Skip to content
← Back to the guide

Defender External Attack Surface Management

4slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 4

Defender External Attack Surface Management

Defender EASM discovers your organisation's internet-facing assets — including the ones you didn't know about.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-external-attack-surface-management

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 4
01

Does Defender EASM need an agent installed anywhere?

No. It's entirely external — it discovers and scans assets from the outside, the way an attacker would, starting from seed domains, IP ranges, and organisation names. Nothing is installed on your infrastructure.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-external-attack-surface-management

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 4
02

How is Defender EASM different from Defender for Cloud?

Defender for Cloud protects and assesses resources you already know you own inside Azure, AWS, or GCP subscriptions you've connected. EASM discovers internet-facing assets regardless of who owns the subscription or whet…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-external-attack-surface-management

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 4
03

What happens to an asset EASM finds that isn't actually ours?

You mark it as not applicable in the confirmed inventory. EASM's discovery is confidence-scored, not certain — a shared hosting provider or a similarly-named third party can surface as a candidate. Triage is expected be…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/defender-external-attack-surface-management

Slide 4Download PNG

Auto-generated from Defender External Attack Surface Management. This page is not indexed and isn't part of the guide itself.