I3: Windows Security Basics
Build safe Windows foundations for accounts, profiles, permissions, updates, built-in protection, Event Viewer, startup activity, services, local security habits, and evidence-based defensive administration.
Module Snapshot
Intermediate
Track
I3 of 17
Module
8
Lessons
25 questions
Module test
Windows defense in context
This module connects identity, permissions, updates, Microsoft Defender, event logs, startup items, services, user behavior, and secure maintenance into one workflow.
Main Question
How do defenders review a Windows device without confusing one setting, alert, event, account, or startup item with the complete security story?
Students will compare the approved device role with accounts, permissions, protection state, updates, logs, startup activity, services, settings, ownership, user behavior, and change history before making controlled recommendations.
Safety Boundary
Every Windows device, account, profile, path, permission, alert, event, service, setting, application, file, share, and organization in this module is fictional. Practice stays authorized, read-only, and limited to supplied training evidence.
Prerequisites
What Students Should Bring into Module I3
Completed I1 Networking for Defenders or can explain addresses, ports, services, firewalls, segmentation, and network evidence limits.
Completed I2 Linux Basics for Security or can explain accounts, permissions, processes, services, logs, packages, updates, and safe change control.
Understands least privilege, ownership, authorization, evidence preservation, rollback, validation, and defensive reporting.
Agrees to use only fictional Windows systems, accounts, logs, alerts, paths, services, applications, and organizations.
Professional Workflow
Identify, Observe, Correlate, Compare, and Document
Identify
Confirm the fictional device role, owner, user population, sensitivity, exposure, support status, location, and approved purpose.
Observe
Review accounts, profiles, permissions, updates, Defender state, event logs, startup items, services, and security settings.
Correlate
Connect users, groups, paths, processes, services, event records, alerts, updates, network activity, and change history.
Compare
Check observed state against the approved baseline, least privilege, system role, support policy, and maintenance plan.
Document
Record confirmed facts, confidence, missing evidence, risk, owner, recommendation, validation, rollback, and review date.
Learning Objectives
What Students Will Be Able to Do
Explain how Windows accounts, profiles, groups, privileges, sign-in methods, ownership, and lifecycle controls connect.
Interpret file, folder, and shared-resource permissions using ownership, inheritance, effective access, and least privilege.
Evaluate update status, restart requirements, support lifecycle, firewall settings, encryption, and built-in protections.
Interpret fictional Microsoft Defender detections, scans, quarantines, exclusions, and reputation signals without overclaiming.
Correlate Event Viewer records, service state, startup activity, user context, and system changes into defensible timelines.
Create a safe Windows security review with evidence, confidence, ownership, validation, rollback, monitoring, and documentation.
Distinguish confirmed device facts from reasonable conclusions, missing evidence, alternate explanations, and unsupported assumptions.
Prioritize findings by exposure, privilege, sensitivity, business impact, confidence, dependency, and change readiness.
Big Ideas
Six Ideas That Shape the Entire Module
A Windows device is a system of connected controls
Accounts, profiles, permissions, Defender, firewall settings, update state, services, startup items, logs, and user behavior influence one another.
An alert is not the same as a conclusion
A Defender detection, Event Viewer record, or failed sign-in must be interpreted with file, process, user, device, network, owner, and timeline evidence.
Least privilege applies to people and software
Standard users, administrators, service accounts, startup apps, scheduled tasks, shared folders, and exclusions should receive only the access they need.
Security and reliability must be managed together
Updates, service changes, account removal, permission correction, and startup cleanup need testing, rollback, validation, and monitoring.
Local habits affect technical outcomes
Locking, downloading, browsing, reporting, removable media, backups, and account choices determine whether technical controls can work effectively.
Evidence limits must be stated clearly
Windows logs, alerts, timestamps, user names, file paths, and process records can support facts without proving complete intent or root cause.
Module Path
Eight Intermediate Lessons
Each lesson includes professional hooks, fictional Windows evidence, technical comparison, defensive workflows, safe labs, scenario decisions, a scored quiz, a checklist, and a portfolio prompt.
I3.1
Lesson 1
Windows Accounts and Profiles
Understand local and connected accounts, standard and administrator roles, user profiles, account lifecycle, sign-in protections, and evidence-based access review.
Defensive Lab
Classify fictional Windows accounts and profiles by owner, role, privilege, activity, lifecycle, sign-in method, and approved purpose.
Lesson Outcome
Produce an account-and-profile review that identifies stale, overprivileged, shared, temporary, and ownerless identities.
Primary Evidence
Account inventory, local-group membership, profile path, last sign-in, owner record, role history, and sign-in protection state.
I3.2
Lesson 2
File Permissions and Shared Folders
Interpret Windows file and folder access, inherited permissions, ownership, groups, sharing, effective access, and least privilege.
Defensive Lab
Review a fictional permissions matrix and identify broad, inherited, stale, duplicate, and mismatched access.
Lesson Outcome
Create a least-privilege permissions recommendation with ownership, validation, rollback, and documentation.
Primary Evidence
NTFS-style permissions, inheritance, explicit entries, group membership, share access, ownership, classification, and usage records.
I3.3
Lesson 3
Windows Updates and Security Settings
Connect update status, restart needs, support lifecycle, firewall settings, account protections, device encryption, and secure maintenance planning.
Defensive Lab
Prioritize fictional Windows updates and security-setting corrections using risk, compatibility, ownership, maintenance windows, and rollback.
Lesson Outcome
Build a Windows maintenance plan that separates security urgency from operational readiness.
Primary Evidence
Installed updates, pending restart, support status, firewall profiles, encryption state, approved exceptions, backup, test, and change records.
I3.4
Lesson 4
Microsoft Defender Concepts
Understand built-in endpoint protection, real-time protection, scans, detections, quarantine, exclusions, reputation controls, and alert limitations.
Defensive Lab
Analyze fictional Defender alerts and decide which evidence, owner, containment, validation, and follow-up are needed.
Lesson Outcome
Write a detection review that distinguishes alert facts from assumptions and recommends safe next actions.
Primary Evidence
Protection state, scan type, detection name, affected path, process context, action, quarantine, exclusion, reputation, and follow-up status.
I3.5
Lesson 5
Event Viewer and Windows Logs
Read fictional Security, System, Application, Defender, and setup events while using timestamps, sources, event IDs, users, and context correctly.
Defensive Lab
Correlate fictional Windows events into a timeline and separate confirmed facts from likely explanations and evidence gaps.
Lesson Outcome
Produce a confidence-rated Windows timeline supported by multiple logs and clearly stated limits.
Primary Evidence
Log name, provider, event ID, timestamp, computer, user, process, service, result, correlation identifier, and change record.
I3.6
Lesson 6
Startup Apps and Services
Connect startup applications, scheduled activity, services, dependencies, users, executable paths, resource use, and approved system roles.
Defensive Lab
Review a fictional startup and service inventory for expected, failed, duplicate, stale, hidden, and review-required entries.
Lesson Outcome
Create a startup-and-service baseline with safe removal, restriction, validation, and rollback recommendations.
Primary Evidence
Startup location, executable path, publisher, service account, state, dependencies, trigger, resource use, owner, package, and logs.
I3.7
Lesson 7
Local Security Habits
Apply strong local-device habits involving locking, updates, downloads, removable media, browser safety, backups, accounts, privacy, and reporting.
Defensive Lab
Create a defensive Windows workstation checklist and evaluate fictional daily-use scenarios.
Lesson Outcome
Build a practical user-facing security guide that connects daily behavior with technical controls.
Primary Evidence
Device-lock habits, update compliance, download source, removable-media handling, browser protections, backup status, and reporting workflow.
I3.8
Lesson 8
Windows Security Review Lab
Combine accounts, profiles, permissions, updates, Defender, event logs, startup items, services, settings, and local security habits.
Defensive Lab
Complete a multi-source fictional Windows security assessment and produce a professional improvement plan.
Lesson Outcome
Deliver a full Windows Security Review Report with prioritized findings, owners, evidence limits, validation, rollback, and monitoring.
Primary Evidence
Inventory, identity, permissions, update status, Defender, events, startup, services, configuration, user behavior, and change management.
Identity Model
Windows Accounts and Profiles Need Lifecycle Control
Standard user
Supports everyday work with limited ability to change system-wide settings.
Main risks
May still expose data through downloads, browser activity, shared folders, removable media, or weak daily habits.
Review evidence
Owner, role, profile, groups, sign-in method, recent activity, application need, and lifecycle.
Local administrator
Performs approved device management or support tasks.
Main risks
Permanent broad privilege increases impact if the account is misused, shared, stale, or poorly monitored.
Review evidence
Named ownership, separate standard account, approval, activity, duration, support need, monitoring, and review date.
Connected organizational account
Provides managed access to applications, settings, files, and organizational services.
Main risks
Old group assignments, profile data, sign-in tokens, and shared-device use can outlive the original role.
Review evidence
Current employment or student status, group assignments, device ownership, profile state, sign-in protection, and offboarding.
Service identity
Runs an approved Windows service, scheduled activity, automation, or application component.
Main risks
Overprivilege, interactive sign-in, unknown ownership, stale credentials, broad folder access, and hidden dependencies.
Review evidence
Service owner, exact dependency, privilege, logon rights, executable path, credential management, monitoring, and expiration.
Temporary support account
Supports time-limited troubleshooting, migration, vendor work, or deployment.
Main risks
Accounts may remain enabled, privileged, or assigned to groups after the approved work ends.
Review evidence
Ticket, owner, approval, expiration, last activity, group membership, profile data, and confirmed removal.
Disabled or retired account
Preserves historical ownership, profile, or audit context after active use ends.
Main risks
May still own files, scheduled tasks, services, encrypted data, or cached resources.
Review evidence
Login disabled, ownership transferred, jobs reassigned, groups removed, data retained correctly, and profile archived or removed.
Permission Model
Effective Access Is More Than One Permission Entry
Ownership
The recorded owner may be able to change permissions and should match the approved data or system responsibility.
Explicit permissions
Access entries applied directly to a file or folder may override the simplicity of inherited design.
Inherited permissions
Permissions passed from a parent folder can provide efficient management but may also spread overly broad access.
Group-based access
Access is easier to govern through approved role groups than through many individual entries.
Effective access
The final result depends on all relevant user, group, inherited, explicit, deny, and share conditions.
Share and local permissions
Network access can depend on both shared-folder rules and local file-system permissions.
Defense-in-Depth
Six Protection Layers on a Windows Device
Account and sign-in protection
Standard-user use, strong sign-in methods, limited administrator membership, lockout, session locking, and lifecycle review.
File and data protection
Least-privilege permissions, approved sharing, ownership, encryption, backup, classification, and retention.
Endpoint protection
Real-time protection, reputation checks, scans, quarantine, cloud-delivered protection, controlled exclusions, and alert review.
Network protection
Firewall profiles, approved services, restricted sharing, trusted zones, segmentation, and monitored connections.
System maintenance
Supported versions, security updates, restart completion, application compatibility, backup, rollback, and post-change validation.
Visibility and response
Event Viewer, Defender records, service logs, monitoring, ownership, incident reporting, and documented escalation.
Evidence Model
Nine Windows Evidence Sources Students Will Connect
Account and profile evidence
Can support
Account type, owner, group membership, privilege, profile path, last sign-in, status, and lifecycle.
Limitation
Does not prove the person behind every action or whether all profile data is still needed.
Permission and sharing evidence
Can support
Ownership, inherited and explicit permissions, group access, share rules, and effective access.
Limitation
Does not prove the approved business purpose or every application-level restriction.
Update and settings evidence
Can support
Installed updates, pending restart, support state, firewall profile, encryption, and security settings.
Limitation
Does not prove application compatibility or that every control is functioning correctly.
Defender evidence
Can support
Protection state, scan result, detection, file path, process context, action, quarantine, and exclusion.
Limitation
Does not automatically prove user intent, full origin, or complete system compromise.
Windows event evidence
Can support
Timestamp, log name, provider, event ID, user, process, service, result, device, and sequence.
Limitation
Logs may be incomplete, filtered, overwritten, delayed, or missing context from another source.
Startup and service evidence
Can support
Startup source, executable path, publisher, service account, state, dependencies, trigger, and resource use.
Limitation
Running or starting automatically does not prove approved need or safe configuration.
Network and firewall evidence
Can support
Observed connections, listening services, ports, profiles, allow or deny decisions, and network scope.
Limitation
Does not prove complete application purpose, data content, or user intent.
Change and ownership evidence
Can support
Approval, owner, deployment, exception, maintenance, test, rollback, and review context.
Limitation
Does not prove the final technical state matches the documented plan.
User-behavior and support evidence
Can support
Reported downloads, removable-media use, browser prompts, support actions, and daily device habits.
Limitation
Human reports may be incomplete and should be correlated with technical records.
Fake Evidence Preview
How Intermediate Windows Evidence Connects
09:12:04
Inventory
training-win-04 documented as a staff learning workstation
Provides the approved device role, owner, environment, and expected protections.
09:14:28
Account
Temporary support account remains in the local Administrators group
Confirms current privilege but still requires lifecycle, owner, and dependency review.
09:17:41
Defender
Potentially unwanted application quarantined from Downloads
Confirms a detection and quarantine action, not the user's intent or complete origin by itself.
09:20:33
Update
Security update installed; restart still required
Shows package installation status but not the final active or validated running state.
09:23:06
Event Viewer
Application startup failure follows missing permission on a shared configuration folder
Connects application failure with access context but still needs ownership and change evidence.
09:28:15
Service
Legacy synchronization service starts automatically with no current owner
Shows active startup behavior and an ownership gap that requires dependency review.
Integrated Case Preview
Fictional Windows Review Finding Matrix
Expired administrator account
Account remains enabled, belongs to local Administrators, expired nine days ago, and has no active ticket.
Unnecessary elevated access increases impact and weakens accountability.
HighPublicly shared internal project folder
Share is reachable by all staff, folder contains internal deployment notes, and inherited access exceeds the approved project group.
Internal information is available beyond the intended team.
HighDefender exclusion without owner
A broad Downloads-folder exclusion exists, no current change record exists, and the original testing project ended.
Broad exclusion reduces scanning coverage in a high-risk location.
HighPending restart after security update
Update installed successfully, restart required, maintenance window still open, and rollback is prepared.
The intended protected running state is not yet active.
MediumUnowned legacy startup service
Service starts automatically, project ended, no recent use appears, and dependency ownership is incomplete.
Unnecessary software and startup exposure increase attack surface and maintenance burden.
MediumVocabulary
Core Windows Security Terms
Local account
An account created and managed on one Windows device.
Connected account
An account linked to an organizational or online identity service.
User profile
The collection of user-specific settings, data, folders, and application state.
Administrator
An account or group with elevated authority to make system-wide changes.
Inheritance
The process by which a file or folder receives permissions from a parent location.
Effective access
The final access result after all relevant user, group, inherited, explicit, deny, and sharing rules are considered.
Real-time protection
Continuous monitoring intended to identify and respond to suspicious files, processes, or activity.
Quarantine
A controlled location or state used to isolate a detected item from normal use.
Exclusion
A configured location, process, or object that a protection control does not inspect normally.
Event ID
A numeric identifier used with a provider and log context to classify an event type.
Provider
The Windows component, application, service, or control that generated an event.
Startup application
Software configured to start when a user signs in or the system starts.
Service
A background component managed by Windows to provide system or application functions.
Pending restart
A state in which an installed change requires a restart before the intended running state is active.
Device encryption
Protection that helps prevent unauthorized access to data stored on a device.
Firewall profile
A set of firewall behavior associated with a network type or trust context.
Common Mistakes
Mistakes That Weaken Windows Security Reviews
Professional Standards
How Every I3 Recommendation Should Be Written
Evidence first
Record the original state before recommending account, permission, update, service, or Defender changes.
One change at a time
Sequence corrections so the team can validate cause and effect and roll back safely.
Named ownership
Every account, share, exclusion, service, exception, and finding needs a responsible owner.
Time-bounded exceptions
Temporary privilege, exclusions, delayed updates, and broad access require expiration and review.
Validation after change
Confirm sign-in, application function, permissions, Defender state, services, logs, network access, and user impact.
Privacy-respecting documentation
Use fictionalized evidence and avoid exposing real device, user, event, file, or security details.
Portfolio Outcome
Windows Security Review Report
Students will build a fictional report containing a device-role summary, account and profile review, permissions matrix, update and settings assessment, Defender evidence, Event Viewer timeline, startup and service review, local-security checklist, prioritized risks, evidence limits, owners, and authorized next actions.
Module Assessment
25-Question I3 Module Test
The test will cover Windows accounts, profiles, permissions, shared folders, updates, security settings, Defender concepts, Event Viewer, startup apps, services, local security habits, evidence limits, change control, and integrated analysis. Answers stay hidden until submission.
Assessment domains
Identity, permissions, updates, Defender, logs, startup, services, user behavior, evidence correlation, prioritization, and safe defensive response.
Completion Path
How to Complete Module I3
Complete all eight lessons
Finish every explanation, lab, scenario, quiz, checklist, and portfolio prompt.
Build the portfolio report
Combine evidence from all lessons into one fictional Windows review.
Take the module test
Complete all 25 questions and identify weak domains.
Review and validate
Return to weak lessons and improve the final report before moving to I4.