Microsoft is retiring standalone MDTI experiences as intelligence capabilities move into the Defender portal.
Key Takeaways:
Microsoft has announced the integration of Microsoft Defender Threat Intelligence (MDTI) into Defender XDR and Microsoft Sentinel. The goal is to provide threat intelligence directly within security analysts’ workflow rather than requiring a separate platform.
Previously, security teams often had to switch between separate MDTI, Microsoft Sentinel, and Defender interfaces to collect threat actor information, indicators of compromise, and investigation context, which slowed down detection and response efforts.
“Beginning August 1, the final phase of Microsoft Defender Threat Intelligence (MDTI) convergence will be generally available in the Defender portal, giving customers real-time Microsoft threat intelligence across detection, investigation, response, hunting, and automation at no additional cost. Announced last year, this unified SecOps experience reduces fragmented context and tool handoffs, creating a clearer path from threat signal to informed action,” Microsoft explained.
Microsoft has enhanced the entity pages in Defender XDR with integrated threat intelligence details. This capability allows security analysts to view contextual information about IPs, domains, and other entities without switching between different tools or tabs. Moreover, Microsoft has made previously premium MDTI data sources more accessible for organizations. Certain MDTI connectors and APIs are now available at no additional cost for eligible Microsoft Sentinel and Defender XDR customers.

The Threat Intelligence Library is now embedded within Threat Analytics in the Defender portal. Users can access detailed threat actor profiles, intelligence reports, and Microsoft security research from a centralized location. Microsoft has upgraded threat analytics with richer intelligence content, including embedded IoCs, MITRE ATT&CK technique mappings, and correlation with related incidents and investigations.
A new case-linking capability allows security analysts to connect threat intelligence findings and IoCs directly to security cases, which improves collaboration, tracking, and documentation. Microsoft is also retiring the standalone MDTI pages this month, including Intel Profiles, Intel Explorer and Intel Projects. The company is consolidating all major MDTI capabilities into the Threat Intelligence section of the Microsoft Defender portal.
Microsoft notes that existing MDTI customers do not need to perform a migration. Starting this week, access to the MDTI value is available through the Threat Analytics tab in the Defender portal.