Microsoft Defender EASM
General

Create and manage policies with policy engine automation

In brief

The page metadata and wording for adding policies were updated. It reiterates that newly created policies can take up to one week to affect inventory.

What Defender admins need to know

No administrator action is stated; allow up to one week for newly created policy changes to appear.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create and manage policies with policy engine automation

To create a policy in your Defender EASM resource, perform the following steps:

  1. Navigate to the Policies page by selecting Policies from the Manage section of the left-hand navigation pane within your Defender EASM resource.
  2. Select + Add Policy. This actionSelecting this button opens a right-hand pane to configure the policy.

Screenshot of Policies page with Add Policies button highlighted and policy configuration panel open.

  1. Then select the query that triggers the policy; any assets that match the query parameters are automatically updated with the designated action. For instance, you may want to label all expiring entities (e.g. domains, SSL certificates) with a "needs renewal" label. You can create a saved query that searches for metadata that expires within 30 days or is already expired. You can then designate that the system applies a "needs renewal" label to all applicable assets. You can either select to power the policy with a previously saved filter, or you can create a new query. All saved queries are visible within the dropdown, or select Create new saved query to configure new filter parameters. If you would like to view the assets that match your query before setting up a policy, it is recommended that you first create a saved query from the Inventory page.
  2. Once all fields are configured, select Add to create your policy.

It takes newlyNewly created policies can take up to one week to apply changes to your inventory. Once the changes are implemented, you see them reflected in the Change history tab. You can also see the impacted assets when using the Policy name filter on your inventory, and the Policies page lists an accurate count of impacted assets. Preexisting policies update any newly applicable assets within five to seven days of the last run.

Edit or delete policies