A four-month, lab-driven curriculum that takes a learner from first logon to designing, running, and hardening a full stack of enterprise Windows services — the operating system and command line, Active Directory, Group Policy, DNS, DHCP, file and web services, remote access, backup, monitoring, and the security and purple-team practice that keep a production Windows estate defensible.
Curriculum home: Repository README
| Property | Value |
|---|---|
| Course Title | Enterprise Windows Infrastructure & Security |
| Folder | Enterprise-Windows-Infrastructure-Security/ |
| Tag | Windows Server Administration & Security |
| Slug | windows-infra |
| Level | Beginner to Advanced |
| Duration | 4 Months (16 Weeks · 1 Hour/Day · ~120 Hours) |
| Focus | Windows Server Administration & Enterprise Hardening |
| Reference Systems | Windows Server 2019 / 2022 / 2025 · Windows 10 / 11 |
| Modules | 20 |
| Delivery | Self-paced notes + hands-on labs |
| Language | English |
Note
What this course is
A study-and-practice track built as an Obsidian knowledge base and published as GitHub-flavored Markdown. Each module is a folder with its own Readme hub and a set of deep-dive notes containing tagged, copy-ready commands and configuration. It is designed to be read in order but is fully cross-linked for reference use.
Master Windows Server administration and defensive hardening end to end: the operating system, the command line, and PowerShell; virtualization and lab setup; networking fundamentals; then the core enterprise identity and infrastructure services — Active Directory Domain Services, Group Policy, DNS, and DHCP — followed by file services and DFS, IIS web hosting, FTP, proxy, and remote-access/VPN. The program closes with server management, backup and disaster recovery, monitoring and logging, and a dedicated enterprise-security and purple-team practice.
The course is delivered through extensive, reproducible hands-on labs modelled on a real corp.local domain, so every concept is paired with a working configuration you can build, break, attack, and harden.
The Enterprise Windows Infrastructure & Security program provides practical, enterprise-ready skills across Windows system administration, directory services, networking, security hardening, and detection. It assumes no prior Windows Server experience and progresses to advanced multi-service, adversary-tested deployments.
By the end of the course, students will be able to:
- Administer Windows from the GUI, the command line, and PowerShell
- Stand up an isolated multi-VM lab and a
corp.localActive Directory forest - Manage users, groups, OUs, and policy at scale with Group Policy
- Deploy and integrate DNS, DHCP, file/DFS, IIS, FTP, proxy, and VPN services
- Operate, back up, and recover an enterprise Windows estate
- Build monitoring, logging, and detection pipelines
- Apply a hardening baseline and validate it against real attacks (purple team)
Tip
Administration and security are taught together — every service module ends with a hardening pass (least privilege, secure configuration, auditing, and firewalling) rather than treating security as an afterthought.
The 20 modules are sequenced into six progressive stages. Complete each stage before advancing; later service and security modules assume the fundamentals from earlier stages.
Stage 1 Foundations ............ OS Fundamentals · Windows OS Administration · Windows Commands · PowerShell
Stage 2 Lab & Networking ....... Lab Setup & Virtualization · Networking Fundamentals
Stage 3 Directory & Core ....... Active Directory (AD DS) · Group Policy (GPO) · DNS · DHCP
Stage 4 Infrastructure ......... File Services & DFS · IIS · FTP · Proxy · Remote Access & VPN
Stage 5 Operate & Resilience ... Server Management · Backup/Restore/Recovery · Monitoring & Logging
Stage 6 Security & Practice ..... Enterprise Security (purple team) · Software Development Life Cycle
flowchart LR
A[Foundations] --> B[Lab & Networking]
B --> C[Directory & Core Services]
C --> D[Infrastructure Services]
D --> E[Operate & Resilience]
E --> F[Enterprise Security & Practice]
Important
Prerequisite chaining — the infrastructure services (Stage 4) depend on Directory & Core Services (Stage 3) and Networking (Stage 2). Attempting an IIS, DFS, or VPN lab without a working domain, DNS, and DHCP will leave gaps in authentication and name resolution.
| Requirement | Level | Notes |
|---|---|---|
| Basic computer literacy | Required | File management, installing software |
| Operating-system familiarity | Required | Any desktop OS is sufficient |
| Basic networking concepts | Recommended | IP addressing, DNS, ports — reinforced in-course |
| Prior Windows Server experience | Not required | Course starts from first logon |
| A machine capable of virtualization | Required | See Hardware & Virtualization Requirements |
Tip
No Windows Server background is needed. If you already administer Windows, you can skim Stage 1 and start at Lab Setup & Virtualization.
| Component | Recommended | Purpose |
|---|---|---|
| Primary server OS | Windows Server 2022 (2019/2025 also covered) | Domain controller and member-server roles |
| Client OS | Windows 10 / 11 | Domain-joined workstation for testing |
| Attacker OS | Kali Linux | Attack & defense / purple-team exercises |
| Hypervisor | VirtualBox 7.x, Hyper-V, or VMware Workstation | Building the multi-VM lab |
| Management tools | RSAT, Windows Admin Center, PowerShell 5.1 / 7.x | Remote administration |
| Optional | Wireshark | Traffic analysis for networking/service labs |
Warning
Track version differences deliberately. Roles, defaults, and security baselines differ across Windows Server 2019/2022/2025 — labs note where they diverge; do not assume a step on 2022 is identical on 2019.
| Resource | Minimum | Recommended |
|---|---|---|
| CPU | 4 cores with VT-x/AMD-V | 6+ cores with virtualization enabled |
| RAM | 8 GB | 16 GB+ (to run 3–4 VMs concurrently) |
| Disk | 120 GB free | 250 GB+ SSD |
| Network | 1 host-only + 1 NAT adapter | Additional internal networks for multi-VM labs |
Important
Hardware virtualization (Intel VT-x / AMD-V) must be enabled in BIOS/UEFI. Without it, hypervisors fall back to slow emulation or fail to start 64-bit guests.
The lab is a small virtual network of guests on a single host. Later phases add an attacker VM and expand into multi-service topologies.
| Item | Detail |
|---|---|
| Hypervisor | VirtualBox 7.x, Hyper-V, or VMware Workstation |
| Guest count | 1 DC + 1 member server + 1 client minimum; add Kali for attack labs |
| Networking | Host-only/internal network (10.10.10.0/24) for isolated service testing; NAT for updates |
| Snapshots | Take a clean baseline snapshot per VM before each lab |
Tip
Snapshot before you harden. Take a snapshot after a clean install and again after base configuration — hardening steps (GPO, LAPS, firewall, LSA protection) are the most common source of lockouts, and snapshots make recovery instant.
A reference topology used across the infrastructure modules — the corp.local domain on an isolated internal network:
┌─────────────────────────┐
│ Host (Hypervisor) │
└───────────┬─────────────┘
│ internal net 10.10.10.0/24 · corp.local
┌───────────────┬───────┴───────┬────────────────┐
│ │ │ │
┌───────────┐ ┌───────────┐ ┌───────────┐ ┌──────────────┐
│ DC01 │ │ SRV01 │ │ WKS01 │ │ Kali │
│ Win Server│ │ Win Server│ │ Win 10/11 │ │ attacker │
│ AD DS·DNS │ │ IIS·FS/DFS│ │ domain │ │ (red team) │
│ DHCP·GPO │ │ FTP·Proxy │ │ client │ │ │
└───────────┘ └───────────┘ └───────────┘ └──────────────┘
| Role | Guest | Services exercised |
|---|---|---|
| Domain controller | DC01 (Windows Server) |
AD DS, DNS, DHCP, Group Policy |
| Member server | SRV01 (Windows Server) |
IIS, File Services/DFS, FTP, Proxy, Remote Access |
| Client | WKS01 (Windows 10/11) |
Domain join, policy testing, resource access |
| Attacker | Kali |
Enumeration, attack & defense, purple-team validation |
Note
Keep the lab on an isolated internal/host-only network. Standing up a rogue DHCP or DNS server, or running attack tooling, on a shared LAN will disrupt other devices.
20 teaching modules grouped into six logical tracks, each linking to the module's own Readme hub — plus the Practical Labs and Enterprise Projects collections (below).
| # | Module | Focus |
|---|---|---|
| 1 | Fundamentals of the Operating System | How Windows works: kernel, processes, services, the registry, file systems |
| 2 | Windows OS Administration | Users, groups, permissions, features, and day-to-day administration |
| 3 | Windows Commands | Core CMD utilities for administration and troubleshooting |
| 4 | Windows PowerShell | Cmdlets, pipelines, scripting, and administration automation |
| # | Module | Focus |
|---|---|---|
| 5 | Lab Setup & Virtualization | Building the isolated multi-VM lab and base VM images |
| 6 | Networking Fundamentals | IP addressing, routing, name resolution, ports, and firewalls |
| # | Module | Focus |
|---|---|---|
| 7 | Active Directory Domain Services (AD DS) | Forests, domains, OUs, users/groups, replication, FSMO, Kerberos |
| 8 | Group Policy Objects (GPO) | Centralized policy, security settings, and configuration at scale |
| 9 | Domain Name System (DNS) | AD-integrated DNS, zones, records, forwarders, and DNSSEC |
| 10 | Dynamic Host Configuration Protocol (DHCP) | Scopes, reservations, options, and failover |
| # | Module | Focus |
|---|---|---|
| 11 | File Services & DFS | Shares, NTFS/share permissions, DFS namespaces and replication |
| 12 | Web Server (IIS) | Sites, bindings, TLS, application pools, and hardening |
| 13 | FTP Server Administration | Secure FTP/FTPS, isolation, and access control |
| 14 | Proxy Server Administration | Forward proxy, filtering, and access policy |
| 15 | Remote Access & VPN | RRAS, VPN protocols, NPS, and remote-desktop services |
| # | Module | Focus |
|---|---|---|
| 16 | Windows Server Management | Roles/features, Server Manager, Windows Admin Center, remote management |
| 17 | Backup, Restore & Recovery | Windows Server Backup, system state, and disaster recovery |
| 18 | Monitoring & Logging | Event logs, performance, auditing, and detection pipelines |
| # | Module | Focus |
|---|---|---|
| 19 | Enterprise Security | Hardening baseline, attack surface, detection, and purple-team practice |
| 20 | Software Development Life Cycle | Secure SDLC concepts underpinning the tooling and automation used |
Warning
The security module includes offensive techniques for validation only. Run enumeration and attack tooling exclusively against your own isolated lab — never against production or third-party systems.
7 standalone labs — each self-contained (objective, requirements, topology, setup, validation, cleanup, troubleshooting). Start at the Practical Labs index.
| # | Lab | Primary track |
|---|---|---|
| 01 | Lab Foundations | Lab Setup & Virtualization |
| 02 | Core Services | DNS · DHCP |
| 03 | Active Directory | AD DS · Group Policy |
| 04 | Remote Access | Remote Access & VPN |
| 05 | Attack & Defense | Enterprise Security |
| 06 | Backup & Recovery | Backup, Restore & Recovery |
| 07 | Monitoring | Monitoring & Logging |
10 multi-service capstone projects — each combines several modules into a realistic, hardened production build with architecture, deployment, security controls, and validation. Start at the Enterprise Projects index.
| # | Project | Integrates |
|---|---|---|
| 01 | Build a Single-DC Domain | AD DS, DNS, base GPO |
| 02 | Core Network Services (DHCP + DNS) | DHCP, DNS, reservations |
| 03 | Publish Web + Database | IIS, TLS, app/data tier |
| 04 | File Services & DFS Namespace | File Services, DFS, permissions |
| 05 | Remote Access for a Branch | RRAS, VPN, NPS |
| 06 | Backup & Disaster Recovery Drill | Windows Server Backup, system state, DR |
| 07 | Monitoring & Detection Pipeline | Event logging, auditing, alerting |
| 08 | Harden the Enterprise | GPO baseline, LAPS, firewall, CIS |
| 09 | Attack the Lab | Enumeration, exploitation, lateral movement |
| 10 | Purple-Team Capstone | Attack + detect + harden, end to end |
On completion, a student can:
| Domain | Outcome |
|---|---|
| Administration | Administer Windows Server from the GUI, CMD, and PowerShell |
| Directory | Design and manage an AD forest, OUs, groups, and Group Policy |
| Services | Deploy DNS, DHCP, File/DFS, IIS, FTP, proxy, and VPN |
| Operations | Manage, back up, and recover an enterprise Windows estate |
| Detection | Build monitoring, logging, and auditing/detection pipelines |
| Hardening | Apply and validate a security baseline against real attacks |
| Infrastructure | Stand up and interconnect a multi-server corp.local domain |
This course's content aligns with the objectives of major Windows administration and security certifications. It is exam-relevant preparation, not a guarantee of passing.
| Certification | Alignment | Strongly covered | Partially covered |
|---|---|---|---|
| Microsoft AZ-800 (Windows Server Hybrid Administrator) | ⭐⭐⭐⭐ High | AD DS, DNS, DHCP, file/storage, Group Policy, remote access | Azure hybrid/cloud integration |
| Microsoft AZ-801 (Configuring Windows Server Hybrid Advanced) | ⭐⭐⭐⭐ High | Security, hardening, monitoring, backup/DR, high availability | Azure-specific migration |
| Microsoft SC-300 / SC-400 (Identity & Information Protection) | ⭐⭐⭐ Medium | Directory identity, authentication | Cloud identity & data governance |
| CompTIA Server+ | ⭐⭐⭐⭐ High | Server hardware, OS, storage, disaster recovery | Vendor-specific hardware |
| CompTIA Network+ | ⭐⭐⭐ Medium | Networking fundamentals stage | Deeper WAN/cloud networking |
Tip
The directory- and services-depth here maps most directly to AZ-800/AZ-801; the security, attack, and purple-team practice reinforces the defensive side of those exams.
- Microsoft Learn — Windows Server — https://learn.microsoft.com/windows-server/
- Microsoft Learn — Active Directory Domain Services — https://learn.microsoft.com/windows-server/identity/ad-ds/
- Windows Security Configuration Framework — https://learn.microsoft.com/windows/security/threat-protection/windows-security-configuration-framework/
- CIS Benchmarks (hardening baselines) — https://www.cisecurity.org/cis-benchmarks
- MITRE ATT&CK (adversary techniques) — https://attack.mitre.org
- Linux Administration & Server Hardening — the Linux counterpart to this course.
Contributions that improve accuracy, add labs, or deepen module notes are welcome.
| Guideline | Detail |
|---|---|
| Conventions | Follow vault house style: one H1 per note (= filename), intro sentence, standard sections, tagged code fences |
| Links | Use relative Markdown links ([text](../Folder/Note.md), [text](Note.md#heading-slug)) — they render on GitHub and still resolve in Obsidian. Avoid [[wikilinks]] |
| Callouts | Use GitHub alert syntax — > [!NOTE], > [!TIP], > [!IMPORTANT], > [!WARNING], > [!CAUTION] (marker alone on its line; a title on the next line as > **Title**) |
| Scope | Keep each note single-topic; wire new notes into the relevant module Readme hub |
| Accuracy | Prefer tested commands and cite upstream docs for configuration claims |
| Safety | Offensive techniques are for the isolated lab only; never target production or third-party systems |
Educational use. These notes are a personal study knowledge base compiled from public documentation and hands-on labs. Third-party trademarks (Microsoft, Windows, Windows Server, Active Directory, and others) belong to their respective owners and are referenced for identification only. Verify every command in an isolated lab before using it in production. Licensed under CC BY 4.0.