Solution

Domain monitoring for MSP customer portfolios

A Microsoft 365 assessment stops at the edge of the tenant. The customer’s domains, subdomains, websites, and certificates sit outside it and are where an opportunistic attacker looks first, because they need no credentials. Domain monitoring registers that footprint as assets and re-checks it on a schedule in the same workspace as the tenant.

What gets checked

Each registered domain and website asset is scanned on its schedule and diffed against the previous run.

DNS and email authentication

DNS, DNSSEC, MX, CAA, plus SPF hardening, graded DMARC, DKIM key inspection, BIMI, MTA-STS, and DANE.

Subdomain discovery

Certificate Transparency logs and DNS probing surface subdomains and forgotten hosts under the domain.

Certificates

Certificate Transparency observations for new or unexpected certificates, and an expiry rollup with lead-time and urgent tiers.

Web and TLS

HTTPS, TLS configuration, HSTS, CSP, security headers, cookies, and technology fingerprints for registered websites.

Exposed services and web-app exposure

Connect-only checks for services that should not face the internet, exposed source-control or environment files, directory listing, and reachable staging.

Severity-ranked findings

Every issue lands in the customer’s findings queue in the same severity language as tenant findings.

Why it belongs in the customer workspace

One queue, not a separate tool

External findings and Microsoft 365 findings share a severity scale and a workspace, so a technician is not switching between an attack-surface tool and a posture tool and reconciling two mental models.

Change becomes an alert

A certificate approaching expiry, a new open port, or a subdomain that appeared this week generates a monitoring notification through the same alert policies as tenant changes.

Covered in the customer report

When a customer asks whether they are secure, the answer covers the website and the certificates as much as the identity configuration, and the report reflects that.

Finding assets the customer forgot

Discovery runs continuously

MSPs inherit a customer’s external footprint at onboarding without an inventory. Passive discovery from Certificate Transparency and DNS surfaces hosts nobody listed, and a host that appears between reviews usually means an undocumented change worth a look.

Discovered is not the same as monitored

Discovered hosts are shown for review and do not count against quotas or scores. You promote the ones that matter to monitored assets; the rest stay visible as context.

Domain asset workflow

Register the domain
Add it as an asset in the customer workspace.
Set the schedule
Configure scan frequency and notification policy for the asset.
Review discovery and findings
Triage new findings and promote discovered hosts worth monitoring.
Include in the report
External posture appears in the customer report alongside the tenant.
Daily monitoring · last scan

Related pages

Frequently asked questions

Next steps

Monitor the customer footprint outside the tenant