Defender for M365 (E5) Defender for Endpoint (E5) Secure Score DLP policies Sensitivity labels
Day 1
Defender for M365
Day 2
Defender for Endpoint
Day 3
Secure Score + Attack simulation
Day 4
DLP policies
Day 5
Sensitivity labels + Assessment

Week 7 shifts from infrastructure to active threat defence. The devices managed in Week 6 become Defender for Endpoint targets. The emails and files governed in Weeks 3–4 become DLP-protected content. The identity stack from Weeks 1–2 gains a Secure Score and an attack simulation. Everything connects — this is the week where students see the M365 security stack as a unified system rather than isolated features.

The Microsoft Defender product family — what's in E5
Defender for M365 Plan 1 + Plan 2
Email, Teams, SharePoint, OneDrive threat scanning. Anti-phishing, Safe Links, Safe Attachments. Threat Explorer. AIR (auto investigation).
Defender for Endpoint Plan 2 (E5)
Device-level EDR — threat detection, behavioural monitoring, vulnerability assessment, device isolation. Integrates with Intune compliance.
Defender for Identity Monitors on-prem AD for identity attacks — pass-the-hash, lateral movement, golden ticket. Connects to on-prem DC via sensor.
Defender for Cloud Apps Cloud Access Security Broker (CASB). Shadow IT discovery, app governance, session control for cloud apps.
Microsoft Sentinel Cloud-native SIEM/SOAR. Aggregates signals across all Defender products. Week 8 preview — not covered in depth this week.
Daily breakdown
Day 1
Lecture: Defender for M365 architecture, Safe Links, Safe Attachments, anti-phishing
Lab 7-A: Enable Defender for M365 → configure Safe Links + Safe Attachments policies → configure anti-phishing → review Threat Explorer → send a test phishing simulation
Day 2
Lecture: Defender for Endpoint architecture, onboarding methods, EDR vs AV
Lab 7-B: Onboard WIN-CLIENT-01 to Defender for Endpoint → configure device group → review device inventory → run a detection test → wire Defender risk level to Intune compliance
Day 3
Lecture: Secure Score model, Attack simulation training concept
Lab 7-C: Review and improve Secure Score → implement 3 recommended actions → run an Attack Simulation Training campaign (credential harvest template) → review simulation results
Day 4
Lecture: DLP architecture, conditions, actions, policy tips, endpoint DLP
Lab 7-D: Create DLP policy for financial data (credit card + NZ bank account numbers) → test with a synthetic document → create endpoint DLP policy for USB block → review DLP alerts
Day 5
Lecture: Sensitivity label architecture, auto-labelling, label inheritance
Lab 7-E (condensed) + Week 7 Assessment: create sensitivity labels → apply to Finance content → assessment scenario: a phishing email bypassed Safe Attachments, a file was exfiltrated — investigate, contain, harden
Key design decisions for Week 7
Defender for Endpoint onboarding uses the Intune integration. WIN-CLIENT-01 is already Intune-managed from Week 6. Onboarding to Defender for Endpoint is done via an Intune configuration profile — a single step that deploys the Defender for Endpoint onboarding package to enrolled devices. This is the Week 6 payoff: the Intune infrastructure built last week is the delivery mechanism for Defender this week.
DLP on Day 4 connects directly to Week 3 (Exchange) and Week 4 (SharePoint/OneDrive). DLP policies in the Purview portal apply across Exchange Online, SharePoint, OneDrive, and Teams simultaneously. Students who configured Exchange transport rules in Week 3 and SharePoint sharing policies in Week 4 will see how DLP supersedes and extends both.
Sensitivity labels on Day 5 are condensed. A full sensitivity label deployment — with auto-labelling, Office app integration, SharePoint library defaults, and label inheritance — is a multi-day topic. Day 5 covers the core: creating labels, applying them manually, and understanding how they interact with DLP. Week 8's Purview module goes deeper into label-based retention and eDiscovery.
Attack Simulation Training on Day 3 sends real emails to real tenant accounts. The simulation uses real M365 mail flow to deliver a credential-harvest simulation to Lakeview Logistics users. Students must understand this is a controlled simulation — no real credentials are captured. The simulation landing page is a Microsoft-hosted training page. Configure the simulation to target only internal test accounts before running.
Week 7 connections to earlier work
Week 7 topicConnects toThe payoff
Defender for Endpoint onboardingWeek 6 — Intune device managementWIN-CLIENT-01 is onboarded via an Intune config profile — the same mechanism used for KFM and Update rings. The device's Defender risk level then feeds back into Intune compliance.
Defender risk → Intune complianceWeek 6 — compliance policies + CAA device with active malware in Defender for Endpoint is automatically marked non-compliant in Intune → blocked from M365 by CA001. The Week 6 CA chain now has a threat-intelligence input.
Safe Links / Safe AttachmentsWeek 3 — Exchange Online, mail flowSafe Links and Safe Attachments sit in front of the Exchange Online mailboxes configured in Week 3. Every email to a Lakeview Logistics user now passes through Defender scanning before delivery.
DLP policiesWeek 3 (Exchange) + Week 4 (SharePoint/OneDrive)A single DLP policy covers all three workloads simultaneously. Students who configured Exchange transport rules and SharePoint sharing policies separately now see unified cross-workload governance.
Sensitivity labelsWeek 4 — SharePoint permissions and document librariesLabels applied to Finance documents in SharePoint restrict who can view or share them — extending the SharePoint permission model with content-level protection that travels with the file.
Secure Score recommendationsWeeks 1–6 — all prior configurationSecure Score evaluates the entire tenant configuration. Students will see their Week 2 MFA, Week 6 device compliance, and other configurations reflected as positive score contributions — and see what gaps remain.
Week 7 portals
PortalURLUsed for
Microsoft Defender portalsecurity.microsoft.comDefender for M365 (Safe Links, Safe Attachments, anti-phishing, Threat Explorer), Defender for Endpoint (device inventory, alerts, incidents), Attack simulation, Secure Score
Microsoft Purview portalpurview.microsoft.comDLP policies, sensitivity labels, data classification, information protection — Weeks 7 and 8
Intune portalintune.microsoft.comDefender for Endpoint onboarding profile, device compliance integration
Entra ID portalentra.microsoft.comCA policy updates (Defender risk level condition)
Start with Day 1 →Week 8 →