We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. External attack surface management
Microsoft Defender External Attack Surface Management

A scanner only covers what somebody typed into it. Breaches tend to begin on the host nobody typed in.

Give it a few things you definitely own, a domain, an address block, an autonomous system number, and it works outward through registration records, DNS, certificates and network relationships until it reaches the boundary of what you are actually answerable for. Microsoft states the reasoning bluntly: most vulnerability programs cannot see past the firewall, and what sits outside it is where breaches predominantly start.

Book an external attack surface reviewSee how discovery works
Microsoft Defender External Attack Surface Management for US organizations
  • Seeds outwardRecursive discovery from what you know
  • Eight asset typesDomains, hosts, pages, certificates, IPs, ASNs
  • Five statesFrom approved inventory to requires investigation
  • ContinuousScheduled rediscovery, not a one-off scan
How it works

Eight reasons this turns up things your scanner never will.

The product continuously discovers and maps your digital attack surface, giving an outside-in view of your infrastructure so that security and IT teams can identify unknowns, rank the risk, remove the threats, and push vulnerability control past the firewall. The word carrying the weight in that sentence is unknowns.

It starts from seeds and works outward recursively

You supply known assets, called seeds, and each one gets scanned recursively to find further entities through whatever it connects to. Seeds sit as central nodes and the search branches outward, picking up everything directly attached, then everything attached to those, repeating until it reaches the edge of what your organization is responsible for managing.

There are six kinds of seed, and one domain will do

A seed can be a domain, an address block, a host, an email contact, an autonomous system name, or a registrant organization. In practice one corporate domain gets you started. From there it reads registration records, DNS, certificates and network data to derive an entirely fresh set of assets worth investigating.

SSL certificates are the connection people forget

One of the documented relationships is every certificate attached to each of your hosts, plus any other host presenting the same certificate. That single link is how a forgotten staging environment resurfaces, or a microsite an agency built for a campaign in 2022, or infrastructure that arrived with an acquisition and was never documented. Certificates leave a public trail no internal tool can follow.

Five asset states, not a flat list

Approved Inventory covers what you own and answer for. Dependency covers infrastructure a third party owns that your assets rely on, a hosting provider address being the obvious case. Monitor Only covers what is genuinely relevant but outside your control, with franchisees and related companies given as the example. Candidate covers a relationship too thin to confirm. Requires Investigation covers whatever the confidence scoring has flagged for a person to decide.

Confidence decays as the search goes deeper, deliberately

As the search reaches third and fourth level connections its confidence in ownership drops, and it may well surface assets relevant to you without being yours. That candor is precisely what makes the output workable. A product that confidently asserted ownership of everything it found would be actively dangerous.

Discovery groups, with recurring schedules

Seeds live inside discovery groups, which is where you automate the search, maintain the seed list, and set it to run on a schedule. Once the inventory exists, continuous scanning uses virtual user technology to examine the content and behavior of each page on applicable sites, which is what produces findings on both vulnerabilities and compliance.

Pages count as assets, and that is where the compliance findings surface

The documented filters run across domains, hosts, pages, contacts, certificates, addresses, address blocks and autonomous system numbers. Pages deserve more attention than their position in that list suggests, because the scanning examines what each page contains and how it behaves. That is what turns up an abandoned framework, a third-party script nobody approved, or a form quietly collecting personal information on a site with no owner, which under CCPA and CPRA and the other state statutes is a legal problem before it is a technical one. A host that merely answers is a modest finding. A page actively gathering personal data on infrastructure your security team has never heard of is an entirely different conversation.

A prebuilt inventory exists before you configure anything

Before configuring anything, you are advised to look for the prebuilt inventory that already exists for your organization, assembled from connections the system has previously identified. That means the first useful output lands in minutes rather than weeks, and it is reliably the moment somebody in the room says they had no idea that was still up.

The gap this fills

No scanner has ever found an asset nobody entered into it.

The problem is documented plainly, and it describes nearly every American company we assess.

  • The documented position: a great many vulnerability programs cannot see outside the firewall at all, leaving them unaware of external risks and threats, which are the primary source of data breaches.
  • And alongside it: digital growth keeps outrunning what a security team can realistically protect, with new initiatives and the entirely commonplace shadow IT together expanding the attack surface beyond the firewall.
  • What that means in practice is a scanner reporting full coverage of every asset in its target list. That statement is entirely true about the list and tells you nothing whatsoever about the estate.
  • External discovery works the other way round. It begins with public evidence of what you own rather than with whatever somebody remembered to add, which is why a first run reliably produces assets nobody present can immediately account for.
Ask us to run a discovery on your domain
How we approach it

Four things that stop this becoming another report nobody opens.

The technology finishes the difficult part inside a week. Whether the engagement was worth anything comes down to the ownership work afterwards, and that is entirely human.

We start triage where Microsoft says to start it

Start with Requires Investigation, because the confidence scoring has already flagged those as needing somebody to decide. Working alphabetically, or by asset type, costs exactly the same hours and returns far less. Five states rather than one list exist precisely because they imply a running order.

We seed from what you actually own, including acquisitions

Domains, address blocks, autonomous system numbers, and registrant organizations. Acquisitions matter out of all proportion here, because each one arrives with its own network ranges, its own certificate history, and its own name servers. They are by some distance the most common source of assets nobody at the parent company has ever laid eyes on.

We draw the line between what you own and what you merely rely on

The Dependency state exists for a reason worth understanding. Infrastructure somebody else owns while your assets depend on it, a provider hosting your web content being the classic case, is genuinely part of your attack surface and entirely outside your authority to fix. Blurring those two produces findings nobody has the power to act on.

The schedule gets set before the first report is ever presented

Discovery groups run on a recurring schedule and continuous scanning keeps the asset detail current. An attack surface that was accurate in March describes nothing by September. Fixing the schedule and naming a reviewer at the outset is exactly what turns this into a control rather than a one-off deliverable.

Where this matters most

Six US situations where external discovery finds something the same week.

The pattern never varies. Any company that has grown, bought something, rebranded, or outsourced a function is running infrastructure its own security team was never told about.

A group that has acquired several businesses

Every acquisition arrives with its own domains, its own network ranges, and its own certificate history. Seeding from the acquired company registrant organization and network numbers pulls all of that into a single inventory, and it regularly surfaces environments the acquired IT team had themselves forgotten, because whoever built them left before the deal closed. For a private equity roll-up this is simply routine.

A business whose marketing runs through agencies

Campaign microsites, landing pages, and event registration forms thrown up quickly on somebody else hosting, carrying a certificate that points straight back at you. That certificate link is precisely how they surface, and without exception they are the least patched and least monitored things in the estate.

A regulated firm asked to evidence its external footprint

SOC 2 auditors, cyber carriers, and enterprise customers now ask what you have facing the internet, not simply what you have patched. A discovered inventory with ownership states, refreshed on a schedule, is a considerably better answer than a hand-maintained spreadsheet, and the trend across quarters is what demonstrates the control is actually working.

An operator with plants and remote facilities

Plants, yards, and remote sites accumulate their own connectivity, their own remote access, and occasionally their own public addressing, all arranged locally to solve a genuine problem that day. Address block and network seeds surface that infrastructure regardless of whether head office ever approved it.

An institution with departmental autonomy

Departments, research groups, and student organizations stand up their own sites and services, frequently on the institution own domain and frequently without central IT hearing about it. Shadow IT is named explicitly as a driver of the expanding external attack surface, and nowhere is that more visible than a university estate.

A business that has rebranded or migrated hosting

Old domains keep resolving, old hosts keep answering, and the migration project was signed off long before the decommissioning was actually finished. These carry the oldest software anywhere in the estate, and because nobody remembers them, nobody has patched them in years. Discovery finds them because DNS and certificates have a longer memory than people do.

Three positions

How US organizations know what they have exposed.

Nearly every company sits in the middle column: a capable scanner, run conscientiously, against a target list assembled from memory and a spreadsheet somebody inherited.
Known assets assessed
External discovery in placeYes
Scanner against a known listYes
Nothing systematicNo
Unknown assets found
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Acquisition infrastructure surfaced
External discovery in placeYes
Scanner against a known listRarely
Nothing systematicNo
Certificate relationships followed
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Third-party dependencies distinguished
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Ownership states tracked
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Discovery runs on a schedule
External discovery in placeYes
Scanner against a known listNot applicable
Nothing systematicNo
New exposure noticed quickly
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Shadow IT visible
External discovery in placeOften
Scanner against a known listNo
Nothing systematicNo
Attack surface trend measurable
External discovery in placeYes
Scanner against a known listNo
Nothing systematicNo
Feature
External discovery in place
Scanner against a known list
Nothing systematic
Known assets assessed
YesYesNo
Unknown assets found
YesNoNo
Acquisition infrastructure surfaced
YesRarelyNo
Certificate relationships followed
YesNoNo
Third-party dependencies distinguished
YesNoNo
Ownership states tracked
YesNoNo
Discovery runs on a schedule
YesNot applicableNo
New exposure noticed quickly
YesNoNo
Shadow IT visible
OftenNoNo
Attack surface trend measurable
YesNoNo
How assets are found

One domain seed, and everything it leads to.

This is the documented relationship set from a single domain seed. The right hand column describes what each one typically drags up in the estates we work in.

Data source

Whois records

Relationship derived
Further domains registered against the same contact address or registrant organization
What it usually surfaces
Campaign domains and brand defensive registrations nobody tracks

Data source

Whois records

Relationship derived
All domains registered to any address at your domain
What it usually surfaces
Domains bought on a personal initiative years ago

Data source

Whois records

Relationship derived
Other domains associated with the same name server
What it usually surfaces
Sister companies, joint ventures and acquisitions

Data source

DNS records

Relationship derived
Every host observed on your domains, plus the websites sitting on those hosts
What it usually surfaces
Staging, UAT and legacy hosts still resolving

Data source

DNS records

Relationship derived
Domains running on different hosts that nonetheless resolve into the same address blocks
What it usually surfaces
Shared hosting neighbors and forgotten co-tenanted sites

Data source

DNS records

Relationship derived
Mail servers associated with your domains
What it usually surfaces
Legacy relays and third-party senders still authorized

Data source

SSL certificates

Relationship derived
Every certificate attached to each host, and any other host presenting the same one
What it usually surfaces
Agency-built microsites and expired-project environments

Data source

ASN records

Relationship derived
Further address blocks under the same autonomous system, with everything resolving into them
What it usually surfaces
Whole ranges from an acquisition that nobody inventoried
Data sourceRelationship derivedWhat it usually surfaces
Whois recordsFurther domains registered against the same contact address or registrant organizationCampaign domains and brand defensive registrations nobody tracks
Whois recordsAll domains registered to any address at your domainDomains bought on a personal initiative years ago
Whois recordsOther domains associated with the same name serverSister companies, joint ventures and acquisitions
DNS recordsEvery host observed on your domains, plus the websites sitting on those hostsStaging, UAT and legacy hosts still resolving
DNS recordsDomains running on different hosts that nonetheless resolve into the same address blocksShared hosting neighbors and forgotten co-tenanted sites
DNS recordsMail servers associated with your domainsLegacy relays and third-party senders still authorized
SSL certificatesEvery certificate attached to each host, and any other host presenting the same oneAgency-built microsites and expired-project environments
ASN recordsFurther address blocks under the same autonomous system, with everything resolving into themWhole ranges from an acquisition that nobody inventoried
How an engagement runs

Five steps, with something useful in your hands during the first week.

Four to eight weeks to a triaged inventory with owners assigned and a schedule running. The discovery is quick. Working out who owns each asset is what consumes the calendar.
  1. 1

    Deploy and check the prebuilt inventory

    The service is created as an Azure resource. Before building anything custom, look for the prebuilt inventory that already exists for your organization, assembled from connections previously identified. That first look takes very little time and frequently produces the single finding that gets the rest of the project funded.

  2. 2

    Define the seeds and the discovery groups

    Domains, address blocks, hosts, email contacts, autonomous system names, and registrant organizations, arranged into groups that mirror how the business is genuinely structured, whether by brand, by region, or by acquired company. The recurring schedule gets configured at this point rather than added as an afterthought.

  3. 3

    Triage by state, starting with Requires Investigation

    Then the Candidate list. Every asset receives an ownership decision: Approved Inventory, Dependency where a third party owns something your assets rely on, or Monitor Only where it matters without being yours to control. This is a business conversation rather than a technical one, and it is where all the value of the exercise actually sits.

  4. 4

    Feed the inventory into what you already run

    Anything newly confirmed has to reach the vulnerability program, the certificate lifecycle process, and whatever asset register your company keeps. Discovery that ends at a list changes precisely nothing. Data connections exist to push the inventory into the tools that will actually do something with it.

  5. 5

    Set the rhythm and watch the trend

    Rediscovery on a schedule, a named person responsible for reviewing anything new that appears, and a reported trend showing how the surface is growing. Continuous scanning keeps the detail current, but a human still has to read what changed, and that role is assigned before we close the engagement.

Straight answers

What organizations ask about external attack surface management.

A scanner assesses whatever you aim it at. This works out what there is to aim at in the first place, beginning from seeds you already know and following registration, DNS, certificate, and network relationships outward. The gap is stated directly in the documentation: many vulnerability programs cannot see beyond the firewall, and external risk is the primary source of breaches.

Almost nothing. A seed is a domain, an address block, a host, an email contact, an autonomous system name, or a registrant organization, and one corporate domain is normally enough to get moving. On top of that, a prebuilt inventory for your organization already exists before you configure a single thing, and looking at it is the recommended first move.

Through relationships sitting in public records. From one domain it derives other domains registered to the same contact address or registrant organization, other domains sharing a name server, every observed host and the websites on them, domains resolving into the same address blocks, mail servers, every certificate attached to your hosts along with any other host presenting the same certificate, and further address blocks under the same autonomous system.

It is deliberately cautious. As the search reaches third and fourth level connections its confidence in ownership falls, and assets can be relevant to you without belonging to you. That is exactly why five states exist instead of one list, and why Candidate and Requires Investigation are separate categories that demand a person makes the call.

Approved Inventory is yours, part of your surface and squarely your responsibility. Dependency is infrastructure a third party owns while your assets rely on it, with a provider hosting your web content given as the example. Monitor Only is relevant but outside your control, such as a franchisee or a related company. Candidate has a relationship too thin to confirm either way. Requires Investigation has been flagged by the confidence scoring for somebody to validate manually.

The guidance is explicit: begin with whatever is labeled Requires Investigation. Those are the assets the confidence scoring has already singled out as needing human judgment, which makes them the highest-yield place to spend your opening triage hours. Working straight through the whole inventory in order costs identical effort spread across far less useful ground.

Continuously, and that is rather the point. Seeds sit inside discovery groups that can be scheduled to run repeatedly, and once the inventory exists, continuous scanning uses virtual user technology to examine the content and behavior of every page on applicable sites. An attack surface that was accurate six months ago tells you close to nothing today.

The documented filters run across domains, hosts, pages, contacts, certificates, addresses, address blocks, and autonomous system numbers. Pages matter far more than anyone expects, because the scanning reads page content and behavior, and that is what exposes compliance problems and unexpected technology on sites nobody was watching, including forms gathering personal information that carries obligations under CCPA, CPRA, and the other state privacy statutes.

It answers an entirely different question from the workload products. Defender for Endpoint, Identity, and Office 365 protect assets you already know about, working from the inside. This looks in from the outside and answers what exists at all. The external surface data feeds the wider exposure picture in the Defender portal, so the two complement rather than duplicate each other, and anything newly confirmed usually goes straight into the vulnerability program.

It is created as an Azure resource, per the published quickstart, which carries two practical consequences worth planning around. It lives inside an Azure subscription with all the governance that implies, and it has a documented notion of billable assets, meaning the size of whatever you discover has a commercial dimension alongside the security one.

Yes, through the documented data connections capability, and it matters more than it sounds. Discovery that terminates inside its own portal changes nothing at all. Newly confirmed assets have to arrive in the vulnerability program, in the certificate lifecycle process, and in whatever asset register you keep, or next quarter scan simply finds the same unpatched host waiting.

Decide the default position before the first triage session, because there will be more than one of these. In our experience the right default is to treat an unclaimed internet-facing asset as a candidate for switching off rather than for adopting, on the straightforward logic that nobody claiming it also means nobody patching it. Commercially, scoping depends on the number of seeds, how many brands or acquired companies are in play, and whether you want the triage run alongside you or handed over when it is done. The Azure resource carries a consumption element tied to billable assets, which we size against your real discovered inventory rather than guessing beforehand. The prebuilt inventory gives an honest asset count before anybody commits to anything, so the commercial conversation happens with a genuine number on the table.
Making it useful

Fifteen questions that turn a discovery into a decision.

The first run gives you a list and nothing more. Everything of value happens afterwards, and it is an exercise in triage and ownership rather than a technical one.

Setting it up

  • Have you checked the prebuilt inventory first?
    Microsoft recommends it before custom work.
  • Which seeds do you actually own?
    Domains, IP blocks, hosts, contacts, ASNs, Whois orgs.
  • Are acquisitions included as seeds?
    They carry their own ASNs and certificates.
  • How are discovery groups organized?
    By brand, region, or business unit.
  • What is the recurrence schedule?
    Discovery is not a one-off exercise.

Triage

  • Who reviews Requires Investigation first?
    Microsoft recommends starting there.
  • Who decides Approved versus Dependency?
    It is an ownership judgment, not technical.
  • Are franchisees or affiliates Monitor Only?
    That is the published use of the state.
  • What happens to a Candidate nobody claims?
    Decide the default in advance.
  • How long should triage take?
    Set a target or it never finishes.

Acting on it

  • Who owns decommissioning an orphaned host?
    Usually nobody, which is the problem.
  • Do findings reach the vulnerability program?
    Otherwise discovery changes nothing.
  • Are expired certificates tracked?
    They are also a discovery signal.
  • Do new assets trigger a review?
    A new host should raise a question.
  • Who sees the trend over time?
    Growth of the surface is the real metric.
Related reading

The pages around this one.

Defender Vulnerability Management

What happens to the assets once you know they exist: continuous assessment, inventories and prioritized remediation.

Learn more

Microsoft Defender XDR

The correlation layer the wider exposure picture feeds into, across endpoint, identity, email and cloud.

Learn more

Cybersecurity audit and compliance

Independent testing of whether the exposure you found is actually exploitable, and the evidence pack behind it.

Learn more
Next step

Send one domain and we will show you everything hanging off it.

Because the prebuilt inventory exists before anything is configured, that first look takes very little time. In every engagement we have run, something has appeared in that list which nobody in the room could immediately explain.

Book an external attack surface reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender Vulnerability Management Services

Defender Vulnerability Management deployment for US organizations:

Learn more

Microsoft Defender XDR Services

One incident queue across endpoint, email and identity

Learn more

Microsoft Security Services

The Microsoft security stack deployed and managed end to end

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA