en|de

Microsoft Defender Threat Intelligence: Retirement on August 1, 2026

On August 1, 2026, Microsoft will retire Microsoft Defender Threat Intelligence (MDTI) as a standalone product. For companies that have licensed and used MDTI separately, this means it is time to realign their threat intelligence strategy.

What is changing

Microsoft is consolidating MDTI capabilities directly into Microsoft Defender and Microsoft Sentinel. Instead of a separate product, there will be a unified threat intelligence experience within the existing security platform.

  • Existing customers: Retain full access to MDTI until the retirement date.
  • After that: The previous MDTI capabilities will only be available with an active Defender or Sentinel license.
  • Consolidation: Threat intelligence data will be available directly in the familiar Defender and Sentinel portals instead of in a separate tool.

Why this is becoming urgent now

If you currently use MDTI as a standalone subscription or have built processes such as SOC workflows, playbooks, or API integrations on top of it, you should check early whether your existing Defender or Sentinel license already covers the capabilities you need – and where integrations will have to be adjusted.

We are happy to clarify whether your current licensing already covers the migration and which steps make sense before August 1, 2026, as part of a Microsoft Security Assessmentget in touch with us.

Leave a comment