Microsoft Defender Threat Intelligence: Retirement on August 1, 2026

As of August 1, 2026, Microsoft Defender Threat Intelligence (MDTI) is no longer available as a standalone product. Microsoft now provides the capabilities at no extra cost through Microsoft Defender or Microsoft Sentinel.

What is changing

Microsoft is consolidating MDTI capabilities directly into Microsoft Defender and Microsoft Sentinel. Instead of a separate product, there will be a unified threat intelligence experience within the existing security platform.

  • Standalone license: The separate MDTI SKU has been retired.
  • Existing platforms: The capabilities are available at no extra cost to customers with Microsoft Defender or Microsoft Sentinel.
  • Migration: Microsoft states that no separate migration step is required; processes, playbooks, and API integrations should still be reviewed.

Why this is becoming urgent now

If you currently use MDTI as a standalone subscription or have built processes such as SOC workflows, playbooks, or API integrations on top of it, you should check early whether your existing Defender or Sentinel license already covers the capabilities you need – and where integrations will have to be adjusted.

Official Microsoft sources

We are happy to clarify whether your current licensing covers the capabilities and which process or integration changes now make sense, as part of a Microsoft Security Assessmentget in touch with us.

Recommended Next Step

Plan the MDTI transition reliably

Assess dependencies, licensing paths, and the transition of your threat intelligence processes.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.