Discovers the internet-facing assets an organisation owns, including domains, hosts, IPs, ASNs and certificates, and highlights their vulnerabilities. Defender for Cloud differs in assessing only the resources you connect to it.
Also called Defender EASM.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender External Attack Surface Management in context, with comparison tables and the common traps.
Terms in this definition
- CONNECT
In SQL Server, the right to open a connection to a database. Fabric's equivalent is Read permission on an item, which allows connecting to a warehouse or SQL endpoint but not querying anything in it.
Related terms
- Approved Inventory
State in Defender EASM for assets the organisation owns directly. Such assets are scanned every day and, by default, are the only ones dashboard charts display.
- ASN
Short for autonomous system number, which identifies a BGP routing domain. Azure VPN gateways use 65515 by default, a reserved value on-premises peers must avoid; Defender EASM also discovers ASNs as an internet asset type.
- Asset chain-based management
Way of removing assets in bulk in Defender EASM, chosen by the discovery group, seed or discovery chain entry that found them; everything discovered downstream goes too.
- Attack surface composition
Within Defender EASM's Attack Surface Summary dashboard, the area that shows how many assets exist in each category; it does not list insights.
- Attack surface priorities
Severity view in Defender EASM's summary dashboard. Insights are banded as high, medium or low, and the low band takes in deprecated technology plus infrastructure that will soon expire.
- Attack Surface Summary
Top-level overview dashboard in Defender EASM. One section, priorities, ranks insights by how severe they are; another, composition, just tallies assets.
- Candidate (Defender EASM asset state)
Asset state in Defender EASM meaning there is some, but insufficient, linkage to your seeds; someone must check ownership by hand, and the asset is only scanned during discovery.
- Defender EASM inventory filters
Inventory view filters in Defender EASM. Because State = Approved is applied by default, clear that filter to list assets in any other state.
See Microsoft Defender External Attack Surface Management in the full glossary