We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. External attack surface management
Microsoft Defender External Attack Surface Management, UAE

Your scanner covers the assets you told it about. The breach usually starts on one you forgot.

Defender EASM starts from a handful of known things you own, a domain, an IP block, an ASN, and works outward through Whois, DNS, SSL certificate and ASN relationships until it reaches the edge of what you are responsible for. Microsoft is blunt about the reason: most vulnerability programmes have no visibility outside the firewall, and external risks are the primary source of data breaches.

Book an external attack surface reviewSee how discovery works
Microsoft Defender External Attack Surface Management for UAE organisations
  • Seeds outwardRecursive discovery from what you know
  • Eight asset typesDomains, hosts, pages, certificates, IPs, ASNs
  • Five statesFrom approved inventory to requires investigation
  • ContinuousScheduled rediscovery, not a one-off scan
How it works

Eight things that explain why this finds what your scanner does not.

Microsoft describes Defender EASM as continuously discovering and mapping your digital attack surface to give an external view of your online infrastructure, so security and IT teams can identify unknowns, prioritise risk, eliminate threats, and extend vulnerability and exposure control beyond the firewall. The operative word is unknowns.

It starts from seeds and works outward recursively

Microsoft describes intaking known assets, called seeds, which are then recursively scanned to discover more entities through their connections. The process uses seeds as central nodes and branches outward, identifying everything directly connected, then everything connected to those, repeating until it reaches the edge of your organisation management responsibility.

Six kinds of seed, and one domain is enough to start

An initial seed can be a domain, an IP address block, a host, an email contact, an autonomous system name, or a Whois organisation. In practice a single corporate domain is enough to begin. From there the system consults Whois, DNS, SSL certificate and ASN records to derive an entirely new set of assets to investigate.

SSL certificates are the connection people forget

Among the published relationships is every SSL certificate connected to each of your hosts, and any other hosts that use the same certificates. That is how a forgotten staging environment, a marketing microsite built by an agency, or an acquisition asset nobody documented reappears. Certificates leave a public trail that nothing internal can see.

Five asset states, not a flat list

Approved Inventory for what you own and are responsible for. Dependency for third-party infrastructure that supports your assets, such as a hosting provider IP. Monitor Only for relevant but not controlled assets, the published example being franchisees or related companies. Candidate for a relationship too weak to confirm. Requires Investigation for assets flagged by confidence scoring.

Confidence decays as the search goes deeper, deliberately

Microsoft explains that as third-level and fourth-level connections are discovered, the system confidence in ownership lessens, and it might detect assets relevant to your organisation but not directly owned by you. That honesty is what makes the output usable. A tool that asserted ownership of everything it found would be worse than useless.

Discovery groups, with recurring schedules

Seeds are organised into discovery groups, which let you automate discovery, configure the seed list and set recurrent run schedules. Once inventory is populated, Microsoft describes continuous scanning using virtual user technology to examine the content and behaviour of each page in applicable sites, producing information you can use to identify vulnerabilities and compliance issues.

Pages are an asset type, and that is where compliance findings appear

The published inventory filters cover domains, hosts, pages, contacts, SSL certificates, IP addresses, IP blocks and autonomous system numbers. Pages matter more than the list suggests, because the continuous scanning examines the content and behaviour of each page in applicable sites. That is what surfaces an old framework, an unexpected third-party script, a form collecting personal data on a site nobody owns, or a compliance banner that was never added. A host that merely resolves is a small finding. A page actively collecting information on infrastructure your security team has never seen is a different conversation entirely, and it is the kind of finding that moves an external discovery exercise from an IT project to a board matter.

A prebuilt inventory exists before you configure anything

Microsoft recommends that all users search for their organisation prebuilt attack surface inventory before creating a custom one, based on asset connections it has already identified. That means the first useful output arrives in minutes rather than weeks, and it is usually the moment somebody in the room says they did not know that was still running.

The gap this fills

A vulnerability scanner cannot find what nobody put on the list.

Microsoft states the problem directly, and it describes almost every UAE organisation we assess.

  • Quoted: many vulnerability programmes lack visibility outside the firewall, and are unaware of external risks and threats, which are the primary source of data breaches.
  • Quoted: digital growth continues to outpace an enterprise security team ability to protect it, and digital initiatives plus the overly common shadow IT lead to an expanding attack surface outside the firewall.
  • The practical consequence is that your scanner reports coverage of one hundred percent of the assets in its target list, which is a true statement about the list and says nothing about the estate.
  • External discovery inverts that. It starts from public evidence of what you own rather than from what somebody remembered to register, which is why the first run consistently surfaces assets nobody in the room can immediately explain.
Ask us to run a discovery on your domain
How we approach it

Four things that stop a discovery run becoming another unread report.

The technology does the hard part in the first week. What determines whether it was worth doing is the ownership work, and that is entirely a human exercise.

We start triage where Microsoft says to start it

Requires Investigation first, because those are the assets flagged by confidence scoring as needing a human decision. Working the list alphabetically, or by asset type, produces the same effort with far less yield. The point of five states rather than one list is that they imply an order.

We seed from what you actually own, including acquisitions

Domains, IP blocks, ASNs and Whois organisations. Acquisitions matter disproportionately because they arrive with their own ASNs, their own certificate history and their own name servers, and they are the single most common source of assets nobody at the parent has ever seen.

We separate what you own from what you depend on

The Dependency state exists for a reason. Infrastructure owned by a third party but supporting your assets, such as an IT provider hosting your web content, is a real part of your attack surface and an unreal part of your remediation authority. Confusing the two produces findings nobody can action.

We set the recurrence before we present the first report

Discovery groups support recurrent run schedules, and continuous scanning refreshes asset detail over time. An attack surface that was accurate in March tells you nothing in September. Establishing the schedule and a named reviewer at the start is what makes this a control rather than a project deliverable.

Where this matters most

Six UAE situations where external discovery finds something the same week.

The pattern is consistent: organisations that have grown, acquired, rebranded or outsourced anything have infrastructure their security team has never been told about.

A group that has acquired several businesses

Each acquisition brings its own domains, its own ASN ranges and its own certificate history. Seeding from the acquired entity Whois organisation and ASN pulls that infrastructure into one inventory, frequently including environments the acquired IT team themselves had forgotten, because the people who built them left before the deal.

A business whose marketing runs through agencies

Campaign microsites, landing pages and event registration sites built quickly on somebody else hosting, using a certificate that ties them straight back to you. The certificate relationship is exactly how these surface, and they are consistently the least patched and least monitored things in an estate.

A regulated firm asked to evidence its external footprint

Auditors and regulators increasingly ask what is internet-facing, not merely what is patched. A discovered inventory with ownership states, refreshed on a schedule, is a materially better answer than a spreadsheet maintained by hand, and the trend over time is what shows the control is working.

An operator with sites and remote facilities

Plants, yards and remote offices accumulate their own connectivity, their own remote access and occasionally their own public addressing, arranged locally to solve a real problem. IP block and ASN seeds surface that infrastructure whether or not the central team ever approved it.

An institution with departmental autonomy

Faculties, research groups and student bodies stand up their own sites and services, often on the institution domain, often without central IT involvement. Microsoft names shadow IT explicitly as a driver of the expanding external attack surface, and education estates are where that is most visible.

A business that has rebranded or migrated hosting

Old domains still resolve, old hosts still respond, and the migration project closed before the decommissioning was finished. These are the assets running the oldest software in the estate, and because nobody remembers them, nobody patches them. Discovery finds them because DNS and certificates still remember.

Three positions

How UAE organisations know what they have exposed.

The middle column is where almost every organisation sits. A good scanner, run diligently, against a target list assembled from memory and a spreadsheet.
Known assets assessed
External discovery in placeYes
Scanner against a known listYes
Nothing systematicNo
Unknown assets found
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Acquisition infrastructure surfaced
External discovery in placeYes
Scanner against a known listRarely
Nothing systematicNo
Certificate relationships followed
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Third-party dependencies distinguished
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Ownership states tracked
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Discovery runs on a schedule
External discovery in placeYes
Scanner against a known listNot applicable
Nothing systematicNo
New exposure noticed quickly
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Shadow IT visible
External discovery in placeOften
Scanner against a known listNo
Nothing systematicNo
Attack surface trend measurable
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Feature
External discovery in place
Scanner against a known list
Nothing systematic
Known assets assessed
YesYesNo
Unknown assets found
YesNoNo
Acquisition infrastructure surfaced
YesRarelyNo
Certificate relationships followed
YesNoNo
Third-party dependencies distinguished
YesNoNo
Ownership states tracked
YesNoNo
Discovery runs on a schedule
YesNot applicableNo
New exposure noticed quickly
YesNoNo
Shadow IT visible
OftenNoNo
Attack surface trend measurable
YesNoNo
How assets are found

One domain seed, and everything it leads to.

The relationship set as published for a single domain seed. The right hand column is what each relationship typically surfaces in a UAE estate, which is ours.
Data sourceRelationship derivedWhat it usually surfaces
Whois recordsOther domains registered to the same contact email or registrant organisationCampaign domains and brand defensive registrations nobody tracks
Whois recordsAll domains registered to any address at your domainDomains bought on a personal initiative years ago
Whois recordsOther domains associated with the same name serverSister companies, joint ventures and acquisitions
DNS recordsAll observed hosts on your domains, and websites associated with those hostsStaging, UAT and legacy hosts still resolving
DNS recordsDomains with different hosts that resolve to the same IP blocksShared hosting neighbours and forgotten co-tenanted sites
DNS recordsMail servers associated with your domainsLegacy relays and third-party senders still authorised
SSL certificatesAll certificates connected to each host, and other hosts using the same certificatesAgency-built microsites and expired-project environments
ASN recordsOther IP blocks on the same ASN, plus hosts and domains resolving to themWhole ranges from an acquisition that nobody inventoried
How an engagement runs

Five steps, and the first output arrives in week one.

Typically four to eight weeks to a triaged inventory with owners assigned and a schedule running. The discovery itself is fast. Deciding who owns each asset is what takes the time.
  1. 1

    Deploy and check the prebuilt inventory

    Defender EASM is created as an Azure resource. Microsoft recommends searching for your organisation prebuilt attack surface inventory before building a custom one, based on connections already identified. That first look is quick and frequently produces the finding that gets the rest of the project funded.

  2. 2

    Define the seeds and the discovery groups

    Domains, IP address blocks, hosts, email contacts, autonomous system names and Whois organisations, organised into groups that reflect how the business is actually structured, by brand, region or acquired entity. Recurrent run schedules are configured here rather than added later.

  3. 3

    Triage by state, starting with Requires Investigation

    Then Candidate. Each asset gets an ownership decision: Approved Inventory, Dependency where a third party owns infrastructure supporting your assets, or Monitor Only where it is relevant but not controlled. This is a business conversation and it is the whole value of the exercise.

  4. 4

    Feed the inventory into what you already run

    Newly confirmed assets belong in the vulnerability programme, in the certificate lifecycle, and in whatever asset register the organisation maintains. Discovery that stops at a list changes nothing. Data connections exist for exporting the inventory into the tooling that will act on it.

  5. 5

    Set the rhythm and watch the trend

    Scheduled rediscovery, a named reviewer for newly appearing assets, and a reported trend of surface growth over time. Continuous scanning keeps asset detail fresh, but somebody still has to look at what changed, and that role is assigned before the engagement closes.

Straight answers

What organisations ask about external attack surface management.

A vulnerability scanner assesses the assets you point it at. Defender EASM works out what those assets are in the first place, starting from seeds you know about and following Whois, DNS, SSL certificate and ASN relationships outward. Microsoft frames the gap directly: many vulnerability programmes lack visibility outside the firewall, and external risks are the primary source of data breaches.

Very little. A seed can be a domain, an IP address block, a host, an email contact, an autonomous system name or a Whois organisation, and a single corporate domain is usually enough to begin. Microsoft also recommends first searching for your organisation prebuilt attack surface inventory, which exists before you configure anything.

Through relationships in public records. From one domain it can derive other domains registered to the same contact email or registrant organisation, other domains on the same name server, all observed hosts and associated websites, domains resolving to the same IP blocks, mail servers, every SSL certificate connected to your hosts plus other hosts using the same certificates, and other IP blocks on the same ASN.

It is deliberately careful about that. Microsoft explains that as third and fourth level connections are discovered, confidence in ownership lessens, and that assets may be relevant to your organisation without being owned by you. That is why there are five states rather than one list, and why Candidate and Requires Investigation exist as explicit categories requiring a human decision.

Approved Inventory is part of your owned attack surface and directly your responsibility. Dependency is third-party infrastructure that supports your assets, the published example being an IT provider hosting your web content. Monitor Only is relevant but not controlled, such as franchisees or related companies. Candidate has a relationship too weak to confirm. Requires Investigation is flagged by internal confidence scoring for manual validation.

Microsoft is explicit: start with assets labelled Requires Investigation. Those are the ones the confidence scoring has flagged as needing human validation, which makes them the highest-yield place to spend the first triage hours. Working the whole inventory in order produces the same effort spread over far less useful findings.

Continuous, and that is the point. Seeds live in discovery groups that can be set to run on a recurrent schedule, and once inventory is populated Microsoft describes continuous scanning using virtual user technology to examine the content and behaviour of each page in applicable sites. An attack surface accurate six months ago tells you very little today.

The published filter set covers domains, hosts, pages, contacts, SSL certificates, IP addresses, IP blocks and autonomous system numbers. Pages matter more than people expect, because the scanning examines page content and behaviour, which is what surfaces compliance issues and unexpected technology on sites nobody was watching.

They answer different questions. Exposure Management builds an internal graph across endpoints, identities and cloud, and finds the choke points where many attack paths converge. EASM looks from the outside in and answers what exists at all. External attack surface data is one of the inputs to the wider exposure picture, so they complement rather than duplicate each other.

As an Azure resource, per the published quickstart. That has two practical consequences worth planning for: it sits in an Azure subscription with the governance that implies, and it has a documented concept of billable assets, so the size of the discovered inventory has a commercial dimension as well as a security one.

Yes, through the documented data connections capability. That matters because discovery that ends in its own portal changes nothing. Newly confirmed assets need to reach the vulnerability programme, the certificate lifecycle process and whatever asset register the organisation maintains, or the next scan finds the same unpatched host again.

Decide the default before the first triage session, because there will be several. In our experience the right default is to treat an unclaimed internet-facing asset as a candidate for decommissioning rather than for adoption, on the basis that nobody claiming it also means nobody is patching it. That decision is far easier made in advance than in the moment.

The prebuilt inventory is available immediately, and in most engagements the first genuinely surprising asset appears in the first session. A full triaged inventory with owners assigned and a schedule running takes four to eight weeks, and almost all of that is ownership decisions rather than technical work.

It is one of the few things that does, for internet-facing shadow IT specifically. Microsoft names shadow IT directly as a driver of the expanding attack surface outside the firewall. Because discovery works from public evidence rather than from an internal register, an environment somebody stood up without asking is exactly as visible as one that went through change control.

We scope per organisation, driven by the number of seeds, how many brands or acquired entities are involved, and whether you want the triage run with you or handed over. The Azure resource itself has a consumption dimension tied to billable assets, which we size against your discovered inventory rather than estimating in advance. That sequencing matters: the prebuilt inventory gives a realistic asset count before any commitment is made, so the commercial conversation happens with a real number rather than an estimate that turns out to be half or double what the estate actually contains.

It becomes a new set of seeds rather than a new project. An acquired entity typically brings its own domains, its own Whois registrant organisation, its own name servers and frequently its own autonomous system numbers, each of which is a valid seed type. Adding them to a dedicated discovery group, with its own recurrent schedule, keeps the acquired estate visible as a distinct population while feeding into the same inventory and the same triage process. In practice this is one of the strongest arguments for having external discovery running before the acquisition rather than after it, because the alternative is asking an acquired IT team to document infrastructure that the people who built it have already left.
Making it useful

Fifteen questions that turn a discovery into a decision.

A first run produces a list. The value comes from what happens next, which is a triage and ownership exercise rather than a technical one.

Setting it up

  • Have you checked the prebuilt inventory first?
    Microsoft recommends it before custom work.
  • Which seeds do you actually own?
    Domains, IP blocks, hosts, contacts, ASNs, Whois orgs.
  • Are acquisitions included as seeds?
    They carry their own ASNs and certificates.
  • How are discovery groups organised?
    By brand, region, or business unit.
  • What is the recurrence schedule?
    Discovery is not a one-off exercise.

Triage

  • Who reviews Requires Investigation first?
    Microsoft recommends starting there.
  • Who decides Approved versus Dependency?
    It is an ownership judgement, not technical.
  • Are franchisees or affiliates Monitor Only?
    That is the published use of the state.
  • What happens to a Candidate nobody claims?
    Decide the default in advance.
  • How long should triage take?
    Set a target or it never finishes.

Acting on it

  • Who owns decommissioning an orphaned host?
    Usually nobody, which is the problem.
  • Do findings reach the vulnerability programme?
    Otherwise discovery changes nothing.
  • Are expired certificates tracked?
    They are also a discovery signal.
  • Do new assets trigger a review?
    A new host should raise a question.
  • Who sees the trend over time?
    Growth of the surface is the real metric.
Related reading

The pages around this one.

Security Exposure Management

The internal graph, attack paths and the choke points where many of them converge.

Learn more

Vulnerability assessment

What happens to the assets once you know they exist.

Learn more

Penetration testing

Testing whether the exposure you found is actually exploitable.

Learn more
Next step

Give us one domain and we will show you what is attached to it.

The prebuilt inventory exists before any configuration, so the first look is quick. In every engagement we have run, something appears in that list that nobody in the room can immediately account for.

Book an external attack surface reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Website Security Audit

OWASP Top 10 2025, tested properly and retested

Learn more

Security Exposure Management

Choke points where many attack paths converge

Learn more

Vulnerability Assessment

Continuous vulnerability scanning and remediation

Learn more

Penetration Testing

Black, grey, and white-box penetration testing

Learn more

Defender Vulnerability Management

Certificates, browser extensions and firmware, not just patching

Learn more

VAPT Testing

CREST-certified vulnerability assessment and penetration testing

Learn more

Shadow IT Discovery

Find the SaaS nobody sanctioned, without driving it underground

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy