As of August 1, 2026, Microsoft Defender Threat Intelligence (MDTI) is no longer available as a standalone product. Microsoft now provides the capabilities at no extra cost through Microsoft Defender or Microsoft Sentinel.
What is changing
Microsoft is consolidating MDTI capabilities directly into Microsoft Defender and Microsoft Sentinel. Instead of a separate product, there will be a unified threat intelligence experience within the existing security platform.
- Standalone license: The separate MDTI SKU has been retired.
- Existing platforms: The capabilities are available at no extra cost to customers with Microsoft Defender or Microsoft Sentinel.
- Migration: Microsoft states that no separate migration step is required; processes, playbooks, and API integrations should still be reviewed.
Why this is becoming urgent now
If you currently use MDTI as a standalone subscription or have built processes such as SOC workflows, playbooks, or API integrations on top of it, you should check early whether your existing Defender or Sentinel license already covers the capabilities you need – and where integrations will have to be adjusted.
Official Microsoft sources
We are happy to clarify whether your current licensing covers the capabilities and which process or integration changes now make sense, as part of a Microsoft Security Assessment – get in touch with us.
Plan the MDTI transition reliably
Assess dependencies, licensing paths, and the transition of your threat intelligence processes.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.
