
On 1 August 2026, Microsoft retired the standalone version of Defender Threat Intelligence (MDTI). All threat intelligence capabilities — from threat actor profiles to IoC databases and MITRE ATT&CK mappings — are now included by default in Defender XDR and Microsoft Sentinel. What changes concretely, which licence do you need, and which steps should your IT team take now?
On 1 August 2026, Microsoft took a step that had been announced in the security world for some time but had remained unaddressed by many organisations: the standalone version of Microsoft Defender Threat Intelligence (MDTI) was definitively closed. What was previously a separate, expensive enterprise product has been fully integrated into two platforms that most organisations already use: Microsoft Defender XDR and Microsoft Sentinel.
Microsoft's message is clear: threat intelligence is no longer a luxury add-on — it is a core component of a modern security environment. For IT teams already working with Defender or Sentinel, this means they have access today to capabilities that were out of reach a year ago.
MDTI was a professional threat intelligence platform aimed at security analysts and SOC teams. Its core function was tracking threat actors: organised groups or state-sponsored hackers actively running campaigns. Microsoft built an extensive database of these actors, their methods, and the technical indicators they leave behind, drawing on its own sensors, government partnerships, and the analysis of millions of attacks.
Concrete features included Intel Profiles — detailed dossiers on more than three hundred threat actors with aliases, active campaigns, and victim profiles. The platform also included an Intel Explorer for free-form searches through threat data, Vulnerability Articles linking current vulnerabilities to active exploit campaigns, a database of Indicators of Compromise such as malicious IP addresses, domain names, and file hashes, and extensive MITRE ATT&CK tactics and techniques documented per actor.
The downside was the price tag. MDTI was a separate SKU and therefore only available to organisations willing to pay a significant premium on top of their Microsoft 365 licences. For most medium-sized IT departments, it was simply out of reach.
All MDTI functionality is now integrated into the Microsoft Defender portal and available at no extra cost for customers with an active Microsoft Defender XDR licence or a Microsoft Sentinel licence. The integration is not partial: Intel Profiles, Intel Explorer, Threat Analytics, Vulnerability Articles, and the full IoC database are available in the same interface IT teams use daily for incident management and security alerts.
For existing standalone MDTI customers, Microsoft is actively reaching out via their account manager or partner with migration guidance. The existing licence can be reduced; features remain available through Defender or Sentinel. There is no data loss: historical intelligence, saved searches, and configured integrations carry over.
The threat intelligence sits in the Defender portal under the Threat Intelligence section. Four main functions are available. First, Intel Profiles — detailed profiles of threat actors such as Midnight Blizzard, Lazarus Group, Scattered Spider, and hundreds of other groups. Per actor, you see active campaigns, sector-specific targets, malware in use, and the TTPs that map to MITRE ATT&CK.
Second, Intel Explorer — a search function that lets you look up arbitrary indicators: an IP address you spot in a log, a domain name from a phishing email, a file hash from a quarantine rule. The platform tells you immediately whether that indicator has been linked by Microsoft to a known threat actor or active campaign.
Third, Threat Analytics — a set of up-to-date reports on ongoing threat campaigns worldwide. Per report, you see the impact on your own tenant: how many devices are vulnerable, which Defender alerts are related, which recommended actions are outstanding. Fourth, Vulnerability Articles — context-rich documents on actively exploited vulnerabilities, directly linked to the threat actors deploying them.
For Microsoft Sentinel, a free MDTI connector is available that automatically loads threat indicators into the Sentinel workspace. This enables richer correlation: an alert relating to an IP address that also appears in the MDTI database is automatically enriched with the associated threat context.
In practice, a SOC analyst handling an incident no longer needs to manually look up externally whether an indicator is known. The context is directly available in Sentinel. Detection rules can be extended with threat-intel tables, and MITRE ATT&CK techniques used by an actor can form the basis for new detection use cases.
Note: the connector itself is free, but the data flowing into your Sentinel workspace via the connector counts as data ingestion. Depending on volume, this may affect your Sentinel costs. Microsoft offers a Basic Logs option for threat intelligence tables to keep costs manageable.
The MDTI features are accessible to customers with one of the following licences: Microsoft 365 E5, Microsoft 365 E5 Security add-on, Microsoft Defender XDR standalone, or Microsoft Sentinel. Organisations on Microsoft 365 Business Premium have access to Defender for Business, but the full threat intelligence section requires a Defender XDR licence.
Organisations that hold none of the above licences cannot access the MDTI features. Microsoft has not created a freely accessible or free tier for threat intelligence. The integration makes the product more accessible within the Defender ecosystem, but it remains behind a paid licence barrier.
Three concrete actions for organisations with a Defender XDR or Sentinel licence. First: activate the threat intelligence section in the Defender portal if you have not already done so. Go to security.microsoft.com, navigate to Threat Intelligence, and verify which Intel Profiles are already available. Select the sectors relevant to your organisation so you receive targeted campaign reports.
Second: run a targeted exercise with Intel Explorer. Take the ten most common external IP addresses or domains from your firewall log or email gateway over the past month and look them up in Intel Explorer. This immediately reveals which known threat indicators are already active in your environment without having triggered an alert.
Third: connect threat intelligence to your incident-response process. An incident involving an IP address or domain matched to a known threat actor deserves higher priority than an unknown indicator. Update your prioritisation policy to leverage this context.
The integration of MDTI into Defender XDR and Sentinel is one of the most impactful licensing changes Microsoft has made over the past year. Organisations already investing in the Microsoft security platform now gain threat intelligence that was previously reserved for larger enterprises. Want to know how to configure threat intelligence optimally in your Defender or Sentinel environment? Contact Zarioh for a concrete assessment of your security configuration.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn