Skip to the main content.
HomeSecurity › Defender Threat Intelligence
Retired August 1, 2026

Defender Threat Intelligence ended. The intelligence did not.

Microsoft retired the standalone Defender Threat Intelligence product on August 1, 2026. The capabilities it used to sit behind did not go away. They moved into the Microsoft Defender portal, where Microsoft says they are available at no extra cost to customers with Microsoft Defender or Microsoft Sentinel. How much of it you actually see depends on which of those products you hold, and most teams have not opened any of it.

  • Threat actor profiles, indicator search, and entity enrichment, inside the portal your analysts already use
  • No migration to run. Microsoft states the features are already available
  • If a Defender Threat Intelligence line item is still on your bill, that is worth a look
What changed on August 1
Ended
Defender Threat Intelligence standalone
The separate product retired. Microsoft states all subscriptions end.
Now in the Defender portal
The same intelligence, in the workflow
  • Intel profiles on tracked actors and their tools
  • Intel explorer for indicators of compromise
  • Threat Intelligence Insights on entity pages (Preview)
  • Threat analytics reports scoped to your environment
Microsoft Partner Center, July 23, 2026, and Microsoft Learn
Aug 1, 2026
Defender Threat Intelligence standalone reaches end of life
Microsoft Partner Center, July 23, 2026
No extra cost
What Microsoft says the capabilities now cost customers with Defender or Sentinel, with what you see scoped to the products you hold
Microsoft Partner Center, July 23, 2026
Zero
Migration steps Microsoft says customers need to take
Microsoft Partner Center, July 23, 2026
4
Entity types enriched with threat intelligence: IP addresses, domains, URLs, files
Microsoft Learn, Microsoft Defender XDR

Microsoft retired the product, not the capability

This is the unusual kind of retirement. Normally a product ends and you go shopping. Here the product ended and the thing it did moved somewhere you already have a licence for.

Microsoft, verbatim
"Microsoft is retiring the MDTI standalone SKU. All MDTI capabilities are now available at no extra cost through the Microsoft Defender portal to any customer with Microsoft Defender or Microsoft Sentinel."
Microsoft Partner Center announcement, MDTI reaches end of life August 1, 2026, dated July 23, 2026. The same announcement goes on to say that customers do not need to take migration action, because the features are already available to them.

Defender Threat Intelligence was a paid add-on. Organizations that wanted Microsoft's threat research as a working tool, rather than as occasional blog posts, licensed it separately. It carried its own portal, its own login, and its own line on the invoice. Plenty of security teams looked at it, agreed it was good, and did not buy it, because the value was hard to defend against a renewal that already felt expensive.

On August 1, 2026 that product ended. Microsoft's own product documentation puts it plainly: the legacy standalone threat intelligence portal and the Intel Explorer experience were retired on that date, and the capabilities are now in the Microsoft Defender portal. Two Microsoft surfaces, the partner channel announcement and the Defender XDR documentation, give the same date.

So there are two readers of this page, and they need different things.

The first reader was paying for it. That subscription has ended. Microsoft's key dates are specific: the product left the price list preview on August 1, 2025, and deprecation took effect on August 1, 2026, when all subscriptions end. If a Defender Threat Intelligence charge is still appearing on your bill, that is a billing question worth raising with whoever handles your Microsoft licensing. It is a small line item for most organizations. It is also the kind of thing that quietly renews for years because nobody owns the invoice line by line.

The second reader never bought it, and is the reason this page exists. If your organization has Microsoft Defender or Microsoft Sentinel, Microsoft's position is that the capability is now available to you without an additional purchase. You did not get a migration email, because there was nothing for you to migrate. You got a capability, silently, in a portal you already sign into. That is the most common way for something valuable to go unused.

Four things your analysts can use this week

These are Microsoft's descriptions of what now sits in the Defender portal, not a vendor summary of them. Where Microsoft labels something Preview, so do we.

Intel profiles

Microsoft describes these as curated content organized by threat actors, the tools they use, and known vulnerabilities. When an alert or an industry warning names an actor, this is where you find out what that actor actually does, rather than piecing it together from news coverage.

Who uses it: whoever writes the incident summary that goes to your board or your examiner. Attribution stated with a source behind it reads very differently from attribution stated as a guess.

Intel explorer

Search and investigate threat intelligence artifacts, indicators of compromise, and the analyses connected to them. This is the answer to the question an analyst asks twenty times a week: I am looking at this address, this domain, this file, has anyone seen it before and in what context.

Who uses it: the person triaging the queue. It shortens the gap between an alert firing and somebody deciding whether it matters.

Preview

Threat Intelligence Insights on entity pages

Entity pages for IP addresses, domains, URLs, and files carry a Threat Intelligence Insights tab. Microsoft describes it as surfacing reputation data, attributed threat reports, sandbox analysis results, and infrastructure relationship data directly on the entity page, so the investigation happens without switching tools.

Read the label. Microsoft marks this experience as Preview. Preview features can change before general release, so treat it as genuinely useful today and not yet as something to write a control procedure around.

Threat analytics

Microsoft calls this the in-product threat intelligence solution from its security researchers. Each report analyses a tracked threat, gives defensive guidance, and, the part that matters most, includes data from your own network indicating whether that threat is active in your environment.

Why that last clause is the whole point: a threat report about the wider world is reading. A threat report that tells you whether it is in your building is work.

Microsoft 365 Defender portal threat intelligence map showing Intel profiles, Intel explorer, Threat Intelligence Insights on entity pages, and Threat analytics, with Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID and Microsoft Purview product callouts
Where the retired product's capabilities now sit inside the Microsoft Defender portal.

Do you know whether anyone has opened it?

Most institutions cannot answer that, because nobody was told there was anything to open. A free security assessment from ABT includes checking what your Microsoft Defender and Microsoft Sentinel licensing actually entitles you to, what is switched on, and what is sitting there unused. In writing, no commitment.

Does free threat intelligence actually help a bank?

Yes, in three specific ways, and no in one important way. A page that only gave you the first half would not be worth reading.

It shortens triage. A credit union with two people covering security is not short of alerts. It is short of context. The difference between an address that belongs to a hosting provider and one that belongs to infrastructure a tracked actor has used before is the difference between closing a ticket in four minutes and escalating it. That context used to require a separate subscription and a separate window. It is now on the entity page.

It improves what you write down. Post-incident reporting is where thin evidence shows. Naming the technique, linking the actor profile, and attaching the report Microsoft published about it turns a paragraph of narrative into something a reviewer can follow. This matters long after the incident closes, because the write-up is what gets read.

It gives an examiner question a real answer. Examiners ask what your threat intelligence sources are and how they inform your controls. "We read the news" is a weak answer that many institutions genuinely give. "Microsoft threat intelligence surfaced in our Defender portal, reviewed on a set cadence, with threat analytics checked against our own environment" is a real one, and it is now available without a purchase order.

Now the honest limit. None of this makes you a threat intelligence function. Intelligence you do not read is not intelligence, it is a tab. The institutions that get value out of this will be the ones that put a name and a recurring calendar entry against it. That is a management decision, not a licensing one, and no vendor can make it for you.

Featured Short

The ten minute check

Four checks that add up to about ten minutes for someone with the right access, and then a fifth step that is not a check at all. The fifth is a decision, it takes longer than the other four combined, and it is the one that determines whether any of this changes anything.

1
Two minutes

Open the Threat intelligence menu

Sign in to the Microsoft Defender portal at security.microsoft.com and look for the Threat intelligence navigation menu. Microsoft's documented path puts Intelligence explorer and Intel profiles there. If you can see them, the capability is surfacing for your tenant, which is the fastest thing to establish and the right place to start.

What this does not settle: how much of the intelligence you can see, which follows from the Defender and Sentinel products you hold. Seeing the menu proves the door is there. It does not tell you which rooms are open. That is the licensing question, and it is the one the assessment below answers properly.

2
Three minutes

Open one entity page and look for the insights tab

Pick any recent alert, click through to an IP address, domain, URL, or file, and look for the Threat Intelligence Insights tab. This is the Preview experience, so its presence and its contents may vary. Seeing it once tells your analysts it exists, which is most of the battle.

3
Three minutes

Read one threat analytics report against your own environment

Open Threat analytics and pick any active report. The section to read is the one showing whether the threat has been seen in your environment. If it has, you have found work. If it has not, you have found the format you will want in front of you the day it does.

4
Two minutes, and the one that costs money

Search your invoice for the retired line item

Ask whoever reconciles your Microsoft billing to search for a Defender Threat Intelligence charge. Microsoft's stated position is that all subscriptions end with the August 1, 2026 deprecation. If a charge is still there, raise it with your licensing provider.

If ABT manages your Microsoft 365 tenant, you do not need to run this step. We can check it against your subscriptions directly and tell you what we find.

5
Not part of the ten minutes, and the step people skip

Put a name against it

Decide who looks at threat analytics, and how often. Monthly is a defensible cadence for an institution of most sizes. Written down, with an owner, it becomes something you can show. Left unassigned, this whole change is a menu item nobody clicks, and in six months nothing will have improved.

Five step ten minute check for Microsoft 365 Defender threat intelligence, covering the Threat intelligence menu, entity page insights, threat analytics, the retired billing line item, and assigning an owner, with Microsoft Defender and Microsoft Sentinel callouts
The five steps, in the order that answers the cheapest questions first.

What this change does not mean

Three claims are floating around about this retirement that go further than Microsoft's own wording. Here is where the line actually sits.

The claimWhat Microsoft actually saysHow to treat it
Every premium threat intelligence capability is now free for every tenant The partner announcement says all capabilities are available at no extra cost to customers with Microsoft Defender or Microsoft Sentinel. The product documentation scopes its equivalent sentence to publicly available threat intelligence data, including entity enrichments, for Microsoft Defender XDR customers. Confirm in your own portal. What you see is governed by which Defender and Sentinel products you hold.
No extra cost for the intelligence means no cost anywhere downstream of it Microsoft's statement is about the cost of the threat intelligence capabilities themselves. Microsoft Sentinel is billed on data ingestion and retention, which is a separate meter from the intelligence surfaced in the Defender portal. If your plans involve pulling intelligence into Sentinel, price the ingestion separately. The intelligence being free does not make the data movement free.
Entity page enrichment is a finished, generally available feature Microsoft labels the entity enrichments experience as Preview and carries a prerelease notice on the documentation. Use it. Do not yet build a documented control procedure on top of it.
There is something you have to migrate Microsoft states that customers do not need to take migration action and that the features are already available to them. Nothing to do. The work is adoption, not migration.
This replaces a security operations team Microsoft describes these as intelligence and investigation experiences inside the Defender portal. They inform analysts. They do not staff a rota or make decisions. Better inputs for the people you have. Not a substitute for having them.
Security Copilot is now free because of this Microsoft describes Copilot in Defender as Security Copilot capability surfaced on the threat analytics, Intel profiles, and Intel explorer pages. That is a separate product with its own licensing. Two different things. Check your Security Copilot position separately.

The reason to be careful here is that this is a good news story, and good news stories get repeated with the qualifiers filed off. Somebody will tell your team that Microsoft made threat intelligence free. That is close enough to true to be useful and far enough from precise to be embarrassing in front of an examiner who asks a follow up question. The precise version is that a standalone product was retired, its capabilities now surface inside the Defender portal, Microsoft states there is no extra cost for customers with Defender or Sentinel, and part of the experience is still in Preview.

That version survives scrutiny. It is also still a genuinely good outcome, which is the point.

A free security assessment, starting with what you already pay for

Most security assessments open by describing what you should buy. This one opens by establishing what you already have and are not using, because that is usually the larger number.

No commitment required

We find the capability. You decide what to do with it.

  • What your Microsoft security licensing actually entitles you to. Written out per product, so the threat intelligence question above gets a specific answer rather than a general one. Where ABT already manages your Microsoft 365 tenant we read it directly; where licensing sits elsewhere we build the same view from what you can export.
  • What is switched on against what is merely licensed. The gap between those two is where most institutions are quietly exposed, and it is invisible from an invoice. This is the part that tends to surprise people.
  • The retired line item checked. If a Defender Threat Intelligence charge is still running against your account, you will hear about it from us, with the subscription detail behind it.
  • A cadence you can actually staff. A monthly threat analytics review is worth more than an ambitious weekly one that lapses in March. We will say what we think your team can sustain, including when the honest answer is less than you hoped.
  • Written so an examiner can read it. Credit unions, banks, and mortgage companies get asked where their threat intelligence comes from. The output is shaped to answer that in the form the question is usually asked.

The assessment is free and carries no obligation. ABT is a Tier 1 Cloud Solution Provider (CSP) serving over 750 financial institutions; we manage Microsoft 365 tenants and host Azure environments for credit unions, banks, and mortgage companies. We did not make these capabilities free and we take no credit for it. What we can do is tell you precisely which of them your licensing reaches, which are switched on, and which have never been opened.

The retirement, answered

August 1, 2026. Microsoft states that deprecation took effect on that date and that all Defender Threat Intelligence subscriptions end. Microsoft also gives an earlier milestone of August 1, 2025, when the product was removed from the price list preview. Microsoft's product documentation gives the same August 1, 2026 date for the retirement of the legacy standalone threat intelligence portal and the Intel Explorer experience.
No. Microsoft states that customers do not need to take migration action and that the features are already available to them. The work this creates is adoption rather than migration: finding the capability in the Microsoft Defender portal, showing your analysts where it is, and deciding who reviews it and how often.
Microsoft's partner announcement states that all capabilities are now available at no extra cost through the Microsoft Defender portal to any customer with Microsoft Defender or Microsoft Sentinel. Microsoft's product documentation words its equivalent statement more narrowly, saying that publicly available Microsoft Threat Intelligence data, including entity enrichments on entity pages, is accessible to all Microsoft Defender XDR customers at no extra cost. Both are Microsoft sources. The practical answer is that what you can see is governed by which Defender and Sentinel products you actually hold, so the reliable check is opening the Threat intelligence menu in your own portal rather than reading a table. One cost does stay separate: Microsoft Sentinel is billed on data ingestion and retention, so moving intelligence into Sentinel carries its own meter whatever the intelligence itself costs.
Raise it with whoever handles your Microsoft licensing. Microsoft's stated position is that all Defender Threat Intelligence subscriptions end with the August 1, 2026 deprecation, so a charge continuing past that point is worth questioning. If ABT manages your Microsoft 365 tenant we can check it against your subscriptions directly.
Sign in to the Microsoft Defender portal at security.microsoft.com and use the Threat intelligence navigation menu, which Microsoft documents as the route to Intelligence explorer and Intel profiles. Entity enrichment appears separately, as a Threat Intelligence Insights tab on the entity pages for IP addresses, domains, URLs, and files. Threat analytics reports sit in their own area of the portal.
Microsoft labels the entity enrichments experience as Preview and carries a prerelease notice on the relevant documentation. Treat it as usable and useful today, but do not yet write a documented control procedure that depends on it, because preview features can change before general release.
No. Microsoft describes Copilot in Defender as Microsoft Security Copilot capability brought into the Defender portal, available on the threat analytics, Intel profiles, and Intel explorer pages. Security Copilot is a separate product with its own licensing, and the Defender Threat Intelligence retirement does not change that. Check your Security Copilot position on its own terms.
Two things, and the second matters more than the first. Show your analysts the Threat Intelligence Insights tab so that entity context becomes part of normal triage rather than a special occasion. Then assign one person to review threat analytics on a set cadence, monthly for most institutions, and record that they did. A capability with no owner and no cadence produces no change, however good it is and however little it costs.
Talk to an Expert

Find out what you already own.

Tell us a little about your institution and we will run a free security assessment: what your Microsoft security licensing entitles you to, what is switched on, and what has never been opened. No commitment, and no obligation to buy anything at the end of it.

Credit Unions Banks Mortgage Companies Microsoft Defender Microsoft Sentinel
Tier 1 Cloud Solution Provider (CSP)Serving over 750 financial institutions. We manage Microsoft 365 tenants and host Azure environments.
An answer, not a sales cycleThe assessment produces a written picture of your current position, whether or not you work with us afterwards.
Written for the people who askShaped so it answers the threat intelligence question the way an examiner tends to ask it.

Request your free security assessment

We will come back to you with what we find, in writing.