Specialization
Identity Protection Engineer
Master enterprise identity protection with Active Directory, Microsoft Entra ID and CyberArk PAM — secure on-prem and cloud identities, detect identity attacks and enforce Zero Trust.
LEARNING OUTCOMES
What you will learn
Active Directory security and hardening
AD attack detection and defense
Microsoft Entra ID Protection and PIM
Privileged access management with CyberArk
Curriculum
Authentication vs authorization, identity attack surface, identity threat landscape, Zero Trust identity principles, best practices
AD architecture, domain controllers, OUs, GPOs, LDAP, Kerberos, NTLM, AD hardening, tiered administration
Pass-the-Hash, Pass-the-Ticket, Kerberoasting, AS-REP Roasting, Golden/Silver Ticket, DCSync, LAPS, credential protection
Conditional Access, MFA, passwordless authentication, Identity Protection, Identity Secure Score, risk detection and policies
Access reviews, access packages, entitlement management, lifecycle workflows, PIM, Just-In-Time access
PAM fundamentals, CyberArk architecture, safe management, session recording, password vault, credential rotation, PSM
Identity threat detection, insider threat detection, Defender XDR and Sentinel integration, executive reporting
Secure Active Directory, configure Entra ID, deploy Conditional Access, configure CyberArk PAM, investigate identity incidents, executive report
Tools covered: Active Directory (AD DS), Group Policy, LDAP, Kerberos, Microsoft Entra ID, Entra Identity Protection, Entra PIM, Microsoft Defender XDR, Microsoft Sentinel, CyberArk PAM
Program experience
Each cohort combines instructor-led sessions, guided practice, weekly assignments, capstone work and career preparation.