Master Class: Securing Active Directory Deep Dive (SADDD-L1)


Who should attend

This course is designed for experienced system administrators, consultants and Active Directory designers. After this seminar, you will be able to design, implement and consult on highly secure Active Directory.


At least 5 years of experience with Active Directory and client systems.

Course Objectives

In this master class course, the topic of Active Directory security is taken centrally into focus - in the meantime, various attack scenarios are known, which were used, for example, in the Bundestag hack ( mimikatz ).

These valid attack scenarios are aimed at credential theft or ransomware implementation (e.g. at the logistics company Maersk with an estimated damage of 300 million euros).

The goal of this workshop is to understand these scenarios so that you can prevent them and implement an Active Directory implementation that resists these attacks and is hardened against future attacks.

The Active Directory are your "crown jewels" - without Active Directory, most corporate environments are completely crippled productively.

That's why: Understand, harden and monitor so you can sleep better.

Course Content

In this DeepDive workshop, you will learn how to implement, configure and operate Active Directory environments in a highly secure manner.

The Active Directory is "getting on in years". Especially from a security point of view, an Active Directory should NEVER be operated in the standard. Attack scenarios such as Pass-the-Hash, Silver-Ticket, Golden-Ticket or even Skeleton-Key are common ways of attackers who can attack the Active Directory and thus the users and administrators and take over the identities. Last but not least, the hack of the Bundestag with the help of mimikatz and others has shown the vulnerability of the Active Directory.

In this Master Class course, the attack scenarios on the Active Directory are first deeply examined and also carried out. With the knowledge gained from this, the Active Directory is now fundamentally hardened. This applies to existing installations, which should first be analyzed in depth, as well as new implementations, which are then completely hardened in order to be considered attack-proof in the future. The knowledge for this course was acquired in over 20 years of Active Directory experience, as well as in years of training by Paula Januszkiewicz and Sami Laiho, both world leaders in the field of security.

This course further incorporates the experience of over 50+ Active Directory concepts written by the instructor over his last 15 years - from SMB to enterprise level with 375,000 users. The topic of security is also being looked at in the direction of the General Data Protection Regulation (GDPR), which came into effect on May 25, 2018.

We promise: Our best know-how for you and your daily work from our most experienced trainers and consultants.

Training Environment:

In the training environment, we work entirely with Hyper-V. For the proactive setup of the training environment, we use a Powershell script with which you can create new virtual machines in seconds. The script was developed by your trainer himself and enables the training setup according to the customer's wishes in extreme speed with little effort.


Each participant has a dedicated server in a data center with a total of 1 Gbit connection to the Internet. Each participant server is equipped as follows:

  • 128 GB RAM
  • at least 20 vCores
  • 2 NVME-SSDs with at least 3,000 MB/s writing and at least 2,000 MB/s reading
  • 1 Gbit to the Internet Total bandwidth

Your trainer

The Advanced Master Class was developed by Andy Wendel and is delivered by himself and his experienced team.

Andy Wendel is a Senior Data Center and Cloud Architect and Certified Security Master Specialization Advanced Windows Security. He was and is trained by the internationally renowned security experts Paula Januszkiewicz and Sami Laiho. This certification is renewed every year. Andy Wendel has been working as an IT trainer and consultant since the late 1990s and is also a Certified Microsoft Learning Consultant (MCLC). Worldwide, Microsoft has only awarded 56 Certified Learning Consultants.

Prices & Delivery methods

Online Training

5 days

  • on request
Classroom Training

5 days

  • on request

Click on town name or "Online Training" to book Schedule

Asia Pacific


Online Training Time zone: UTC+8 Course language: English
Guaranteed date:   iTLS will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training.
This is a FLEX course, which is delivered both virtually and in the classroom.