location
Scandic Frankfurt Hafenpark
Eytelweinstraße 1
Frankfurt am Main
Tel.: +49 69 219 777 0