Microsoft Defender EASM
General

Understand billable assets in Microsoft Defender EASM

In brief

The Microsoft Defender EASM article now more clearly explains host:IP combinations and how billable resolving hosts affect IP and domain counts. Screenshots, metadata, and article naming were also updated.

What Defender admins need to know

Administrators can use the clarified definitions to interpret billable host, IP address, and domain counts consistently.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Understand billable assets in Microsoft Defender External Attack Surface Management

When customers create their first Microsoft Defender External Attack Surface Management (Defender EASM) resource, they're automatically granted a 30-day free trial. Once the trial completes, customers are automatically charged based on their count of billable assets. The charged amount appears on their core Azure billing, with Defender EASM appearing as separate line item on their invoice.

The host:IP combination list is then analyzed to identify duplicate entries and eliminate duplicate hosts. If a host is a subdomain of a parent host that resolves to the same IP address, we exclude the child from the billable host count. For example, if both www.contoso.com and contoso.com resolve to 1.2.3.4, then we exclude www.contoso.com 1.2.3.4 from our Host Count list.

Approved IP addresses

A billable resolving host is any host already counted as a billable host:IP combination. Excluding the IP addresses that resolve to a billable resolving host, allhost are excluded from the billable IP address count. All other active IP addresses in the Approved Inventory state are part of the billable IP address count.

For an IP address to be considered active and therefore billable, it must have one of the following:

Approved domains

A billable resolving host is a hostHosts already counted as a billable host:IP combination. Excluding the domainscombinations are considered billable resolving hosts. Domains associated with athose hosts are excluded from the billable resolving host, alldomain count. All other domains in the Approved Inventory state are part of the billable domain count. If a billable host is registered to the domain in question, the domain isn't included in the billable asset count.

For example: if server1.contoso.com recently resolved to an IP address and is therefore included in your billable asset count, then contoso.com isn't added to thisthe billable domain count.

View billable asset data

  1. From the Defender EASM resource, select Billable assets from the Manage section of the left-hand navigation menu.

    :::image type="content" source="media/billable-1a.png" alt-text="Screenshot of Billable assets dashboard with left-hand Manage section highlighted in navigation pane.":::

  • Screenshot of Billable assets dashboard with left-hand Manage section highlighted in navigation pane.

    1. The chart displays billable asset counts over the past 30 days (if we have 30 days of data). The individual bars are segmented by asset type so users can quickly understand how their billable assets are distributed across their attack surface. Users can view the daily counts for each kind of asset by hovering their mouse over the chart.

      :::image type="content" source="media/billable-2a.png" alt-text="Screenshot of Billable assets chart showing asset counts when hovering over bar.":::

  • Screenshot of Billable assets chart showing asset counts when hovering over bar.

    1. Beneath the chart, users can view their current billable asset counts. These numbers are useful when approximating your monthly spend to best protect your organization’s attack surface.

      :::image type="content" source="media/billable-3.png" alt-text="Screenshot of Billable assets counts beneath dashboard.":::

    Screenshot of Billable assets counts beneath dashboard.

    Related content