Episode Details

Back to Episodes
Microsoft Defender EASM - Simply Explained

Microsoft Defender EASM - Simply Explained

Season 3 Published 17 hours ago
Description
Microsoft Defender External Attack Surface Management, or Defender EASM, helps organizations understand a critical security question: what can someone outside your company actually see? Your public footprint is much larger than your official website. Forgotten subdomains, old campaign pages, test environments, cloud services, public IP addresses, certificates, and internet-facing servers can remain visible long after the teams that created them have moved on. Defender EASM approaches security from an attacker's perspective and helps discover that external footprint.

YOU CAN'T PROTECT WHAT YOU CAN'T SEE
Traditional security inventories usually start from inside the organization. IT knows about managed laptops, servers, applications, and user accounts. Marketing may maintain its own websites, while cloud teams and suppliers manage additional services. The problem exists between those inventories. Projects end, but test websites remain online. Subdomains are forgotten. IP addresses change. Certificates expire. Suppliers may continue operating public services that internal security teams no longer actively track. If something remains reachable from the public internet, attackers can potentially discover it even when your organization has forgotten about it.

WHAT MICROSOFT DEFENDER EASM ACTUALLY DOES
Microsoft Defender EASM is designed to find, map, and monitor the parts of an organization that face the public internet. EASM stands for External Attack Surface Management. External means resources visible outside your internal network. Attack surface represents the public locations, systems, and services that could potentially be reached or inspected. Management means continuously understanding and maintaining that external picture. Defender EASM can discover domains, subdomains, hosts, public IP addresses, web pages, certificates, and internet-facing services associated with an organization.

EASM IS NOT ANOTHER FIREWALL OR ANTIVIRUS
The Defender name can create some confusion. Defender EASM doesn't replace firewalls, endpoint protection, patch management, email security, or cloud workload protection. Instead, it helps answer the question that comes before those controls: what does the public internet know about your organization? Internal security tools can tell you about systems you already manage. Defender EASM starts from outside and can potentially uncover assets that never made it into your internal inventory.

HOW EASM DISCOVERY WORKS
Discovery begins with something Microsoft calls a seed. A seed is a known piece of public information associated with your organization. This could include a domain, public IP address or range, hostname, email contact, Autonomous System Number, or company information contained in public registration data. You don't need to provide a complete inventory. Instead, Defender EASM follows relationships between publicly available information to build a broader picture of your external attack surface.

FROM ONE DOMAIN TO AN ENTIRE MAP
Imagine starting with your primary company domain. That domain could reveal a subdomain. A certificate associated with the subdomain could contain additional names. Those names could point toward hosts, which could lead to public IP addresses and internet-facing services. Each discovery can create another clue. Microsoft describes this as recursive discovery. Defender EASM follows public relationships and continuously expands the map of assets potentially associated with your organization.

OWNERSHIP STILL MATTERS
Finding a relationship doesn't automatically mean your company owns the resource. An IP address could belong to a shared cloud provider. A certificate might contain names associated with several customers. A public website could be operated by an external agency or supplier. Defender EASM helps identify these relationsh
Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us