Ensure that a Microsoft Defender External Attack Surface Management (EASM) workspace is deployed to scan your organization's externally facing online infrastructure, such as domains, hosts, IP address CIDR blocks, and SSL certificates. When you create a Defender EASM workspace, you provide Seeds (FQDNs, IP CIDR blocks, and WHOIS records) that the service uses to crawl and scan the internet, building an Inventory of publicly exposed assets. Within 24-48 hours of adding Seeds, Defender EASM generates Insights for the discovered Inventory items, including known vulnerabilities (CVEs), open ports and protocols, and weak or expired SSL certificates, with each finding classified as High, Medium, or Low risk and some entries including proposed mitigations.
Monitoring your organization's external attack surface helps security and IT teams identify unknown or unmanaged internet-facing assets before an external threat actor can discover and exploit them. Microsoft Defender EASM continuously enriches your inventory of exposed assets with vulnerability, network, and certificate data, and lets you export these findings, including as CSV files, for use in vulnerability management workflows and red/purple team exercises, reducing the risk of overlooked entry points such as forgotten domains, exposed hosts, or SSL certificates nearing expiration.
Note: Insights are not generated immediately. Microsoft Defender EASM requires 24-48 hours after Seeds are provided to complete its initial scan and populate the Inventory with enrichment data. This recommendation is a manual check: beyond confirming that a Defender EASM workspace exists, there is no single measurable setting that defines "appropriately configured" — Seeds, exclusions, and Inventory review policies should be tailored to your own organization’s known online infrastructure.
Microsoft Defender EASM workspaces are available with a 30-day free trial but can accrue significant charges afterward. Costs are calculated daily as the number of billable Inventory items multiplied by the per-item daily cost, and an estimated cost is not provided within the tool. Contact your Microsoft sales representative for pricing information and set a reminder before the trial period ends, since no charges are billed if the workspace is deleted by the last day of the trial.
Audit
To determine if Microsoft Defender EASM is enabled for your Azure subscriptions, perform the following operations:
Remediation / Resolution
To deploy and configure a Microsoft Defender EASM workspace for your Azure subscriptions, perform the following operations:
Note: Microsoft Defender EASM is billed daily, based on the number of billable Inventory items, once the 30-day free trial period ends. Set a reminder to review or delete the workspace before the trial expires to avoid unexpected charges, and contact your Microsoft sales representative for detailed pricing information.References
- Azure Official Documentation
- Defender External Attack Surface Management
- Create a Defender EASM Azure Resource
- Azure Command Line Interface (CLI) Documentation
- az account
- az account
- az resource
- az resource
- az resource
- az group