Microsoft Defender EASM
General

Inventory Filters

In brief

The article now links directly to asset-specific filter guidance, uses clearer section titles and anchors, and clarifies the procedure for removing the default Approved state filter. Metadata was also updated.

What Defender admins need to know

Administrators can find relevant filter references and sections more easily when searching Defender EASM inventories; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

To save a query:

  1. First, carefully select the filters to produce the results you want. For more information on the applicable filters for each kind of asset, see Related contentthe asset-specific filter articles such as Domain asset filters, Host asset filters, and IP address asset filters. In this example, you're searching for domains that expire within 30 days that require renewal. Select Search.

    Screenshot of the Inventory page showing where to run a search and access saved queries.

    Screenshot of the Saved queries tab listing existing saved queries with options to open, edit, or delete them.

FilterInventory filter operators reference

Inventory filters can be used with the following operators. Some operators aren't available for every filter. Some operators are hidden if they aren't logically applicable to the specific filter.

| Greater Than or Equal To | Returns results that are greater than or equal to a numerical value. Includes dates. | | Between | Returns results within a numerical range. Includes date ranges. |

Common Defender EASM inventory filters

The following common filters apply to all kinds of assets within an inventory. You can use these filters when you search for a wider range of assets. For filters specific to each kind of asset, see Related contentthe asset-specific filter articles such as ASN asset filters, Domain asset filters, Host asset filters, and IP address asset filters.

Defined Defined-value inventory filters

The following filters provide a dropdown list of options that you can select. The available values are predefined.

| Updated At | Filters by the date that asset data was last updated in inventory. | Date range via calendar dropdown | | | Wildcard | A wildcard DNS record answers DNS requests for subdomains that haven't already been defined. An example is *.contoso.com. | True, False | Equals, Not Equals |

Freeform inventory filters

The following filters require you to manually enter the value you want to use for your search. Many of these values are case sensitive.

Filter for assets outside your approved inventory

Use the following steps toTo remove the default Approved state filter and locate assets in other states, such as Candidate or Requires investigation., complete this procedure:

  1. On the leftmost pane, select Inventory to view your inventory.