Advanced Microsoft Security Course for 2027

The Advanced Microsoft Security Course for 2027 will cover a diverse range of 12 subjects, all hand-selected by our globally acclaimed TOP cybersecurity experts – Paula Januszkiewicz, Sami Laiho, Peter Kloep, and Amr Thabet to name a few. The crucial topics are set to define the field in 2027, equipping you with the foresight and knowledge to stay ahead of the curve.

Crafted by top cybersecurity experts working on the frontlines of the cybersecurity industry, our six-week course for advanced professionals holds practicality at its core. You’ll acquire the tools and techniques necessary to prepare yourself against threats in 2027, irrespective of your work location.

This unique course takes place ONLY once a year and each edition offers a fresh perspective and a new Syllabus.

To keep the training highly interactive, enrollment is limited to 200 participants.

Course benefits

  • You’ll participate in a live, online certification program, divided into 12 modules + 1 bonus module spread over 6 weeks.
  • Live, online sessions happening twice a week, 2 hours each (at 7PM CET / 10AM PDT / 1PM EDT).
  • The syllabus covers 12 modules.
  • The program has an interactive, hands-on formula — and after every class, you’ll be able to ask questions.
  • During the 6 week program, you’ll also get free access to the CQURE Training Lab and closed Discord group where you can share your challenges and upgrade your network.
  • Official CQURE certificate “Microsoft Security Master 2027” after passing the final exam.
  • All the video recordings and extra materials are yours to keep for 12 months from the start of the program.
  • 30-Day, Money-Back Guarantee
  • Interactive classroom
  • After every class you’ll be able to ask questions.

Prerequisites

The Advanced Microsoft Security Course for 2027 is unique and not everyone’s cup of tea.
It’s designed for those who already have a solid foundation in cybersecurity.

 Target Audience

In the realm of cybersecurity, knowledge is the ultimate currency. While the digital world may offer unlimited access to information, it’s critical to discern that not all information holds significant value. AMSC is a certified 6-week online cybersecurity course created for advanced professionals as well as all the geeks who are already fluent in the Windows environment (including security skills, penetration testing, etc.).

Intermediate to advanced Windows Security Professionals
This program is for you, if you want to level up and become key expert in your company (or even in your field). We promise to challenge your ways of thinking and executing.

Ethical Hackers (who are familiar with…)
Attendee needs to have general fluency in Windows environment (including security skills, penetration testing etc.) Active Directory related knowledge is required. Take the quiz to see where are you at.

Brave Newbies
If you are a newbie you can still apply, but the program WILL NOT cover the basics — so it might be really challenging for you to get in or to keep up with the group.

 

The Advanced Microsoft Security Course for 2027 will cover a diverse range of 12 subjects, all hand-selected by our globally acclaimed TOP cybersecurity experts – Paula Januszkiewicz, Sami Laiho, Peter Kloep, and Amr Thabet to name a few. The crucial topics are set to define the field in 2027, equipping you with the foresight and knowledge to stay ahead of the curve.

Each year, we strive to enhance our program, incorporating feedback and trends to keep it relevant and impactful.

This year get ready for 6 weeks of intense learning featuring (please note that module titles, the agenda, and individual module dates may be subject to change):

Module 0: Opening Keynote | Modern Cybersecurity Signals: What Global Breaches Teach Us About Modern Defense

October 27, 2026
with Paula Januszkiewicz, Amr Thabet, Artur Kalinowski, Marcin Krawczyk

Real-world attacks rarely reveal themselves through obvious indicators. This session explores the threat hunting signals, investigation techniques, and attack patterns observed during recent incident response engagements. Attendees will learn how modern adversaries operate across identity, endpoint, cloud, and hybrid infrastructures, and how security teams can identify the signals attackers hope remain unnoticed.

Module 1: Tiering 2.0: Administrative Forests, PAWs and Modern Privileged Access

October 29, 2026
with Peter Kloep

Traditional administrative models are struggling to keep pace with today’s threat landscape. This session examines the evolution of privileged access management through Tiering 2.0, administrative forests, and Privileged Access Workstations (PAWs). Attendees will learn how to design resilient administrative environments, reduce credential exposure, and build architectures that limit the impact of identity compromise while supporting modern hybrid infrastructures.

Module 2: AI-Powered Infrastructure Profiling: Building a Security Blueprint with AI Agents

November 3, 2026
with Amr Thabet, Artur Kalinowski

Learn how AI agents can analyze infrastructure, configurations, identities, attack paths, vulnerabilities, and security telemetry to create a comprehensive security profile of an organization. The session demonstrates practical approaches for identifying weaknesses, prioritizing remediation efforts, and accelerating security assessments using AI-assisted analysis.

Module 3: Security Baseline Assessment and Hardening for Modern Windows Server Environments

November 5, 2026
with Norbert Krzepicki

A secure environment starts with a strong foundation. This session explores practical approaches to assessing and hardening Windows Server environments against modern attack techniques. Attendees will learn how to evaluate security baselines, identify common configuration weaknesses, prioritize remediation efforts, and implement controls that reduce attack surface while maintaining operational efficiency. Real-world examples will demonstrate how seemingly minor misconfigurations can lead to significant security exposures.

Module 4: Identity-First Security: Protecting Entra ID and Hybrid Identity Infrastructure

November 10, 2026
with Marcin Krawczyk

As identities become the primary target for attackers, organizations must rethink their defensive strategies. This session focuses on securing Microsoft Entra ID and hybrid identity environments against modern threats. Participants will explore attack paths targeting synchronization services, privileged identities, conditional access policies, and authentication mechanisms while learning practical techniques for monitoring, detection, and risk reduction.

Module 5: Privileged Access Abuse in Databases: Detection and Defense

November 12, 2026
with Margarita Naumova

Databases often contain an organization’s most valuable information, making privileged accounts highly attractive targets for attackers. This session explores common techniques used to abuse elevated database privileges, establish persistence, and access sensitive information. Attendees will learn how to detect suspicious administrative activity, monitor for indicators of compromise, and implement defensive controls that strengthen database security without disrupting business operations.

Module 6: AI-Powered Security Operations: Building the SOC of 2027

November 17, 2026
with Amr Thabet, Marcin Krawczyk

Security Operations Centers are entering a new era where AI is becoming an active participant in detection, investigation, and response. This session examines how AI-powered workflows can assist analysts by automating repetitive tasks, accelerating investigations, correlating telemetry across multiple platforms, and uncovering hidden attack patterns. Attendees will gain practical insights into building a modern SOC that combines human expertise with AI-driven decision support.

Module 7: Enterprise Forensics and Attack Correlation: Reconstructing the Full Attack Story

November 19, 2026
with Paula Januszkiewicz, Artur Kalinowski

Successful investigations require more than collecting evidence. They require understanding the complete story behind an attack. This session demonstrates how to correlate endpoint, identity, cloud, and forensic artifacts to reconstruct attacker activity from initial access through persistence, lateral movement, and objectives. Attendees will learn practical investigation methodologies and discover how seemingly unrelated artifacts can reveal critical insights about an adversary’s actions.

Module 8: What’s New in PKI: Preparing for Post-Quantum Cryptography

November 24, 2026
with Peter Kloep

The arrival of quantum computing presents one of the most significant cryptographic challenges organizations have faced in decades. This session explores the latest developments in Public Key Infrastructure and the transition toward post-quantum cryptographic algorithms. Participants will gain an understanding of emerging standards, migration challenges, certificate lifecycle considerations, and practical steps organizations can take today to prepare for a post-quantum future.

Module 9: Digital Certificates and Enterprise PKI with Microsoft Active Directory Certificate Services (AD CS)

November 26, 2026
with Richard Hicks

Digital certificates underpin modern authentication, encryption, and trust. This session provides a practical deep dive into designing, deploying, and securing enterprise PKI using Microsoft Active Directory Certificate Services. Attendees will learn best practices for certificate lifecycle management, common implementation pitfalls, security considerations, and how modern PKI supports identity-first security strategies across hybrid environments.

Module 10: Securing Your On-Prem AD: Air-Gapped or Not?

December 1, 2026
with Sami Laiho

Despite the rise of cloud services, Active Directory remains the backbone of identity for many organizations. This session focuses on protecting on-premises AD environments against modern attack techniques regardless of whether they operate in connected or isolated environments. Participants will learn how attackers target AD, what defensive controls provide the greatest value, and how to build a resilient identity infrastructure capable of withstanding today’s threats.

Module 11: Cloud Security Monitoring and Detection Engineering for Hybrid Enterprises

December 3, 2026
with Marcin Krawczyk

Hybrid infrastructures introduce new visibility challenges and attack opportunities. This session explores modern approaches to cloud security monitoring and detection engineering, focusing on Microsoft cloud environments and hybrid architectures. Attendees will learn how to build meaningful detections, identify cloud persistence techniques, correlate activity across environments, and improve visibility into attacker behavior without overwhelming security teams with noise.

Module 12: – BONUS – Browser Extension Management: The Most Overlooked Enterprise Attack Surface

December 8, 2026
with Norbert Krzepicki

Browser extensions have become one of the fastest-growing attack surfaces in modern enterprise environments. This session explores the risks associated with unmanaged extensions, including credential theft, session hijacking, data exfiltration, malicious updates, and supply chain compromise. Attendees will learn how to assess extension-related risks, implement governance strategies, monitor extension activity, and build controls that reduce exposure while maintaining user productivity.

Module 13: – BONUS – Effective LOLBAS Monitoring: Detecting Living-Off-the-Land Techniques in Enterprise Environments

with Norbert Krzepicki

Attackers increasingly rely on legitimate operating system tools to evade detection and blend into normal administrative activity. This session focuses on monitoring and detecting Living-Off-the-Land Binaries, Scripts and Libraries (LOLBAS) commonly abused during modern attacks. Attendees will learn how to identify suspicious usage patterns, distinguish malicious activity from legitimate administration, and develop monitoring strategies that improve detection effectiveness while minimizing false positives.

Module 14: – BONUS – PowerShell for Digital Investigation

with Amr Thabet

PowerShell remains one of the most powerful tools available to investigators and incident responders. This session demonstrates how PowerShell can be leveraged to collect evidence, analyze system artifacts, investigate suspicious activity, and automate forensic workflows at scale. Attendees will learn practical techniques for accelerating investigations, validating findings, and uncovering attacker activity using native Windows capabilities and advanced PowerShell-based forensic methodologies.

Module 15: – BONUS – BitLocker Done the Modern Way: Implementing Protection Against YellowKey and Emerging Physical Access Threats

with Norbert Krzepicki

As physical attack techniques continue to evolve, organizations must revisit how they protect data at rest. This session explores modern BitLocker deployment strategies, secure PIN implementation, TPM-based protection mechanisms, recovery key management, and defenses against attacks such as YellowKey. Attendees will learn practical approaches for strengthening endpoint protection and reducing the risk of credential theft and unauthorized access through physical compromise.

Certification

You’ll receive an official CQURE certificate “Microsoft Security Master 2027″ after passing the final exam. Yes, there will be a final exam. And 24 hours counting towards your CPE’s.

 

 

 

FAQ – Advanced Microsoft Security Course for 2027

Hva koster kurset?
Prisen er 39 500 NOK. Kurset inkluderer lab-øvelser, kursmateriell og sertifisering.

Hvor lenge varer kurset?
Kurset går over 6 uker og består av 12 moduler + bonusmoduler. Live online-sesjonene gjennomføres to ganger i uken, med 2 timer per sesjon.

Hvordan gjennomføres kurset?
Kurset gjennomføres som live online-undervisning med engelskspråklig kursmateriell og engelsktalende instruktører. Programmet er interaktivt, og deltakerne kan stille spørsmål etter hver klasse.

Hvem passer kurset for?
Kurset passer for avanserte fagpersoner innen Microsoft-sikkerhet, Windows-miljøer, identitet, hybrid infrastruktur og cybersikkerhet.

  • Intermediate to advanced Windows Security Professionals
  • Ethical Hackers med erfaring fra Windows-miljøer
  • Security Engineers og Security Architects
  • Incident Responders og Threat Hunters
  • SOC-analytikere
  • IT-profesjonelle med solid grunnlag i cybersikkerhet

Hvilke forkunnskaper anbefales?
Kurset er utviklet for deltakere som allerede har et solid grunnlag innen cybersikkerhet. Erfaring med Windows-miljøer, sikkerhet, penetration testing og Active Directory anbefales.

Passer kurset for nybegynnere?
Kurset dekker ikke grunnleggende cybersikkerhet. Nybegynnere kan delta, men innholdet er avansert og kan være krevende uten forkunnskaper.

Hva lærer jeg i løpet av kurset?
Du får innsikt i avanserte sikkerhetstemaer som forventes å prege trusselbildet i 2027. Etter kurset vil du ha bedre forståelse for:

  • Moderne angrepsmønstre og sikkerhetssignaler
  • Privileged access management og moderne administrative modeller
  • AI-drevet infrastrukturprofilering og sikkerhetsvurdering
  • Hardening av Windows Server-miljøer
  • Beskyttelse av Entra ID og hybrid identity
  • AI-powered security operations og fremtidens SOC
  • Enterprise forensics og attack correlation
  • PKI, post-quantum cryptography og AD CS
  • On-prem AD security, cloud monitoring og detection engineering

Er kurset praktisk rettet?
Ja. Kurset er utviklet av CQURE-eksperter og har en praktisk og interaktiv form. Deltakerne får tilgang til CQURE Training Lab og jobber med aktuelle teknikker, verktøy og scenarioer.

Hvilke temaer dekkes i kurset?
Kurset dekker blant annet:

  • Modern cybersecurity signals og globale sikkerhetshendelser
  • Tiering 2.0, administrative forests og Privileged Access Workstations
  • AI-powered infrastructure profiling med AI-agenter
  • Security baseline assessment og Windows Server hardening
  • Identity-first security for Entra ID og hybrid identity
  • Privileged access abuse i databaser
  • AI-powered security operations og SOC of 2027
  • Enterprise forensics og attack correlation
  • Post-quantum cryptography og moderne PKI
  • Active Directory Certificate Services
  • On-prem AD security
  • Cloud security monitoring og detection engineering
  • Browser extension management
  • LOLBAS monitoring
  • PowerShell for digital investigation
  • Moderne BitLocker-beskyttelse

Får jeg tilgang til opptak og materiell etter kurset?
Ja. Deltakerne får tilgang til videoopptak og ekstra kursmateriell i 12 måneder fra programstart.

Får jeg sertifisering etter kurset?
Ja. Etter bestått avsluttende eksamen mottar du det offisielle CQURE-sertifikatet Microsoft Security Master 2027.

Hva er spesielt med dette kurset?
Kurset gjennomføres kun én gang i året, og hver utgave har nytt pensum. Programmet er laget for avanserte fagpersoner som vil holde seg oppdatert på kommende trusler, teknikker og sikkerhetsstrategier.

Er det begrenset antall plasser?
Ja. For å holde kurset interaktivt er antall deltakere begrenset til 200.

Kan kurset leveres bedriftsinternt?
Kursinformasjonen beskriver dette som et årlig live online-program. Eventuell bedriftsintern gjennomføring må avklares med Glasspaper.