Microsoft Defender External Attack Surface Management (Defender EASM) is one of the few EASM platforms with a public list price, which makes it easy to quote and hard to budget. The rate is fixed; the number of assets it applies to is decided by discovery. This guide covers Microsoft Defender EASM pricing as of September 2026: the published rate, exactly what Microsoft counts as a billable asset, worked estimates for three estate sizes, the settings that move the bill, and how it relates to Microsoft Security Exposure Management licensing. We build a competing product (Attack Surface Scan), so the Microsoft facts below are cited to Microsoft's own documentation and price list, and we say plainly where Defender is the better buy.

Defender external attack surface management pricing: the rate

Defender EASM costs $0.011 per billable asset per day in US dollars, billed through your Azure subscription as its own line item. Microsoft's retail price list shows a single meter, "Defender EASM Standard Asset," at $0.011 in every region listed, alongside a "30 Day Trial Asset" meter at $0.00. The rate has been unchanged since the meter took effect in August 2022.

ItemWhat Microsoft publishes
Rate$0.011 per billable asset per day (Azure meter "Defender EASM Standard Asset")
Per month (30 days)$0.33 per billable asset
Per year (365 days)$4.015 per billable asset
Free trial30 days, granted automatically on each new Defender EASM resource
After the trialCharged automatically on your billable asset count, no opt-in step
Minimums, seats, tiersNone published: one meter, no user charges

Two practical notes. Microsoft's old Azure pricing URL for Defender EASM now redirects to a Microsoft Security pricing page that points you to the Azure pricing calculator and sales, rather than printing the number; the Azure Retail Prices API is where the $0.011 figure is published directly. And enterprise agreements can carry negotiated discounts, so treat the list rate as the ceiling, not necessarily what a large Microsoft customer pays.

What counts as a billable asset in Defender EASM

Only assets you (or discovery) place in the Approved Inventory state are billed, and they come in three kinds: approved host:IP combinations, approved IP addresses and approved domains. Candidate, Requires Investigation, Dependency, Monitor Only and archived assets are not charged, and Microsoft removes duplicates before counting.

Asset kindBillable whenNot billable when
Host:IP combinationThe host is Approved and resolved to that IP in the last 30 days. Each distinct IP counts separately.A subdomain resolves to the same IP as its parent host (the child is dropped as a duplicate).
IP addressIt is Approved and "active": an open port or TLS certificate observed in the last 30 days.It already serves a billable host, or shows no recent port or certificate.
DomainIt is Approved and no billable host sits under it.Any host under it is already billed (the domain is then free).

The detail that surprises people is the host:IP rule. A hostname behind a CDN or load balancer that resolved to four different IP addresses in the past month is four billable assets, not one. Microsoft's own example: if www.contoso.com resolved to both 1.2.3.4 and 5.6.7.8, both pairs are counted. Conversely, if www.contoso.com and contoso.com both resolve to 1.2.3.4, only one is billed.

The count is a rolling 30-day view. The Billable assets page in the resource (under Manage) charts daily counts by asset type for the last 30 days, excluding the most recent couple of days that have not finished processing. Trial users see the same dashboard, which is the single most useful thing to do with the trial: read your real count before the first invoice.

Worked cost estimates for small, medium and large estates

At the published rate, every 100 billable assets cost about $33 a month or $401.50 a year. The table below is arithmetic on the list price, not a quote; your count depends on what discovery approves, and a 31-day month costs about 3% more than the 30-day figures shown.

Estate (example)Billable assetsPer dayPer month (30 days)Per year (365 days)
Startup: 2 domains, a marketing site, an app, a mail host3030 × $0.011 = $0.33$0.33 × 30 = $9.90$0.33 × 365 = $120.45
Small business: a few domains, CDN-fronted hosts100100 × $0.011 = $1.10$1.10 × 30 = $33.00$1.10 × 365 = $401.50
Mid-size company: several brands, cloud IPs1,0001,000 × $0.011 = $11.00$11.00 × 30 = $330.00$11.00 × 365 = $4,015
Large enterprise: subsidiaries, acquisitions10,00010,000 × $0.011 = $110.00$110 × 30 = $3,300$110 × 365 = $40,150
Global group50,00050,000 × $0.011 = $550.00$550 × 30 = $16,500$550 × 365 = $200,750

Two things these rows hide. First, the asset count is rarely the number you would guess: a single CDN-fronted hostname can be several host:IP pairs, and recursive discovery on a mature company routinely finds far more than the security team had on its list. Second, the count moves on its own. A new marketing microsite, a migration that changes IPs, or an acquisition added as a seed changes next month's bill without anyone opening a purchase order.

How discovery seeds and approved inventory drive the bill

Discovery seeds decide what Defender EASM finds, and inventory state decides what you pay for; broad seeds plus automatic approval is how a small bill becomes a large one. Seeds are known assets you give the discovery engine as starting points: organization names, domains, IP blocks, hosts, email contacts, ASNs, Whois organizations and certificate common names. Discovery then recurses through observed connections to build your attack surface.

Microsoft's discovery documentation says that when a run finishes, new assets appear in your approved inventory. Assets with a strong enough connection to your seeds are approved and therefore billable straight away; weaker matches land as Candidate or Requires Investigation for manual review and are not billed until someone approves them. Discovery groups default to a weekly recurrence, so the approved set keeps growing as your infrastructure does.

Seeds are not all equal. A domain or IP block seed is tight. A Whois organization, a registrant email contact or an ASN can pull in far more, including assets that belong to a parent company, a franchisee or an employee's personal project registered with a work address (Microsoft's own documentation walks through exactly that last case).

How to keep a Defender EASM bill down

  1. Measure during the trial. Build the attack surface, wait for discovery to settle, then read the Billable assets page before day 30. Multiply by $0.33 for a monthly estimate.
  2. Start with tight seeds. Domains and known IP blocks first; add Whois organization, email contact and ASN seeds deliberately, one discovery group at a time, so you can see what each one adds.
  3. Use exclusions. Discovery groups accept exclusions so related entities you do not own (a sold subsidiary, a shared-hosting neighbour) never enter inventory.
  4. Label state accurately. Third-party infrastructure that supports you but that you do not run belongs in Dependency, and related companies you watch for reporting belong in Monitor Only. Neither is billed. Parking assets you do own outside Approved to save money defeats the purpose of buying the tool, so do this for accuracy, not as a discount.
  5. Prune by chain. If a seed pulled in junk, delete it with seed-based removal, which archives every asset that seed brought in. Discovery-chain and discovery-group removal work the same way further down the tree.
  6. Let dead hosts age out. A host only bills while it has resolved in the last 30 days, so decommissioned infrastructure falls off the count on its own a month after its DNS is gone.

Defender EASM and Microsoft Security Exposure Management licensing

Microsoft Security Exposure Management does not include a Defender EASM subscription; it consumes EASM data, and asset-level EASM data still requires a Defender EASM resource billed at the per-asset rate. Exposure Management itself is licensed through the Defender portal with Microsoft 365 E5 or A5, E3 with the E5 Security or EMS E5 add-on, Microsoft 365 Business Premium, Defender for Business, Defender for Endpoint, Defender for Cloud and several other Defender licenses.

Inside Exposure Management, the External Attack Surface Protection initiative has two modes:

ModeNeeds a Defender EASM subscription?What you get
Pre-built footprintNoHigh-level metrics and scores from a Microsoft-prepared footprint of your organization. No asset-level or detailed exposure information.
Full integrationYes (trial or paid)Asset-level detail, metrics and the attack surface map, pulled from your connected Defender EASM resource. Metrics calculate within 32 hours of connecting.

Separately, the Defender CSPM plan in Defender for Cloud uses EASM data for internet-exposure discovery and attack path analysis of your cloud resources, and Microsoft states that this integration is included in Defender CSPM without a Defender EASM license. That covers your multicloud resources seen from outside; it is not the same as a full EASM inventory of everything your organization owns on the internet.

Is Defender EASM being retired?

No retirement had been announced as of September 24, 2026. Microsoft's Defender EASM documentation was last revised in August 2026, the Azure meter is active, and the product is listed as a first-party data source for Exposure Management. The direction of travel is integration into the Defender portal rather than removal. Microsoft has moved other products from the Azure portal to the Defender portal on published timelines (Microsoft Sentinel is the recent example), so check the Defender EASM documentation and Azure updates before you sign a multi-year commitment.

When Defender EASM is the right buy, and when a flat per-domain monitor is

Defender EASM wins when you need to find assets you do not know you own, at scale, inside a Microsoft security stack; a flat per-domain monitor wins when you already know your domains and want predictable cost and change alerts on them.

Where Defender EASM is genuinely stronger:

  • Attribution at scale. Microsoft's internet-wide dataset (inherited from the RiskIQ acquisition) and recursive discovery from Whois, ASN and contact seeds find shadow IT, forgotten acquisitions and subsidiary infrastructure that a list-driven tool never sees.
  • Microsoft integration. Data flows into Exposure Management, Defender for Cloud CSPM attack paths and Microsoft Sentinel, and billing lands on the Azure invoice you already approve.
  • Very small estates on price alone. At 30 billable assets the list rate is about $9.90 a month, cheaper than our entry plan. The two cross at roughly 75 assets ($25 ÷ $0.33).
  • CVE-style observations. Defender EASM surfaces CVEs mapped to the web components it fingerprints, which Attack Surface Scan does not attempt.

Where a flat per-domain monitor like Attack Surface Scan fits better:

  • Predictable spend. Starter is $25 a month for one domain and 20 hosts, Growth $49 for five domains and 100 hosts per domain, MSP $149 for 25 domains and 250 hosts per domain. Hosts discovered from certificate transparency count against the per-domain allowance, so the invoice does not move when a subdomain appears.
  • Change alerts on the things that break. Certificate transparency read every 15 minutes against an authorized-CA list, served-certificate probes with stalled-renewal detection, SPF, DMARC, MTA-STS, TLS-RPT and CAA change alerts, security headers, exposed ports, lookalike domains and registration expiry, with critical changes alerted immediately and the rest in a weekly digest.
  • No Azure tenant required. Useful for teams on Google Workspace or AWS with no Azure subscription to hang a resource on.
  • Agencies and MSPs. Defender EASM does not support cross-tenant access, including through Azure Lighthouse, so managing clients means signing into each tenant. Our MSP plan has client workspaces, per-client alert routing and white-label reports (more on MSP tooling).

What Attack Surface Scan does not do: it monitors domains you have verified, so it will not attribute unknown assets to your company from a Whois name, and it does not run authenticated CVE scanning or active web application tests. If your problem is "we do not know what we own," start with Defender EASM's trial. If it is "we know what we own and want to hear the moment it drifts," a flat monitor is usually cheaper and quieter. For the wider market, see attack surface management pricing and the best external attack surface monitoring tools.

Frequently asked questions

How much does Microsoft Defender EASM cost?

The list rate is $0.011 (US) per billable asset per day, about $0.33 per asset per month or $4.02 per asset per year, charged on your Azure bill after a 30-day free trial. At that rate 100 billable assets cost about $33 a month, 1,000 about $330 and 10,000 about $3,300.

Is there a Defender EASM pricing calculator?

Microsoft's Defender EASM pricing page points to the Azure pricing calculator for estimates. The quicker method is to multiply your billable asset count by $0.011 per day, and to get that count, read the Billable assets page inside a trial resource, which shows exactly what Microsoft would charge for.

Which resources can be discovered by Microsoft Defender EASM?

Discovery finds domains, IP address blocks, hosts, email contacts, autonomous system numbers (ASNs) and Whois organizations, and indexes web applications, third-party dependencies and other connections it observes on those assets. Of these, only approved hosts (as host:IP pairs), IP addresses and domains are billable.

What is a discovery seed in Defender EASM?

A discovery seed is a known asset you give Defender EASM as a starting point: an organization name, domain, IP block, host, email contact, ASN, Whois organization or certificate common name. Discovery recursively follows connections from seeds to build your inventory. Broader seed types find more and usually raise the bill, because strongly connected results are approved automatically.

Do I need a Microsoft Security Exposure Management license to use Defender EASM?

No. Defender EASM is a standalone Azure resource billed per asset. Exposure Management is licensed separately through Microsoft 365 E5, Business Premium, Defender for Endpoint and similar licenses; it can show a pre-built external footprint without Defender EASM, but asset-level external data requires connecting a Defender EASM resource, which is billed as usual.

Are candidate assets billed in Defender EASM?

No. Microsoft bills only assets in the Approved Inventory state. Candidate, Requires Investigation, Dependency, Monitor Only and archived assets are not charged, and duplicate hosts are removed before counting.

Is Microsoft Defender EASM being retired?

Not as of September 2026. Microsoft has announced no retirement date, its documentation was updated in August 2026, and Defender EASM is listed as a data source for Microsoft Security Exposure Management. Check the product documentation before signing a long commitment in case that changes.

Sources