The Advanced Microsoft Security Course for 2027 will cover a diverse range of 12 subjects, all hand-selected by our globally acclaimed TOP cybersecurity experts – Paula Januszkiewicz, Sami Laiho, Peter Kloep, and Amr Thabet to name a few. The crucial topics are set to define the field in 2027, equipping you with the foresight and knowledge to stay ahead of the curve.
Crafted by top cybersecurity experts working on the frontlines of the cybersecurity industry, our six-week course for advanced professionals holds practicality at its core. You’ll acquire the tools and techniques necessary to prepare yourself against threats in 2027, irrespective of your work location.

The Advanced Microsoft Security Course for 2027 will cover a diverse range of 12 subjects, all hand-selected by our globally acclaimed TOP cybersecurity experts – Paula Januszkiewicz, Sami Laiho, Peter Kloep, and Amr Thabet to name a few. The crucial topics are set to define the field in 2027, equipping you with the foresight and knowledge to stay ahead of the curve.
Each year, we strive to enhance our program, incorporating feedback and trends to keep it relevant and impactful.
This year get ready for 6 weeks of intense learning featuring (please note that module titles, the agenda, and individual module dates may be subject to change):
Module 0: Opening Keynote | Modern Cybersecurity Signals: What Global Breaches Teach Us About Modern Defense
October 27, 2026
with Paula Januszkiewicz, Amr Thabet, Artur Kalinowski, Marcin Krawczyk
Real-world attacks rarely reveal themselves through obvious indicators. This session explores the threat hunting signals, investigation techniques, and attack patterns observed during recent incident response engagements. Attendees will learn how modern adversaries operate across identity, endpoint, cloud, and hybrid infrastructures, and how security teams can identify the signals attackers hope remain unnoticed.
Module 1: Tiering 2.0: Administrative Forests, PAWs and Modern Privileged Access
October 29, 2026
with Peter Kloep
Traditional administrative models are struggling to keep pace with today’s threat landscape. This session examines the evolution of privileged access management through Tiering 2.0, administrative forests, and Privileged Access Workstations (PAWs). Attendees will learn how to design resilient administrative environments, reduce credential exposure, and build architectures that limit the impact of identity compromise while supporting modern hybrid infrastructures.
Module 2: AI-Powered Infrastructure Profiling: Building a Security Blueprint with AI Agents
November 3, 2026
with Amr Thabet, Artur Kalinowski
Learn how AI agents can analyze infrastructure, configurations, identities, attack paths, vulnerabilities, and security telemetry to create a comprehensive security profile of an organization. The session demonstrates practical approaches for identifying weaknesses, prioritizing remediation efforts, and accelerating security assessments using AI-assisted analysis.
Module 3: Security Baseline Assessment and Hardening for Modern Windows Server Environments
November 5, 2026
with Norbert Krzepicki
A secure environment starts with a strong foundation. This session explores practical approaches to assessing and hardening Windows Server environments against modern attack techniques. Attendees will learn how to evaluate security baselines, identify common configuration weaknesses, prioritize remediation efforts, and implement controls that reduce attack surface while maintaining operational efficiency. Real-world examples will demonstrate how seemingly minor misconfigurations can lead to significant security exposures.
Module 4: Identity-First Security: Protecting Entra ID and Hybrid Identity Infrastructure
November 10, 2026
with Marcin Krawczyk
As identities become the primary target for attackers, organizations must rethink their defensive strategies. This session focuses on securing Microsoft Entra ID and hybrid identity environments against modern threats. Participants will explore attack paths targeting synchronization services, privileged identities, conditional access policies, and authentication mechanisms while learning practical techniques for monitoring, detection, and risk reduction.
Module 5: Privileged Access Abuse in Databases: Detection and Defense
November 12, 2026
with Margarita Naumova
Databases often contain an organization’s most valuable information, making privileged accounts highly attractive targets for attackers. This session explores common techniques used to abuse elevated database privileges, establish persistence, and access sensitive information. Attendees will learn how to detect suspicious administrative activity, monitor for indicators of compromise, and implement defensive controls that strengthen database security without disrupting business operations.
Module 6: AI-Powered Security Operations: Building the SOC of 2027
November 17, 2026
with Amr Thabet, Marcin Krawczyk
Security Operations Centers are entering a new era where AI is becoming an active participant in detection, investigation, and response. This session examines how AI-powered workflows can assist analysts by automating repetitive tasks, accelerating investigations, correlating telemetry across multiple platforms, and uncovering hidden attack patterns. Attendees will gain practical insights into building a modern SOC that combines human expertise with AI-driven decision support.
Module 7: Enterprise Forensics and Attack Correlation: Reconstructing the Full Attack Story
November 19, 2026
with Paula Januszkiewicz, Artur Kalinowski
Successful investigations require more than collecting evidence. They require understanding the complete story behind an attack. This session demonstrates how to correlate endpoint, identity, cloud, and forensic artifacts to reconstruct attacker activity from initial access through persistence, lateral movement, and objectives. Attendees will learn practical investigation methodologies and discover how seemingly unrelated artifacts can reveal critical insights about an adversary’s actions.
Module 8: What’s New in PKI: Preparing for Post-Quantum Cryptography
November 24, 2026
with Peter Kloep
The arrival of quantum computing presents one of the most significant cryptographic challenges organizations have faced in decades. This session explores the latest developments in Public Key Infrastructure and the transition toward post-quantum cryptographic algorithms. Participants will gain an understanding of emerging standards, migration challenges, certificate lifecycle considerations, and practical steps organizations can take today to prepare for a post-quantum future.
Module 9: Digital Certificates and Enterprise PKI with Microsoft Active Directory Certificate Services (AD CS)
November 26, 2026
with Richard Hicks
Digital certificates underpin modern authentication, encryption, and trust. This session provides a practical deep dive into designing, deploying, and securing enterprise PKI using Microsoft Active Directory Certificate Services. Attendees will learn best practices for certificate lifecycle management, common implementation pitfalls, security considerations, and how modern PKI supports identity-first security strategies across hybrid environments.
Module 10: Securing Your On-Prem AD: Air-Gapped or Not?
December 1, 2026
with Sami Laiho
Despite the rise of cloud services, Active Directory remains the backbone of identity for many organizations. This session focuses on protecting on-premises AD environments against modern attack techniques regardless of whether they operate in connected or isolated environments. Participants will learn how attackers target AD, what defensive controls provide the greatest value, and how to build a resilient identity infrastructure capable of withstanding today’s threats.
Module 11: Cloud Security Monitoring and Detection Engineering for Hybrid Enterprises
December 3, 2026
with Marcin Krawczyk
Hybrid infrastructures introduce new visibility challenges and attack opportunities. This session explores modern approaches to cloud security monitoring and detection engineering, focusing on Microsoft cloud environments and hybrid architectures. Attendees will learn how to build meaningful detections, identify cloud persistence techniques, correlate activity across environments, and improve visibility into attacker behavior without overwhelming security teams with noise.
Module 12: – BONUS – Browser Extension Management: The Most Overlooked Enterprise Attack Surface
December 8, 2026
with Norbert Krzepicki
Browser extensions have become one of the fastest-growing attack surfaces in modern enterprise environments. This session explores the risks associated with unmanaged extensions, including credential theft, session hijacking, data exfiltration, malicious updates, and supply chain compromise. Attendees will learn how to assess extension-related risks, implement governance strategies, monitor extension activity, and build controls that reduce exposure while maintaining user productivity.
Module 13: – BONUS – Effective LOLBAS Monitoring: Detecting Living-Off-the-Land Techniques in Enterprise Environments
with Norbert Krzepicki
Attackers increasingly rely on legitimate operating system tools to evade detection and blend into normal administrative activity. This session focuses on monitoring and detecting Living-Off-the-Land Binaries, Scripts and Libraries (LOLBAS) commonly abused during modern attacks. Attendees will learn how to identify suspicious usage patterns, distinguish malicious activity from legitimate administration, and develop monitoring strategies that improve detection effectiveness while minimizing false positives.
Module 14: – BONUS – PowerShell for Digital Investigation
with Amr Thabet
PowerShell remains one of the most powerful tools available to investigators and incident responders. This session demonstrates how PowerShell can be leveraged to collect evidence, analyze system artifacts, investigate suspicious activity, and automate forensic workflows at scale. Attendees will learn practical techniques for accelerating investigations, validating findings, and uncovering attacker activity using native Windows capabilities and advanced PowerShell-based forensic methodologies.
Module 15: – BONUS – BitLocker Done the Modern Way: Implementing Protection Against YellowKey and Emerging Physical Access Threats
with Norbert Krzepicki
As physical attack techniques continue to evolve, organizations must revisit how they protect data at rest. This session explores modern BitLocker deployment strategies, secure PIN implementation, TPM-based protection mechanisms, recovery key management, and defenses against attacks such as YellowKey. Attendees will learn practical approaches for strengthening endpoint protection and reducing the risk of credential theft and unauthorized access through physical compromise.

Certification
You’ll receive an official CQURE certificate “Microsoft Security Master 2027″ after passing the final exam. Yes, there will be a final exam. And 24 hours counting towards your CPE’s.

FAQ – Advanced Microsoft Security Course for 2027
Hva koster kurset?
Prisen er 39 500 NOK. Kurset inkluderer lab-øvelser, kursmateriell og sertifisering.
Hvor lenge varer kurset?
Kurset går over 6 uker og består av 12 moduler + bonusmoduler. Live online-sesjonene gjennomføres to ganger i uken, med 2 timer per sesjon.
Hvordan gjennomføres kurset?
Kurset gjennomføres som live online-undervisning med engelskspråklig kursmateriell og engelsktalende instruktører. Programmet er interaktivt, og deltakerne kan stille spørsmål etter hver klasse.
Hvem passer kurset for?
Kurset passer for avanserte fagpersoner innen Microsoft-sikkerhet, Windows-miljøer, identitet, hybrid infrastruktur og cybersikkerhet.
Hvilke forkunnskaper anbefales?
Kurset er utviklet for deltakere som allerede har et solid grunnlag innen cybersikkerhet. Erfaring med Windows-miljøer, sikkerhet, penetration testing og Active Directory anbefales.
Passer kurset for nybegynnere?
Kurset dekker ikke grunnleggende cybersikkerhet. Nybegynnere kan delta, men innholdet er avansert og kan være krevende uten forkunnskaper.
Hva lærer jeg i løpet av kurset?
Du får innsikt i avanserte sikkerhetstemaer som forventes å prege trusselbildet i 2027. Etter kurset vil du ha bedre forståelse for:
Er kurset praktisk rettet?
Ja. Kurset er utviklet av CQURE-eksperter og har en praktisk og interaktiv form. Deltakerne får tilgang til CQURE Training Lab og jobber med aktuelle teknikker, verktøy og scenarioer.
Hvilke temaer dekkes i kurset?
Kurset dekker blant annet:
Får jeg tilgang til opptak og materiell etter kurset?
Ja. Deltakerne får tilgang til videoopptak og ekstra kursmateriell i 12 måneder fra programstart.
Får jeg sertifisering etter kurset?
Ja. Etter bestått avsluttende eksamen mottar du det offisielle CQURE-sertifikatet Microsoft Security Master 2027.
Hva er spesielt med dette kurset?
Kurset gjennomføres kun én gang i året, og hver utgave har nytt pensum. Programmet er laget for avanserte fagpersoner som vil holde seg oppdatert på kommende trusler, teknikker og sikkerhetsstrategier.
Er det begrenset antall plasser?
Ja. For å holde kurset interaktivt er antall deltakere begrenset til 200.
Kan kurset leveres bedriftsinternt?
Kursinformasjonen beskriver dette som et årlig live online-program. Eventuell bedriftsintern gjennomføring må avklares med Glasspaper.

CQURE Masterclass & Microsoft Security
Threat Hunting, SOC & Incident Response
Identity, AD & Microsoft Security sertifisering