High School IntermediateModule I3 of 17Defensive Only

I3: Windows Security Basics

Build safe Windows foundations for accounts, profiles, permissions, updates, built-in protection, Event Viewer, startup activity, services, local security habits, and evidence-based defensive administration.

Module Snapshot

Intermediate

Track

I3 of 17

Module

8

Lessons

25 questions

Module test

Windows defense in context

This module connects identity, permissions, updates, Microsoft Defender, event logs, startup items, services, user behavior, and secure maintenance into one workflow.

Main Question

How do defenders review a Windows device without confusing one setting, alert, event, account, or startup item with the complete security story?

Students will compare the approved device role with accounts, permissions, protection state, updates, logs, startup activity, services, settings, ownership, user behavior, and change history before making controlled recommendations.

Safety Boundary

Every Windows device, account, profile, path, permission, alert, event, service, setting, application, file, share, and organization in this module is fictional. Practice stays authorized, read-only, and limited to supplied training evidence.

Prerequisites

What Students Should Bring into Module I3

1

Completed I1 Networking for Defenders or can explain addresses, ports, services, firewalls, segmentation, and network evidence limits.

2

Completed I2 Linux Basics for Security or can explain accounts, permissions, processes, services, logs, packages, updates, and safe change control.

3

Understands least privilege, ownership, authorization, evidence preservation, rollback, validation, and defensive reporting.

4

Agrees to use only fictional Windows systems, accounts, logs, alerts, paths, services, applications, and organizations.

Professional Workflow

Identify, Observe, Correlate, Compare, and Document

1

Identify

Confirm the fictional device role, owner, user population, sensitivity, exposure, support status, location, and approved purpose.

2

Observe

Review accounts, profiles, permissions, updates, Defender state, event logs, startup items, services, and security settings.

3

Correlate

Connect users, groups, paths, processes, services, event records, alerts, updates, network activity, and change history.

4

Compare

Check observed state against the approved baseline, least privilege, system role, support policy, and maintenance plan.

5

Document

Record confirmed facts, confidence, missing evidence, risk, owner, recommendation, validation, rollback, and review date.

Learning Objectives

What Students Will Be Able to Do

Explain how Windows accounts, profiles, groups, privileges, sign-in methods, ownership, and lifecycle controls connect.

Interpret file, folder, and shared-resource permissions using ownership, inheritance, effective access, and least privilege.

Evaluate update status, restart requirements, support lifecycle, firewall settings, encryption, and built-in protections.

Interpret fictional Microsoft Defender detections, scans, quarantines, exclusions, and reputation signals without overclaiming.

Correlate Event Viewer records, service state, startup activity, user context, and system changes into defensible timelines.

Create a safe Windows security review with evidence, confidence, ownership, validation, rollback, monitoring, and documentation.

Distinguish confirmed device facts from reasonable conclusions, missing evidence, alternate explanations, and unsupported assumptions.

Prioritize findings by exposure, privilege, sensitivity, business impact, confidence, dependency, and change readiness.

Big Ideas

Six Ideas That Shape the Entire Module

A Windows device is a system of connected controls

Accounts, profiles, permissions, Defender, firewall settings, update state, services, startup items, logs, and user behavior influence one another.

An alert is not the same as a conclusion

A Defender detection, Event Viewer record, or failed sign-in must be interpreted with file, process, user, device, network, owner, and timeline evidence.

Least privilege applies to people and software

Standard users, administrators, service accounts, startup apps, scheduled tasks, shared folders, and exclusions should receive only the access they need.

Security and reliability must be managed together

Updates, service changes, account removal, permission correction, and startup cleanup need testing, rollback, validation, and monitoring.

Local habits affect technical outcomes

Locking, downloading, browsing, reporting, removable media, backups, and account choices determine whether technical controls can work effectively.

Evidence limits must be stated clearly

Windows logs, alerts, timestamps, user names, file paths, and process records can support facts without proving complete intent or root cause.

Module Path

Eight Intermediate Lessons

Each lesson includes professional hooks, fictional Windows evidence, technical comparison, defensive workflows, safe labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.

I3.1

Lesson 1

Windows Accounts and Profiles

Understand local and connected accounts, standard and administrator roles, user profiles, account lifecycle, sign-in protections, and evidence-based access review.

Defensive Lab

Classify fictional Windows accounts and profiles by owner, role, privilege, activity, lifecycle, sign-in method, and approved purpose.

Lesson Outcome

Produce an account-and-profile review that identifies stale, overprivileged, shared, temporary, and ownerless identities.

Open →

Primary Evidence

Account inventory, local-group membership, profile path, last sign-in, owner record, role history, and sign-in protection state.

I3.2

Lesson 2

File Permissions and Shared Folders

Interpret Windows file and folder access, inherited permissions, ownership, groups, sharing, effective access, and least privilege.

Defensive Lab

Review a fictional permissions matrix and identify broad, inherited, stale, duplicate, and mismatched access.

Lesson Outcome

Create a least-privilege permissions recommendation with ownership, validation, rollback, and documentation.

Open →

Primary Evidence

NTFS-style permissions, inheritance, explicit entries, group membership, share access, ownership, classification, and usage records.

I3.3

Lesson 3

Windows Updates and Security Settings

Connect update status, restart needs, support lifecycle, firewall settings, account protections, device encryption, and secure maintenance planning.

Defensive Lab

Prioritize fictional Windows updates and security-setting corrections using risk, compatibility, ownership, maintenance windows, and rollback.

Lesson Outcome

Build a Windows maintenance plan that separates security urgency from operational readiness.

Open →

Primary Evidence

Installed updates, pending restart, support status, firewall profiles, encryption state, approved exceptions, backup, test, and change records.

I3.4

Lesson 4

Microsoft Defender Concepts

Understand built-in endpoint protection, real-time protection, scans, detections, quarantine, exclusions, reputation controls, and alert limitations.

Defensive Lab

Analyze fictional Defender alerts and decide which evidence, owner, containment, validation, and follow-up are needed.

Lesson Outcome

Write a detection review that distinguishes alert facts from assumptions and recommends safe next actions.

Open →

Primary Evidence

Protection state, scan type, detection name, affected path, process context, action, quarantine, exclusion, reputation, and follow-up status.

I3.5

Lesson 5

Event Viewer and Windows Logs

Read fictional Security, System, Application, Defender, and setup events while using timestamps, sources, event IDs, users, and context correctly.

Defensive Lab

Correlate fictional Windows events into a timeline and separate confirmed facts from likely explanations and evidence gaps.

Lesson Outcome

Produce a confidence-rated Windows timeline supported by multiple logs and clearly stated limits.

Open →

Primary Evidence

Log name, provider, event ID, timestamp, computer, user, process, service, result, correlation identifier, and change record.

I3.6

Lesson 6

Startup Apps and Services

Connect startup applications, scheduled activity, services, dependencies, users, executable paths, resource use, and approved system roles.

Defensive Lab

Review a fictional startup and service inventory for expected, failed, duplicate, stale, hidden, and review-required entries.

Lesson Outcome

Create a startup-and-service baseline with safe removal, restriction, validation, and rollback recommendations.

Open →

Primary Evidence

Startup location, executable path, publisher, service account, state, dependencies, trigger, resource use, owner, package, and logs.

I3.7

Lesson 7

Local Security Habits

Apply strong local-device habits involving locking, updates, downloads, removable media, browser safety, backups, accounts, privacy, and reporting.

Defensive Lab

Create a defensive Windows workstation checklist and evaluate fictional daily-use scenarios.

Lesson Outcome

Build a practical user-facing security guide that connects daily behavior with technical controls.

Open →

Primary Evidence

Device-lock habits, update compliance, download source, removable-media handling, browser protections, backup status, and reporting workflow.

I3.8

Lesson 8

Windows Security Review Lab

Combine accounts, profiles, permissions, updates, Defender, event logs, startup items, services, settings, and local security habits.

Defensive Lab

Complete a multi-source fictional Windows security assessment and produce a professional improvement plan.

Lesson Outcome

Deliver a full Windows Security Review Report with prioritized findings, owners, evidence limits, validation, rollback, and monitoring.

Open →

Primary Evidence

Inventory, identity, permissions, update status, Defender, events, startup, services, configuration, user behavior, and change management.

Identity Model

Windows Accounts and Profiles Need Lifecycle Control

Standard user

Supports everyday work with limited ability to change system-wide settings.

Main risks

May still expose data through downloads, browser activity, shared folders, removable media, or weak daily habits.

Review evidence

Owner, role, profile, groups, sign-in method, recent activity, application need, and lifecycle.

Local administrator

Performs approved device management or support tasks.

Main risks

Permanent broad privilege increases impact if the account is misused, shared, stale, or poorly monitored.

Review evidence

Named ownership, separate standard account, approval, activity, duration, support need, monitoring, and review date.

Connected organizational account

Provides managed access to applications, settings, files, and organizational services.

Main risks

Old group assignments, profile data, sign-in tokens, and shared-device use can outlive the original role.

Review evidence

Current employment or student status, group assignments, device ownership, profile state, sign-in protection, and offboarding.

Service identity

Runs an approved Windows service, scheduled activity, automation, or application component.

Main risks

Overprivilege, interactive sign-in, unknown ownership, stale credentials, broad folder access, and hidden dependencies.

Review evidence

Service owner, exact dependency, privilege, logon rights, executable path, credential management, monitoring, and expiration.

Temporary support account

Supports time-limited troubleshooting, migration, vendor work, or deployment.

Main risks

Accounts may remain enabled, privileged, or assigned to groups after the approved work ends.

Review evidence

Ticket, owner, approval, expiration, last activity, group membership, profile data, and confirmed removal.

Disabled or retired account

Preserves historical ownership, profile, or audit context after active use ends.

Main risks

May still own files, scheduled tasks, services, encrypted data, or cached resources.

Review evidence

Login disabled, ownership transferred, jobs reassigned, groups removed, data retained correctly, and profile archived or removed.

Permission Model

Effective Access Is More Than One Permission Entry

Ownership

The recorded owner may be able to change permissions and should match the approved data or system responsibility.

Explicit permissions

Access entries applied directly to a file or folder may override the simplicity of inherited design.

Inherited permissions

Permissions passed from a parent folder can provide efficient management but may also spread overly broad access.

Group-based access

Access is easier to govern through approved role groups than through many individual entries.

Effective access

The final result depends on all relevant user, group, inherited, explicit, deny, and share conditions.

Share and local permissions

Network access can depend on both shared-folder rules and local file-system permissions.

Intermediate defenders do not ask only, “Can this user open the folder?” They ask, “Through which user, group, inherited rule, explicit rule, share, owner, and approved role does this access exist?”

Defense-in-Depth

Six Protection Layers on a Windows Device

1

Account and sign-in protection

Standard-user use, strong sign-in methods, limited administrator membership, lockout, session locking, and lifecycle review.

2

File and data protection

Least-privilege permissions, approved sharing, ownership, encryption, backup, classification, and retention.

3

Endpoint protection

Real-time protection, reputation checks, scans, quarantine, cloud-delivered protection, controlled exclusions, and alert review.

4

Network protection

Firewall profiles, approved services, restricted sharing, trusted zones, segmentation, and monitored connections.

5

System maintenance

Supported versions, security updates, restart completion, application compatibility, backup, rollback, and post-change validation.

6

Visibility and response

Event Viewer, Defender records, service logs, monitoring, ownership, incident reporting, and documented escalation.

Evidence Model

Nine Windows Evidence Sources Students Will Connect

Account and profile evidence

Can support

Account type, owner, group membership, privilege, profile path, last sign-in, status, and lifecycle.

Limitation

Does not prove the person behind every action or whether all profile data is still needed.

Permission and sharing evidence

Can support

Ownership, inherited and explicit permissions, group access, share rules, and effective access.

Limitation

Does not prove the approved business purpose or every application-level restriction.

Update and settings evidence

Can support

Installed updates, pending restart, support state, firewall profile, encryption, and security settings.

Limitation

Does not prove application compatibility or that every control is functioning correctly.

Defender evidence

Can support

Protection state, scan result, detection, file path, process context, action, quarantine, and exclusion.

Limitation

Does not automatically prove user intent, full origin, or complete system compromise.

Windows event evidence

Can support

Timestamp, log name, provider, event ID, user, process, service, result, device, and sequence.

Limitation

Logs may be incomplete, filtered, overwritten, delayed, or missing context from another source.

Startup and service evidence

Can support

Startup source, executable path, publisher, service account, state, dependencies, trigger, and resource use.

Limitation

Running or starting automatically does not prove approved need or safe configuration.

Network and firewall evidence

Can support

Observed connections, listening services, ports, profiles, allow or deny decisions, and network scope.

Limitation

Does not prove complete application purpose, data content, or user intent.

Change and ownership evidence

Can support

Approval, owner, deployment, exception, maintenance, test, rollback, and review context.

Limitation

Does not prove the final technical state matches the documented plan.

User-behavior and support evidence

Can support

Reported downloads, removable-media use, browser prompts, support actions, and daily device habits.

Limitation

Human reports may be incomplete and should be correlated with technical records.

Fake Evidence Preview

How Intermediate Windows Evidence Connects

09:12:04

Inventory

training-win-04 documented as a staff learning workstation

Provides the approved device role, owner, environment, and expected protections.

09:14:28

Account

Temporary support account remains in the local Administrators group

Confirms current privilege but still requires lifecycle, owner, and dependency review.

09:17:41

Defender

Potentially unwanted application quarantined from Downloads

Confirms a detection and quarantine action, not the user's intent or complete origin by itself.

09:20:33

Update

Security update installed; restart still required

Shows package installation status but not the final active or validated running state.

09:23:06

Event Viewer

Application startup failure follows missing permission on a shared configuration folder

Connects application failure with access context but still needs ownership and change evidence.

09:28:15

Service

Legacy synchronization service starts automatically with no current owner

Shows active startup behavior and an ownership gap that requires dependency review.

A strong conclusion uses the records together: device purpose, account privilege, file access, protection state, update status, restart needs, event logs, service ownership, and current defensive need.

Integrated Case Preview

Fictional Windows Review Finding Matrix

Expired administrator account

Account remains enabled, belongs to local Administrators, expired nine days ago, and has no active ticket.

Unnecessary elevated access increases impact and weakens accountability.

High

Publicly shared internal project folder

Share is reachable by all staff, folder contains internal deployment notes, and inherited access exceeds the approved project group.

Internal information is available beyond the intended team.

High

Defender exclusion without owner

A broad Downloads-folder exclusion exists, no current change record exists, and the original testing project ended.

Broad exclusion reduces scanning coverage in a high-risk location.

High

Pending restart after security update

Update installed successfully, restart required, maintenance window still open, and rollback is prepared.

The intended protected running state is not yet active.

Medium

Unowned legacy startup service

Service starts automatically, project ended, no recent use appears, and dependency ownership is incomplete.

Unnecessary software and startup exposure increase attack surface and maintenance burden.

Medium

Vocabulary

Core Windows Security Terms

Local account

An account created and managed on one Windows device.

Connected account

An account linked to an organizational or online identity service.

User profile

The collection of user-specific settings, data, folders, and application state.

Administrator

An account or group with elevated authority to make system-wide changes.

Inheritance

The process by which a file or folder receives permissions from a parent location.

Effective access

The final access result after all relevant user, group, inherited, explicit, deny, and sharing rules are considered.

Real-time protection

Continuous monitoring intended to identify and respond to suspicious files, processes, or activity.

Quarantine

A controlled location or state used to isolate a detected item from normal use.

Exclusion

A configured location, process, or object that a protection control does not inspect normally.

Event ID

A numeric identifier used with a provider and log context to classify an event type.

Provider

The Windows component, application, service, or control that generated an event.

Startup application

Software configured to start when a user signs in or the system starts.

Service

A background component managed by Windows to provide system or application functions.

Pending restart

A state in which an installed change requires a restart before the intended running state is active.

Device encryption

Protection that helps prevent unauthorized access to data stored on a device.

Firewall profile

A set of firewall behavior associated with a network type or trust context.

Common Mistakes

Mistakes That Weaken Windows Security Reviews

Assuming every Windows account belongs to an active person or current role.
Giving permanent administrator access for occasional support tasks.
Reviewing only share permissions and ignoring local file permissions.
Treating inherited access as automatically correct because it came from a parent folder.
Assuming an installed update is complete when a restart is still required.
Disabling Defender protection or creating broad exclusions for convenience.
Treating one Defender detection as proof of complete system compromise.
Reading one Event Viewer record without checking related events, provider, time, user, process, and change history.
Stopping startup apps or services before checking dependencies and owner records.
Treating high resource use or an unfamiliar publisher as proof of malicious activity.
Ignoring encryption, backups, recovery, and support lifecycle because the device appears healthy.
Publishing real usernames, hostnames, event data, paths, device identifiers, or security settings in a portfolio.

Professional Standards

How Every I3 Recommendation Should Be Written

Evidence first

Record the original state before recommending account, permission, update, service, or Defender changes.

One change at a time

Sequence corrections so the team can validate cause and effect and roll back safely.

Named ownership

Every account, share, exclusion, service, exception, and finding needs a responsible owner.

Time-bounded exceptions

Temporary privilege, exclusions, delayed updates, and broad access require expiration and review.

Validation after change

Confirm sign-in, application function, permissions, Defender state, services, logs, network access, and user impact.

Privacy-respecting documentation

Use fictionalized evidence and avoid exposing real device, user, event, file, or security details.

Portfolio Outcome

Windows Security Review Report

Students will build a fictional report containing a device-role summary, account and profile review, permissions matrix, update and settings assessment, Defender evidence, Event Viewer timeline, startup and service review, local-security checklist, prioritized risks, evidence limits, owners, and authorized next actions.

Executive summary
Scope and authorization
Device role and owner
Account and profile matrix
Permissions and sharing review
Update and settings status
Defender analysis
Event timeline
Startup and service review
Risk prioritization
Validation and rollback
Final baseline

Module Assessment

25-Question I3 Module Test

The test will cover Windows accounts, profiles, permissions, shared folders, updates, security settings, Defender concepts, Event Viewer, startup apps, services, local security habits, evidence limits, change control, and integrated analysis. Answers stay hidden until submission.

Assessment domains

Identity, permissions, updates, Defender, logs, startup, services, user behavior, evidence correlation, prioritization, and safe defensive response.

Open Module Test

Completion Path

How to Complete Module I3

1

Complete all eight lessons

Finish every explanation, lab, scenario, quiz, checklist, and portfolio prompt.

2

Build the portfolio report

Combine evidence from all lessons into one fictional Windows review.

3

Take the module test

Complete all 25 questions and identify weak domains.

4

Review and validate

Return to weak lessons and improve the final report before moving to I4.

← Intermediate TrackStart I3.1 →