What is Microsoft Defender EASM?
Microsoft Defender External Attack Surface Management (EASM) continuously discovers and monitors your organization’s external, internet-exposed attack surface. The service uses Microsoft’s proprietary discovery technology to recursively identify further connected domains, IP addresses, hosts, and web applications, starting from known assets (discovery seeds).
EASM goes beyond traditional vulnerability scanners by also finding unknown or forgotten assets: shadow IT, expired domains, orphaned subdomains, or exposed development environments. Many security incidents begin with the exploitation of exactly such forgotten resources.
The service provides a dynamic inventory of all external assets (current or historic), evaluates their security risk through dashboards covering vulnerabilities, compliance, and security hygiene, and prioritizes recommendations.
Core Features
- Automatic, recursive discovery of external assets starting from discovery seeds such as domains, IP ranges, or ASNs
- Dynamic asset inventory with classification into current and historic assets
- Dashboards covering vulnerabilities, compliance status, and security hygiene
- Filterable inventory view for specific use cases
- Integration with Microsoft Sentinel and Microsoft Defender for Cloud
Typical Use Cases
Attack Surface Reduction: Identifying and eliminating unnecessarily exposed services, forgotten subdomains, and outdated web applications to reduce the attack surface.
M&A Due Diligence: Assessing the external attack surface of an acquisition target to identify security risks before the acquisition and factor them into the valuation.
Compliance Monitoring: Continuously verifying that all externally reachable systems comply with security policies, including SSL certificates, patch levels, and configuration.
Benefits
- Visibility across the entire external attack surface from an attacker’s perspective
- Detection of shadow IT and forgotten assets that internal scanners cannot reach
- Prioritized recommendations instead of data overload
- Selectable storage region for customer data, including within the EU
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Microsoft Defender EASM: from initial setup and asset discovery to risk assessment and developing a strategy for reducing your external attack surface.
Frequently Asked Questions
What differentiates EASM from a vulnerability scanner?
Vulnerability scanners check known assets for known vulnerabilities. EASM first recursively discovers all connected assets, including unknown ones, starting from discovery seeds such as domains, IP ranges, or Whois organizations, and then evaluates their risk.
What seed information is required?
For initial setup, known, legitimate assets such as domains, IP address blocks, hosts, email contacts, or autonomous system numbers are sufficient. EASM automatically expands these seeds by analyzing observed connections to the organization.
What does Microsoft Defender EASM cost?
Billing is usage-based per billable asset in the inventory, calculated on a daily basis. After a trial period, tracked assets are billed automatically; refer to the official pricing page for current rates.
Where is the data stored?
Defender EASM processes global internet data as well as customer-specific data such as your own labels. Customer-specific data is stored in the Azure region you select, which allows storage within the EU.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
