Microsoft Defender EASM Implementation — External Attack Surface Monitoring
This $2500, 21-day service (SKU: ITPWW610IMPOT; manager: Roman Sotnik) helps organizations implement Microsoft Defender External Attack Surface Management in Azure so they can discover, map, and monitor external-facing digital assets such as domains, IP blocks, hosts, email contacts, Autonomous System Numbers (ASNs), and WHOIS organizations.
What this engagement is
Microsoft Defender External Attack Surface Management (Defender EASM) provides continuous discovery and monitoring of an organization’s external digital attack surface. It uses Microsoft’s proprietary discovery technology to uncover infrastructure connected to known assets and build an inventory of external-facing properties exposed to the open internet. IT Partner guides the initial setup, Azure resource configuration, seed configuration, initial assessment, monitoring setup, and knowledge transfer so the client can use Defender EASM to understand exposure, prioritize risks, and respond to changes in the external attack surface.
Success criteria
What you receive
How the work unfolds
Verify the client’s Azure subscription and access permissions.
Collect information on known legitimate assets to be used for initial discovery.
Create a new resource group in Azure for Defender EASM.
Configure the Defender EASM resource in the resource group.
Configure the discovery settings and connect initial discovery seeds.
Start the initial discovery process to map the external attack surface.
Establish monitoring rules and alerts for newly discovered assets.
Provide recommendations for further optimization based on initial discovery results.
Prerequisites
Who does what
IT Partner
- Assist in setting up or verifying the existing Azure subscription or Defender EASM trial account.
- Guide the client through understanding the core functionalities and prerequisites for Defender EASM.
- Set up the Defender EASM Azure resource.
- Configure seed and start initial assessment.
- Provide knowledge on how to use the tool effectively, including interpreting reports and responding to alerts.
- Provide guidance to optimize the monitoring process and suggest enhancements based on the client's evolving security needs.
Your team
- Ensure access to the required Azure.
- Provide details of known legitimate assets that can be used as discovery "seeds" for the initial setup.
- Collaborate with IT Partner to define key security priorities and known assets.
What's not included
Frequently asked questions
What is included in the Microsoft Defender External Attack Surface Management service?
This service includes setup of Microsoft Defender External Attack Surface Management in the client’s Azure environment, configuration of discovery seeds, launch of the initial discovery process, monitoring rules and alerts for newly discovered assets, optimization recommendations, and knowledge transfer. The goal is to help the organization discover, map, and monitor external-facing digital assets exposed to the open internet.
How much does the Defender EASM implementation service cost?
The Microsoft Defender External Attack Surface Management implementation service is priced at $2500. The service SKU is ITPWW610IMPOT, and the listed service manager is Roman Sotnik.
How long does the Defender EASM service take?
This is a 21-day service. During that period, IT Partner verifies Azure readiness, configures the Defender EASM resource, connects discovery seeds, starts the initial assessment, establishes monitoring and alerts, and provides knowledge transfer.
What is Microsoft Defender External Attack Surface Management used for?
Microsoft Defender External Attack Surface Management helps organizations continuously discover and monitor their external digital attack surface. It can identify internet-facing assets such as domains, IP blocks, hosts, email contacts, Autonomous System Numbers, and WHOIS organizations so security teams can better understand exposure and prioritize risk mitigation.
What are discovery seeds in Defender EASM?
Discovery seeds are known legitimate assets provided by the client, such as domains or other external identifiers, that Defender EASM uses as starting points for discovery. IT Partner configures these seeds so Microsoft’s discovery technology can uncover connected infrastructure and build an external-facing asset inventory.
What assets can Defender EASM help discover and monitor?
Defender EASM can help discover and monitor external-facing digital assets such as domains, IP blocks, hosts, email contacts, Autonomous System Numbers, and WHOIS organizations. The service focuses on assets exposed to the open internet and connected to known organizational assets.
Do we need an Azure subscription for this service?
Yes, an Azure subscription is required for the Defender EASM setup. If needed, a 30-day free trial of Defender EASM can be used for initial setup and evaluation, subject to Microsoft’s availability and terms.
What are the client prerequisites before the engagement starts?
The client must provide access to the required Azure environment and details of known legitimate assets to use as discovery seeds. The client should also collaborate with IT Partner to define key security priorities and identify known assets that should be included in the initial setup.
What does IT Partner do during the Defender EASM engagement?
IT Partner assists with verifying or setting up the Azure subscription or Defender EASM trial, creates the Azure resource group, configures the Defender EASM resource, connects discovery seeds, and starts the initial assessment. IT Partner also establishes monitoring rules and alerts, provides optimization recommendations, and transfers knowledge on interpreting reports and responding to alerts.
What is the client responsible for during the service?
The client is responsible for ensuring access to the required Azure environment, providing known legitimate assets for discovery seeds, and working with IT Partner to define security priorities. These inputs are important because Defender EASM discovery starts from known assets and expands outward to connected external infrastructure.
Will implementing Defender EASM cause downtime or affect production systems?
The service is focused on configuring Defender EASM in Azure and discovering external-facing assets, so production downtime is not identified as part of the stated scope. Any environment-specific access, monitoring, or alerting considerations should be confirmed with IT Partner before implementation.
What happens during the initial discovery process?
During initial discovery, Defender EASM uses configured seeds to identify infrastructure connected to the organization’s known assets and begins mapping the external attack surface. This helps create an inventory of external-facing properties that can then be monitored for changes and new discoveries.
Does the service include alerting for newly discovered assets?
Yes, the service includes establishing monitoring rules and alerts for newly discovered assets. This helps the security team track changes in the external attack surface and respond when new external-facing properties are identified.
Will IT Partner remediate the risks discovered by Defender EASM?
The stated service includes discovery, configuration, monitoring setup, recommendations, and knowledge transfer, but it does not explicitly include remediation of discovered risks. If hands-on remediation is needed, the scope and any additional services should be confirmed with IT Partner.
Does this service provide a complete external attack surface inventory?
The service starts the Defender EASM discovery process and aims to map the organization’s external attack surface, including domains, IP blocks, and other assets. Because external attack surfaces evolve and discovery depends on available signals and seed quality, ongoing review and separately contracted monitoring services may be important after the initial setup.
What deliverables will we receive at the end of the engagement?
Deliverables include a Defender EASM Azure resource set up in the client’s Azure environment, configured discovery seeds, an initial discovery process started, monitoring rules and alerts for newly discovered assets, optimization recommendations, and knowledge transfer. These deliverables are intended to leave the client with an operational Defender EASM setup and an understanding of how to use it.
What knowledge transfer is included?
IT Partner provides knowledge transfer on using Defender EASM, including how to interpret reports and respond to alerts. The intent is to help the client’s security team effectively use and manage Defender EASM after the engagement.
What happens after the 21-day Defender EASM service is completed?
After completion, the client should have Defender EASM configured and operational in Azure, with initial discovery started and monitoring rules and alerts established. The client’s security team can continue using Defender EASM for ongoing visibility, while any additional optimization, remediation, 24/7 support, continuous monitoring services, or ongoing maintenance beyond the stated engagement should be discussed with IT Partner as optional extra-cost add-ons.
Are Microsoft licensing or Azure consumption costs included in the $2500 service price?
The provided service scope states the implementation service price is $2500, but it does not define whether Microsoft licensing, Defender EASM trial terms, or Azure consumption costs are included. Buyers should confirm licensing, subscription, and any usage-based costs with IT Partner before starting.
What is not included in this Defender EASM implementation service?
The implementation service does not include 24/7 support, continuous monitoring services, ongoing maintenance, ongoing managed monitoring, SOC operations, incident response, continuous investigation, remediation, custom integrations, or extended reporting by default. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons when separately contracted, delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.