
M365.FM · 2026-08-08 · 18 min
Microsoft Defender External Attack Surface Management, or Defender EASM, helps organizations understand a critical security question: what can someone outside your company actually see? Your public footprint is much larger than your official website. Forgotten subdomains, old campaign pages, test environments, cloud services, public IP addresses, certificates, and internet-facing servers can remain visible long after the teams that created them have moved on. Defender EASM approaches security from an attacker's perspective and helps discover that external footprint. ㅤ YOU CAN'T PROTECT WHAT YOU CAN'T SEE Traditional security inventories usually start from inside the organization. IT knows about managed laptops, servers, applications, and user accounts. Marketing may maintain its own websites, while cloud teams and suppliers manage additional services. The problem exists between those inventories. Projects end, but test websites remain online. Subdomains are forgotten. IP addresses change. Certificates expire. Suppliers may continue operating public services that internal security teams no longer actively track.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.