Microsoft Security Exposure Management
Vulnerabilities and exposure

External Attack Surface Management Initiative in Microsoft Security Exposure Management

In brief

The page title, headings, terminology, prerequisites, navigation steps, and linked guidance were updated. Instructions now explicitly refer to the initiative and clarify the pre-built footprint workflow and its limitations.

What Defender admins need to know

Administrators can use the revised instructions when configuring or reviewing the initiative; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

External Attack Surface Managementattack surface management initiative in Exposure Management

Explore how to integrate Microsoft Defender External Attack Surface Management (MDEASM) with Microsoft Security Exposure Management (MSEM) to enhance visibility and control over your organization's external exposures. By connecting MDEASM insights to MSEM using the External Attack Surface Management initiative,attack surface management initiative in Microsoft Security Exposure Management, you can assess the risk associated with your organization's or vendor's external attack surface and manage your security posture more effectively within the Exposure Management portal.

There are two ways to use thisthe External Attack Surface Management initiative:

  • Pre-built footprint: Provides high-level insights using a predefined set of external assets, without requiring a full MDEASM subscription.
  • Full integration with MDEASM: Connects directly to your MDEASM subscription for comprehensive exposure analysis and asset-level details.

Using the EASM initiative with pre-built footprint

The pre-built footprint option for the External Attack Surface Management initiative provides high-level insights without a full connection to an MDEASM subscription and doesn't require an active MDEASM subscription.

Prerequisites: To configure your External Attack Surface initiative, you need to have Global Administrator role, or Core security settings (manage) permissions.

  1. Go to the Connect data source to open the settings tab.
  1. Choose Search for your organization's pre-built footprint.

  2. Select the footprint you want to use from the list of available pre-built footprints and choose Connect.

    :::image type="content" source="media/EASM/EASM-Pre-built-footprint.png" alt-text="Screenshot of side panel for EASM pre-built footprint selection" lightbox="media/EASM/EASM-Pre-built-footprint.png":::

  3. In up to 1 hour, the initiative is populated with high-level metrics and scores from the selected footprint.

Using the EASM initiative with full MDEASM integration

Prerequisites

Full integration with MDEASM requires a full MDEASM subscription (trial or paid) and provides comprehensive exposure analysis and asset-level details.

To configure your External Attack Surface initiative, you need to have Global Administrator role or Core security settings (manage) permissions.

To deploy an MDEASM resource, follow these steps:

  1. Log into the Azure portal.
  2. Create a Resource Group with the appropriate subscription and region.
  3. Deploy an MDEASM Resource within that group, see,group; see Create a Defender EASM Azure resource. Each new resource will automatically get a free 30 day trial.

Discover the attack surface

You can discover your attack surface in two ways:

  1. Use the Get Started option to search for your organization and build a preconfigured attack surface.

  2. Or,

    You can alternately create a custom discovery group by providing:

  • Domains
  • IP Blocks or Addresses (use example IPs such as 203.0.113.0 if needed)
  • Hosts
  • ASNs
  • Emails
  • WHOIS organization data

For more information, see Discover your attack surface

  1. Go to the Connect data source to open the settings tab.
  1. Choose Connect your MDEASM workspace.

  2. To enable the initiative to pull data from your Defender EASM resource, enter the values from your resource's Essentials section on the Overview pane found in Azure.

    • Resource Group Name
    • Region

    :::image type="content" source="media/EASM/EASM-full_integration.png" alt-text="Screenshot of side panel for EASM initiative":::

  3. Select Connect. After validation, data will begin flowing into the graph, and metrics will calculate within 32 hours.

You can review your security initiative data through security metrics that reflect various exposure types as assessed by the External Attack Surface assessment engine. Select a metric to view additional information such as the exposed assets and their types.

You can also explore the data integrated from EASM using the attack surface map to uncover insights related to your attack surface. You can search for various assets such as IP addresses, domains, hosts, and more, and review the findings on these assets.

Related content