Microsoft Defender EASM Implementation — External Attack Surface Monitoring
This service helps organizations implement Microsoft Defender External Attack Surface Management in Azure so they can discover, map, and monitor external-facing digital assets such as domains, IP blocks, hosts, email contacts, Autonomous System Numbers (ASNs), and WHOIS organizations. The service is $2,500 per project, runs 21 days, and is managed by Roman Sotnik.
What this engagement is
Microsoft Defender External Attack Surface Management (Defender EASM) provides continuous discovery and monitoring of an organization’s external digital attack surface. It uses Microsoft’s proprietary discovery technology to uncover infrastructure connected to known assets and build an inventory of external-facing properties exposed to the open internet. IT Partner guides the initial setup, Azure resource configuration, seed configuration, initial assessment, monitoring setup, and knowledge transfer so the client can use Defender EASM to understand exposure, prioritize risks, and respond to changes in the external attack surface.
Success criteria
What you receive
How the work unfolds
Verify the client’s Azure subscription and access permissions.
Collect information on known legitimate assets to be used for initial discovery.
Create a new resource group in Azure for Defender EASM.
Configure the Defender EASM resource in the resource group.
Configure the discovery settings and connect initial discovery seeds.
Start the initial discovery process to map the external attack surface.
Establish monitoring rules and alerts for newly discovered assets.
Provide recommendations for further optimization based on initial discovery results.
Prerequisites
Who does what
IT Partner
- Assist in setting up or verifying the existing Azure subscription or Defender EASM trial account.
- Guide the client through understanding the core functionalities and prerequisites for Defender EASM.
- Set up the Defender EASM Azure resource.
- Configure seed and start initial assessment.
- Provide knowledge on how to use the tool effectively, including interpreting reports and responding to alerts.
- Provide guidance to optimize the monitoring process and suggest enhancements based on the client's evolving security needs.
Your team
- Ensure access to the required Azure subscription and grant the permissions needed to create and manage the Defender EASM resource.
- Provide details of known legitimate assets that can be used as discovery "seeds" for the initial setup.
- Collaborate with IT Partner to define key security priorities and known assets.
What's not included
Frequently asked questions
What is included in the Microsoft Defender External Attack Surface Management service?
This service includes setup of Microsoft Defender External Attack Surface Management in the client’s Azure environment, configuration of discovery seeds, launch of the initial discovery process, monitoring rules and alerts for newly discovered assets, optimization recommendations, and knowledge transfer. The goal is to help the organization discover, map, and monitor external-facing digital assets exposed to the open internet.
How much does the Defender EASM implementation service cost?
The Microsoft Defender External Attack Surface Management implementation service is $2,500 per project, quoted fixed-price in writing before work begins.
How long does the Defender EASM service take?
This is a 21-day service. During that period, IT Partner verifies Azure readiness, configures the Defender EASM resource, connects discovery seeds, starts the initial assessment, establishes monitoring and alerts, and provides knowledge transfer.
What is Microsoft Defender External Attack Surface Management used for?
Microsoft Defender External Attack Surface Management helps organizations continuously discover and monitor their external digital attack surface. It can identify internet-facing assets such as domains, IP blocks, hosts, email contacts, Autonomous System Numbers, and WHOIS organizations so security teams can better understand exposure and prioritize risk mitigation.
What are discovery seeds in Defender EASM?
Discovery seeds are known legitimate assets provided by the client, such as domains or other external identifiers, that Defender EASM uses as starting points for discovery. IT Partner configures these seeds so Microsoft’s discovery technology can uncover connected infrastructure and build an external-facing asset inventory.
Do we need an Azure subscription for this service?
Yes, an Azure subscription is required for the Defender EASM setup. If needed, a 30-day free trial of Defender EASM can be used for initial setup and evaluation, subject to Microsoft’s availability and terms.
What does IT Partner do during the Defender EASM engagement?
IT Partner assists with verifying or setting up the Azure subscription or Defender EASM trial, creates the Azure resource group, configures the Defender EASM resource, connects discovery seeds, and starts the initial assessment. IT Partner also establishes monitoring rules and alerts, provides optimization recommendations, and transfers knowledge on interpreting reports and responding to alerts.
What is the client responsible for during the service?
The client ensures access to the required Azure subscription with the permissions needed to create the Defender EASM resource, provides known legitimate assets for discovery seeds, and works with IT Partner to define security priorities. These inputs matter because Defender EASM discovery starts from known assets and expands outward to connected external infrastructure.
Will IT Partner remediate the risks discovered by Defender EASM?
No — hands-on remediation of discovered exposures, vulnerabilities, misconfigurations, DNS issues, or certificate issues is not included beyond providing recommendations. Remediation work can be scoped separately with IT Partner.
Are Microsoft licensing or Azure consumption costs included in the service price?
No. Defender EASM subscription charges and Azure consumption are billed by Microsoft and are not included in the $2,500 per project implementation price.
What is not included in this Defender EASM implementation service?
The service does not include 24/7 support, continuous monitoring services, ongoing maintenance, SOC operations, incident response, penetration testing, custom SIEM/SOAR or ticketing integrations, large-scale asset ownership validation, or changes to production workloads, DNS, or registrar settings. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons when separately contracted, delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
What happens after the 21-day Defender EASM service is completed?
After completion, the client has Defender EASM configured and operational in Azure, with initial discovery started and monitoring rules and alerts established. The client’s security team continues using Defender EASM for ongoing visibility, while additional optimization, remediation, or ongoing monitoring beyond the engagement can be scoped as optional extra-cost add-ons.