Defender for M365 (E5)
Defender for Endpoint (E5)
Secure Score
DLP policies
Sensitivity labels
Day 1
Defender for M365
Day 2
Defender for Endpoint
Day 3
Secure Score + Attack simulation
Day 4
DLP policies
Day 5
Sensitivity labels + Assessment
Week 7 shifts from infrastructure to active threat defence. The devices managed in Week 6 become Defender for Endpoint targets. The emails and files governed in Weeks 3–4 become DLP-protected content. The identity stack from Weeks 1–2 gains a Secure Score and an attack simulation. Everything connects — this is the week where students see the M365 security stack as a unified system rather than isolated features.
The Microsoft Defender product family — what's in E5
Defender for M365
Plan 1 + Plan 2
Email, Teams, SharePoint, OneDrive threat scanning. Anti-phishing, Safe Links, Safe Attachments. Threat Explorer. AIR (auto investigation).
Defender for Endpoint
Plan 2 (E5)
Device-level EDR — threat detection, behavioural monitoring, vulnerability assessment, device isolation. Integrates with Intune compliance.
Defender for Identity
Monitors on-prem AD for identity attacks — pass-the-hash, lateral movement, golden ticket. Connects to on-prem DC via sensor.
Defender for Cloud Apps
Cloud Access Security Broker (CASB). Shadow IT discovery, app governance, session control for cloud apps.
Microsoft Sentinel
Cloud-native SIEM/SOAR. Aggregates signals across all Defender products. Week 8 preview — not covered in depth this week.
Daily breakdown
Day 1
Lecture: Defender for M365 architecture, Safe Links, Safe Attachments, anti-phishing
Lab 7-A: Enable Defender for M365 → configure Safe Links + Safe Attachments policies → configure anti-phishing → review Threat Explorer → send a test phishing simulation
Day 2
Lecture: Defender for Endpoint architecture, onboarding methods, EDR vs AV
Lab 7-B: Onboard WIN-CLIENT-01 to Defender for Endpoint → configure device group → review device inventory → run a detection test → wire Defender risk level to Intune compliance
Day 3
Lecture: Secure Score model, Attack simulation training concept
Lab 7-C: Review and improve Secure Score → implement 3 recommended actions → run an Attack Simulation Training campaign (credential harvest template) → review simulation results
Day 4
Lecture: DLP architecture, conditions, actions, policy tips, endpoint DLP
Lab 7-D: Create DLP policy for financial data (credit card + NZ bank account numbers) → test with a synthetic document → create endpoint DLP policy for USB block → review DLP alerts
Day 5
Lecture: Sensitivity label architecture, auto-labelling, label inheritance
Lab 7-E (condensed) + Week 7 Assessment: create sensitivity labels → apply to Finance content → assessment scenario: a phishing email bypassed Safe Attachments, a file was exfiltrated — investigate, contain, harden
Key design decisions for Week 7
Defender for Endpoint onboarding uses the Intune integration. WIN-CLIENT-01 is already Intune-managed from Week 6. Onboarding to Defender for Endpoint is done via an Intune configuration profile — a single step that deploys the Defender for Endpoint onboarding package to enrolled devices. This is the Week 6 payoff: the Intune infrastructure built last week is the delivery mechanism for Defender this week.
DLP on Day 4 connects directly to Week 3 (Exchange) and Week 4 (SharePoint/OneDrive). DLP policies in the Purview portal apply across Exchange Online, SharePoint, OneDrive, and Teams simultaneously. Students who configured Exchange transport rules in Week 3 and SharePoint sharing policies in Week 4 will see how DLP supersedes and extends both.
Sensitivity labels on Day 5 are condensed. A full sensitivity label deployment — with auto-labelling, Office app integration, SharePoint library defaults, and label inheritance — is a multi-day topic. Day 5 covers the core: creating labels, applying them manually, and understanding how they interact with DLP. Week 8's Purview module goes deeper into label-based retention and eDiscovery.
Attack Simulation Training on Day 3 sends real emails to real tenant accounts. The simulation uses real M365 mail flow to deliver a credential-harvest simulation to Lakeview Logistics users. Students must understand this is a controlled simulation — no real credentials are captured. The simulation landing page is a Microsoft-hosted training page. Configure the simulation to target only internal test accounts before running.
Week 7 connections to earlier work
| Week 7 topic | Connects to | The payoff |
| Defender for Endpoint onboarding | Week 6 — Intune device management | WIN-CLIENT-01 is onboarded via an Intune config profile — the same mechanism used for KFM and Update rings. The device's Defender risk level then feeds back into Intune compliance. |
| Defender risk → Intune compliance | Week 6 — compliance policies + CA | A device with active malware in Defender for Endpoint is automatically marked non-compliant in Intune → blocked from M365 by CA001. The Week 6 CA chain now has a threat-intelligence input. |
| Safe Links / Safe Attachments | Week 3 — Exchange Online, mail flow | Safe Links and Safe Attachments sit in front of the Exchange Online mailboxes configured in Week 3. Every email to a Lakeview Logistics user now passes through Defender scanning before delivery. |
| DLP policies | Week 3 (Exchange) + Week 4 (SharePoint/OneDrive) | A single DLP policy covers all three workloads simultaneously. Students who configured Exchange transport rules and SharePoint sharing policies separately now see unified cross-workload governance. |
| Sensitivity labels | Week 4 — SharePoint permissions and document libraries | Labels applied to Finance documents in SharePoint restrict who can view or share them — extending the SharePoint permission model with content-level protection that travels with the file. |
| Secure Score recommendations | Weeks 1–6 — all prior configuration | Secure Score evaluates the entire tenant configuration. Students will see their Week 2 MFA, Week 6 device compliance, and other configurations reflected as positive score contributions — and see what gaps remain. |
Week 7 portals
| Portal | URL | Used for |
| Microsoft Defender portal | security.microsoft.com | Defender for M365 (Safe Links, Safe Attachments, anti-phishing, Threat Explorer), Defender for Endpoint (device inventory, alerts, incidents), Attack simulation, Secure Score |
| Microsoft Purview portal | purview.microsoft.com | DLP policies, sensitivity labels, data classification, information protection — Weeks 7 and 8 |
| Intune portal | intune.microsoft.com | Defender for Endpoint onboarding profile, device compliance integration |
| Entra ID portal | entra.microsoft.com | CA policy updates (Defender risk level condition) |