Your scanner covers the assets you told it about. The breach usually starts on one you forgot.
Defender EASM starts from a handful of known things you own, a domain, an IP block, an ASN, and works outward through Whois, DNS, SSL certificate and ASN relationships until it reaches the edge of what you are responsible for. Microsoft is blunt about the reason: most vulnerability programmes have no visibility outside the firewall, and external risks are the primary source of data breaches.

- Seeds outwardRecursive discovery from what you know
- Eight asset typesDomains, hosts, pages, certificates, IPs, ASNs
- Five statesFrom approved inventory to requires investigation
- ContinuousScheduled rediscovery, not a one-off scan
Eight things that explain why this finds what your scanner does not.
It starts from seeds and works outward recursively
Microsoft describes intaking known assets, called seeds, which are then recursively scanned to discover more entities through their connections. The process uses seeds as central nodes and branches outward, identifying everything directly connected, then everything connected to those, repeating until it reaches the edge of your organisation management responsibility.
Six kinds of seed, and one domain is enough to start
An initial seed can be a domain, an IP address block, a host, an email contact, an autonomous system name, or a Whois organisation. In practice a single corporate domain is enough to begin. From there the system consults Whois, DNS, SSL certificate and ASN records to derive an entirely new set of assets to investigate.
SSL certificates are the connection people forget
Among the published relationships is every SSL certificate connected to each of your hosts, and any other hosts that use the same certificates. That is how a forgotten staging environment, a marketing microsite built by an agency, or an acquisition asset nobody documented reappears. Certificates leave a public trail that nothing internal can see.
Five asset states, not a flat list
Approved Inventory for what you own and are responsible for. Dependency for third-party infrastructure that supports your assets, such as a hosting provider IP. Monitor Only for relevant but not controlled assets, the published example being franchisees or related companies. Candidate for a relationship too weak to confirm. Requires Investigation for assets flagged by confidence scoring.
Confidence decays as the search goes deeper, deliberately
Microsoft explains that as third-level and fourth-level connections are discovered, the system confidence in ownership lessens, and it might detect assets relevant to your organisation but not directly owned by you. That honesty is what makes the output usable. A tool that asserted ownership of everything it found would be worse than useless.
Discovery groups, with recurring schedules
Seeds are organised into discovery groups, which let you automate discovery, configure the seed list and set recurrent run schedules. Once inventory is populated, Microsoft describes continuous scanning using virtual user technology to examine the content and behaviour of each page in applicable sites, producing information you can use to identify vulnerabilities and compliance issues.
Pages are an asset type, and that is where compliance findings appear
The published inventory filters cover domains, hosts, pages, contacts, SSL certificates, IP addresses, IP blocks and autonomous system numbers. Pages matter more than the list suggests, because the continuous scanning examines the content and behaviour of each page in applicable sites. That is what surfaces an old framework, an unexpected third-party script, a form collecting personal data on a site nobody owns, or a compliance banner that was never added. A host that merely resolves is a small finding. A page actively collecting information on infrastructure your security team has never seen is a different conversation entirely, and it is the kind of finding that moves an external discovery exercise from an IT project to a board matter.
A prebuilt inventory exists before you configure anything
Microsoft recommends that all users search for their organisation prebuilt attack surface inventory before creating a custom one, based on asset connections it has already identified. That means the first useful output arrives in minutes rather than weeks, and it is usually the moment somebody in the room says they did not know that was still running.
A vulnerability scanner cannot find what nobody put on the list.
Microsoft states the problem directly, and it describes almost every UAE organisation we assess.
- Quoted: many vulnerability programmes lack visibility outside the firewall, and are unaware of external risks and threats, which are the primary source of data breaches.
- Quoted: digital growth continues to outpace an enterprise security team ability to protect it, and digital initiatives plus the overly common shadow IT lead to an expanding attack surface outside the firewall.
- The practical consequence is that your scanner reports coverage of one hundred percent of the assets in its target list, which is a true statement about the list and says nothing about the estate.
- External discovery inverts that. It starts from public evidence of what you own rather than from what somebody remembered to register, which is why the first run consistently surfaces assets nobody in the room can immediately explain.
Four things that stop a discovery run becoming another unread report.
We start triage where Microsoft says to start it
Requires Investigation first, because those are the assets flagged by confidence scoring as needing a human decision. Working the list alphabetically, or by asset type, produces the same effort with far less yield. The point of five states rather than one list is that they imply an order.
We seed from what you actually own, including acquisitions
Domains, IP blocks, ASNs and Whois organisations. Acquisitions matter disproportionately because they arrive with their own ASNs, their own certificate history and their own name servers, and they are the single most common source of assets nobody at the parent has ever seen.
We separate what you own from what you depend on
The Dependency state exists for a reason. Infrastructure owned by a third party but supporting your assets, such as an IT provider hosting your web content, is a real part of your attack surface and an unreal part of your remediation authority. Confusing the two produces findings nobody can action.
We set the recurrence before we present the first report
Discovery groups support recurrent run schedules, and continuous scanning refreshes asset detail over time. An attack surface that was accurate in March tells you nothing in September. Establishing the schedule and a named reviewer at the start is what makes this a control rather than a project deliverable.
Six UAE situations where external discovery finds something the same week.
A group that has acquired several businesses
Each acquisition brings its own domains, its own ASN ranges and its own certificate history. Seeding from the acquired entity Whois organisation and ASN pulls that infrastructure into one inventory, frequently including environments the acquired IT team themselves had forgotten, because the people who built them left before the deal.
A business whose marketing runs through agencies
Campaign microsites, landing pages and event registration sites built quickly on somebody else hosting, using a certificate that ties them straight back to you. The certificate relationship is exactly how these surface, and they are consistently the least patched and least monitored things in an estate.
A regulated firm asked to evidence its external footprint
Auditors and regulators increasingly ask what is internet-facing, not merely what is patched. A discovered inventory with ownership states, refreshed on a schedule, is a materially better answer than a spreadsheet maintained by hand, and the trend over time is what shows the control is working.
An operator with sites and remote facilities
Plants, yards and remote offices accumulate their own connectivity, their own remote access and occasionally their own public addressing, arranged locally to solve a real problem. IP block and ASN seeds surface that infrastructure whether or not the central team ever approved it.
An institution with departmental autonomy
Faculties, research groups and student bodies stand up their own sites and services, often on the institution domain, often without central IT involvement. Microsoft names shadow IT explicitly as a driver of the expanding external attack surface, and education estates are where that is most visible.
A business that has rebranded or migrated hosting
Old domains still resolve, old hosts still respond, and the migration project closed before the decommissioning was finished. These are the assets running the oldest software in the estate, and because nobody remembers them, nobody patches them. Discovery finds them because DNS and certificates still remember.
How UAE organisations know what they have exposed.
| Feature | External discovery in place | Scanner against a known list | Nothing systematic |
|---|---|---|---|
Known assets assessed | Yes | Yes | No |
Unknown assets found | Yes | No | No |
Acquisition infrastructure surfaced | Yes | Rarely | No |
Certificate relationships followed | Yes | No | No |
Third-party dependencies distinguished | Yes | No | No |
Ownership states tracked | Yes | No | No |
Discovery runs on a schedule | Yes | Not applicable | No |
New exposure noticed quickly | Yes | No | No |
Shadow IT visible | Often | No | No |
Attack surface trend measurable | Yes | No | No |
One domain seed, and everything it leads to.
| Data source | Relationship derived | What it usually surfaces | |
|---|---|---|---|
| Whois records | Other domains registered to the same contact email or registrant organisation | Campaign domains and brand defensive registrations nobody tracks | |
| Whois records | All domains registered to any address at your domain | Domains bought on a personal initiative years ago | |
| Whois records | Other domains associated with the same name server | Sister companies, joint ventures and acquisitions | |
| DNS records | All observed hosts on your domains, and websites associated with those hosts | Staging, UAT and legacy hosts still resolving | |
| DNS records | Domains with different hosts that resolve to the same IP blocks | Shared hosting neighbours and forgotten co-tenanted sites | |
| DNS records | Mail servers associated with your domains | Legacy relays and third-party senders still authorised | |
| SSL certificates | All certificates connected to each host, and other hosts using the same certificates | Agency-built microsites and expired-project environments | |
| ASN records | Other IP blocks on the same ASN, plus hosts and domains resolving to them | Whole ranges from an acquisition that nobody inventoried |
Five steps, and the first output arrives in week one.
- 1
Deploy and check the prebuilt inventory
Defender EASM is created as an Azure resource. Microsoft recommends searching for your organisation prebuilt attack surface inventory before building a custom one, based on connections already identified. That first look is quick and frequently produces the finding that gets the rest of the project funded.
- 2
Define the seeds and the discovery groups
Domains, IP address blocks, hosts, email contacts, autonomous system names and Whois organisations, organised into groups that reflect how the business is actually structured, by brand, region or acquired entity. Recurrent run schedules are configured here rather than added later.
- 3
Triage by state, starting with Requires Investigation
Then Candidate. Each asset gets an ownership decision: Approved Inventory, Dependency where a third party owns infrastructure supporting your assets, or Monitor Only where it is relevant but not controlled. This is a business conversation and it is the whole value of the exercise.
- 4
Feed the inventory into what you already run
Newly confirmed assets belong in the vulnerability programme, in the certificate lifecycle, and in whatever asset register the organisation maintains. Discovery that stops at a list changes nothing. Data connections exist for exporting the inventory into the tooling that will act on it.
- 5
Set the rhythm and watch the trend
Scheduled rediscovery, a named reviewer for newly appearing assets, and a reported trend of surface growth over time. Continuous scanning keeps asset detail fresh, but somebody still has to look at what changed, and that role is assigned before the engagement closes.
What organisations ask about external attack surface management.
Fifteen questions that turn a discovery into a decision.
Setting it up
- Have you checked the prebuilt inventory first?Microsoft recommends it before custom work.
- Which seeds do you actually own?Domains, IP blocks, hosts, contacts, ASNs, Whois orgs.
- Are acquisitions included as seeds?They carry their own ASNs and certificates.
- How are discovery groups organised?By brand, region, or business unit.
- What is the recurrence schedule?Discovery is not a one-off exercise.
Triage
- Who reviews Requires Investigation first?Microsoft recommends starting there.
- Who decides Approved versus Dependency?It is an ownership judgement, not technical.
- Are franchisees or affiliates Monitor Only?That is the published use of the state.
- What happens to a Candidate nobody claims?Decide the default in advance.
- How long should triage take?Set a target or it never finishes.
Acting on it
- Who owns decommissioning an orphaned host?Usually nobody, which is the problem.
- Do findings reach the vulnerability programme?Otherwise discovery changes nothing.
- Are expired certificates tracked?They are also a discovery signal.
- Do new assets trigger a review?A new host should raise a question.
- Who sees the trend over time?Growth of the surface is the real metric.
The pages around this one.
Give us one domain and we will show you what is attached to it.
The prebuilt inventory exists before any configuration, so the first look is quick. In every engagement we have run, something appears in that list that nobody in the room can immediately account for.
Related Services
Explore more solutions that work great with this service
Website Security Audit
OWASP Top 10 2025, tested properly and retested
Security Exposure Management
Choke points where many attack paths converge
Vulnerability Assessment
Continuous vulnerability scanning and remediation
Penetration Testing
Black, grey, and white-box penetration testing
Defender Vulnerability Management
Certificates, browser extensions and firmware, not just patching
VAPT Testing
CREST-certified vulnerability assessment and penetration testing
Shadow IT Discovery
Find the SaaS nobody sanctioned, without driving it underground
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own