
E-mmersion Security: practice attack detection and investigation in a live lab
Hands-on security labs where your team simulates real attacks and investigates the alerts they generate. The first lab covers Microsoft Defender for Identity protecting Active Directory.
- Format
- Instructor-led hands-on lab
- First lab
- Microsoft Defender for Identity
- Levels
- Lab 1 (light) and Lab 2 (full)
- Delivery
- In person, hybrid or remote
Think like the attacker, respond like the defender
Identity is the most common path into the enterprise. These labs reproduce the techniques attackers use against Active Directory and show how each one is detected and investigated.
- Deploy and manage Microsoft Defender for Identity sensors in a controlled environment
- Simulate user, IP address and network reconnaissance over SMB, DNS and LDAP
- Detect Kerberoasting preparation and suspected DC Sync replication attacks
- Investigate credential access and lateral movement alerts end to end
- Detect data exfiltration over SMB, such as copying ntds.dit from a domain controller
- Review detection logic, response options and practices to mitigate identity-based threats
Identity protection in action
The first E-mmersion Security lab focuses on Microsoft Defender for Identity, with two levels so you can match depth to your team.
Attack, detect and investigate on a lab Active Directory: reconnaissance, credential access, lateral movement and exfiltration scenarios, with real-time alerts analyzed alongside our experts. Available as a light or a full lab.
What your team takes away
Practical detection skills
Analysts learn to spot anomalous behavior and investigate identity alerts with the full context Defender for Identity provides.
Understanding of attack paths
Direct experience of how reconnaissance, credential theft and lateral movement unfold against Active Directory.
Clear priorities for your environment
A closing review with key takeaways and recommendations to strengthen identity protection in production.
For teams that defend identity
- Technical decision makers responsible for security posture
- Security analysts and IT professionals who operate Active Directory and Microsoft Entra ID
- Organizations evaluating or expanding Microsoft Defender for Identity
- Technical support and expert guidance are provided throughout the lab
Strengthen identity beyond the lab
Detection is one layer. These offerings cover access controls, passwordless authentication and round-the-clock response.
Start your Security E-mmersion
Tell us about your identity environment and what you want your team to practice. We confirm the lab level and schedule it.
Share your contextYour Active Directory and Microsoft Entra ID setup and your detection priorities.
Choose the levelA light lab for a focused session or a full lab for deeper practice.
Run the labIn English or Spanish, in person, hybrid or remote.