Broken management of Defender EASM via Azure Lighthouse

Sascha Reuter 30 Reputation points
2025-04-08T11:05:56.09+00:00

We try to manage Defender EASM from a customer using Azure Lighthoure.

We have Contributor Rights to the Customer Subscription using Azure Lighthouse ARM Template.

Everything in the Customer Subscription can be managed fine, but management of Defender EASM is totally broken when being managed via Azure Lighthouse.

Sometimes we get the message that we do not have access to the ressource.
Then we click on our own Defender EASM Instance in our management resource group and then click back again on Defender EASM in the customer Defender EASM and then it works! Totally strange.
However in the defender EASM overview and also other menus we see strangest errors (empty field, 0 assets, "Malformed Query" when visiting the EASM Inventory.

This problem is not tied to a particular customer tenant, but is fully reproducable also with other customer tenants. We get the impression that Defender EASM is somehow incompatible with Azure Lighthouse.

Any hints on what to do?

Azure Lighthouse
Azure Lighthouse
An Azure service that provides secure managed services and access control for partners and customers.
89 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.