On this page · 11 sections
- What actually changed on 1 August 2026
- Where each MDTI feature now lives
- The licensing question: who keeps access, and who now pays
- The eight checks to run this week
- If you land in Sentinel, the cost model changes shape
- What this looks like inside an already-busy 2026
- India-specific considerations
- What good looks like a week from now
- FAQ
- How eCorpIT can help
- References
Summary. Microsoft retired the standalone Microsoft Defender Threat Intelligence (MDTI) product on 1 August 2026, two days before this article was published. The change was announced in Message Center post MC1192257 on 5 December 2025, revised twice, and given a final act-by date of 1 August 2026 on 22 December 2025. After that date, MDTI capabilities require an active Microsoft Defender or Microsoft Sentinel licence. Microsoft 365 E5 carries the entitlement at no extra cost, and E5 moved from $57 to $60 per user per month on 1 July 2026, a 5% increase. Microsoft 365 E3 does not carry it without an add-on. The Defender Suite standalone SKU lists at $12.00 per user per month. The intelligence itself did not go anywhere: Intel profiles, Intel explorer and Intel projects now sit under the Threat intelligence menu in the Microsoft Defender portal, alongside Threat analytics and Sentinel-powered Intel management. What breaks is everything pointed at the old address: analyst bookmarks, Microsoft Graph calls, SOAR playbooks and enrichment jobs that assumed a standalone entitlement. This article covers what moved where, who now pays, the Graph API prerequisite that Microsoft's own documentation still lists incorrectly, and the eight checks to run before a stale dependency turns into an incident-response delay.
What actually changed on 1 August 2026
Two things happened at once, and conflating them is the most common way teams get this wrong.
The first is a portal retirement. The legacy standalone Microsoft Threat Intelligence portal, including the Intel Explorer experience served from it, stopped being the place you go. Existing Defender TI customers kept the old product experience right up to the cutoff, which is why so many SOCs left the work until the last week of July 2026.
The second is a licensing retirement. MDTI is no longer sold as a separate product. As Message Center post MC1192257 puts it, "After August 1, 2026, MDTI capabilities will require an active Microsoft Defender or Microsoft Sentinel license." Those are different failure modes. A portal move breaks bookmarks and scripts. A licensing change breaks entitlement, and it breaks it silently for the accounts that were carrying a standalone subscription rather than an E5 or Defender seat.
Microsoft has been staging this for a year. As of August 2025, all MDTI data was published through the free Sentinel connector, and new Threat Analytics APIs replaced the retired MDTI APIs. The 1 August 2026 date is the end of a migration that started well before it, not a switch that was flipped without notice.
Alym Rayani, Vice President of Marketing for Microsoft Security, framed the convergence in the company's July 2026 update this way: "Threat intelligence enhancements, including Microsoft Defender Threat Intelligence convergence and an enhanced Threat Intelligence Agent, bring more out-of-the-box intelligence and automation into the unified SecOps workflow, so teams can move from summary to action." That is the upside. The downside is that every integration built against the old surface has to be re-pointed by someone.
Where each MDTI feature now lives
The Defender portal gained a Threat intelligence navigation menu that pulls from three sources: Defender XDR Threat analytics reports, Defender TI articles and data sets, and Microsoft Sentinel threat intelligence. Here is the mapping that matters when you rewrite a runbook.
| Old location (standalone portal) | New location (Defender portal) | What to re-point |
|---|---|---|
| Intel Explorer search and pivoting | Threat intelligence, then Intel explorer | Analyst bookmarks, saved searches, training screenshots |
| Actor and tooling profiles | Threat intelligence, then Intel profiles | Links inside case notes and detection documentation |
| Projects and shared artefacts | Threat intelligence, then Intel projects | Collaborator access lists, exported indicator sets |
| Entity enrichment for IPs, domains, URLs, files | Threat Intelligence Insights tab on entity pages | Triage runbooks that told analysts to switch portals |
| Threat reports and analyst write-ups | Threat analytics, with IOCs embedded in reports | Report distribution lists and reading assignments |
| MDTI APIs | Threat Analytics APIs and the Sentinel connector | Enrichment jobs, SOAR playbooks, custom dashboards |
| Indicator management at scale | Intel management, powered by Microsoft Sentinel | STIX ingestion pipelines and upload API integrations |
Two of those rows deserve a warning. Intel projects and custom tagging were the features that lagged furthest behind during the transition period. Microsoft's Defender XDR documentation for Defender TI, last revised in April 2024, still states that the in-portal experience "doesn't include the ability to apply custom tags or project capabilities." Microsoft's newer unified security operations documentation, revised in 2026, lists Intel projects as a page in the Threat intelligence menu. The docs disagree with each other. Trust the tenant, not the page: sign in as a working analyst and look.
Intel management is the row most teams underestimate. It is powered by Microsoft Sentinel rather than Defender XDR, it speaks structured threat information expression (STIX), and it is where bulk indicator work now happens. If your team lived in the standalone portal and never touched Sentinel, this is a new product to learn, not a renamed tab.
The licensing question: who keeps access, and who now pays
This is where budgets move. MDTI capabilities are bundled rather than billed separately, so the cost did not disappear; it was folded into suites whose prices rose on 1 July 2026.
| Licence you hold | MDTI access after 1 August 2026 | List price from 1 July 2026 |
|---|---|---|
| Microsoft 365 E5 | Included at no extra cost | $60 per user per month, up from $57 |
| Microsoft 365 E3, no add-ons | Not included | $39 per user per month, up from $36 |
| E5 Security add-on or Defender for Endpoint P2 | Included | Priced per add-on; Defender Suite lists at $12.00 |
| Microsoft Sentinel | Included through the connector; ingestion charges may apply | Consumption based, no per-user list price |
| Standalone MDTI | Retired on 1 August 2026 | No longer sold |
Thomas Rosquin, a content strategist and technology writer at TrustedTech, a Microsoft Cloud Solution Provider, put the entitlement question plainly: "No. MDTI will no longer be sold as a standalone product. The standalone offering will retire on August 1, 2026, and continued access will require a Microsoft Defender or Microsoft Sentinel license."
Three practical consequences follow.
Organisations on Microsoft 365 E5 mostly have nothing to buy. Their work is confirming access and retraining analysts, not raising a purchase order. The 5% E5 increase on 1 July 2026 was not caused by this convergence, but it lands in the same budget cycle and the two get discussed together in renewal meetings.
Organisations on Microsoft 365 E3 have a real decision. E3 rose 8% to $39 per user per month on 1 July 2026 and still does not carry MDTI. Closing the gap means an E5 Security add-on, Defender for Endpoint P2, or leaning on Sentinel and accepting ingestion costs instead of seat costs.
Organisations that bought standalone MDTI as a third-party-intel replacement have the sharpest deadline, because their entitlement was the thing that retired. If nobody has confirmed which Defender or Sentinel licence now carries the capability, assume access is at risk and test it today.
There is a quieter saving worth checking. Because Defender XDR and Sentinel customers now get this intelligence without a separate line item, the overlap with commercial threat-intel feeds is larger than it was. That is a genuine consolidation candidate, and it belongs in the same review as the rest of your cloud cost optimisation for Indian teams work rather than in a separate security budget conversation.
The eight checks to run this week
TechRepublic published four checks on 29 July 2026, two days before the cutoff. Those four are correct and they are the right starting point. In practice we would run eight, because the four published checks assume the licence question is already settled and that nothing downstream consumes the data on a schedule.
1. Test with an analyst account, not an admin account
Global Administrator sees almost everything, which makes it the worst account to validate an entitlement change with. Sign in as a tier-one analyst, a threat hunter and an on-call responder, and confirm each can open Intel profiles, Intel explorer, Intel projects and the Threat Intelligence Insights tab on an entity page. A successful portal login proves nothing on its own.
2. Write down the licence each workflow depends on
For every workflow, record the licence and the role that make it work. When something fails at 03:00 during an incident, the difference between an entitlement problem and a role assignment problem determines who you call. Without that record, both look identical from the console.
3. Re-run your five most common investigations
Take the five searches your team actually runs, IP address, domain, URL, file hash and actor name, and execute them in the Defender portal. Confirm enrichment data appears, confirm pivoting still works, and confirm the analyst can get from an alert to actor context without leaving the portal. Time it. If the new path takes materially longer, that is a training gap you can close now rather than during an incident.
4. Reconcile Intel projects and their collaborators
Microsoft's Intel projects documentation states that the projects page shows projects a user owns or that other users in the tenant have shared. Ownership and sharing are the two things that quietly break in a migration. Have each project owner open their projects, verify the collaborator list, and export indicators or notes where your policy requires an independent copy. Treat an unexported project with a departed owner as data you no longer have.
5. Inventory every automated consumer of the data
List every script, connector, enrichment job, scheduled query, SOAR playbook and dashboard that reads Defender TI data. For each one, record the endpoint, the authentication method, the Microsoft Graph permissions, the licence it assumes, and a named owner. Then send one representative request per integration and read the response body, not just the status code. An integration returning empty results with HTTP 200 is the failure mode that survives a casual check.
6. Read the Graph API prerequisites with suspicion
This is the trap. Microsoft continues to publish Defender Threat Intelligence API documentation on Microsoft Graph, and as TechRepublic noted on 29 July 2026, that page still lists an active Defender Threat Intelligence Portal licence and API add-on as prerequisites, for a portal that has now retired. Do not take a documentation page as confirmation of post-retirement entitlement. Confirm with Microsoft support or your licensing partner in writing, and keep the answer with your integration inventory.
7. Rewrite the runbooks, the bookmarks and the screenshots
Every onboarding guide, wiki page, alert template and training deck that tells an analyst to open the standalone portal is now wrong. Screenshots are the ones teams forget, and they are the ones a new joiner trusts most. Replace the navigation instructions with the Defender portal path, and date-stamp the page so the next reviewer knows it was checked after 1 August 2026.
8. Review the third-party feeds you may no longer need
With the intelligence now bundled into Defender XDR and Sentinel entitlements, run a deliberate overlap review against commercial feeds. Do not cancel anything on the strength of a marketing table. Compare coverage on threats that actually matter to your sector, and only then decide. The same discipline applies here as in a multicloud security posture management decision: tool consolidation is worth doing, and worth doing slowly.
If you land in Sentinel, the cost model changes shape
Teams that answer the entitlement question with "we will use the Sentinel connector" have swapped a per-user cost for a per-gigabyte one. That is often the right trade, and it is a different budgeting exercise.
CyberOne, a UK managed security provider, published a 2026 Sentinel pricing breakdown on 25 June 2026, updated 13 July 2026, authored by Microsoft Practice Director Luke Elston. The figures below are from that analysis rather than from a Microsoft price list, so treat them as an order-of-magnitude planning input and confirm current rates for your region before committing.
| Commitment level | Effective rate per GB | Note |
|---|---|---|
| Pay-as-you-go | $4.30 | Flexible, no reservation |
| 100 GB per day | About $2.96 | Roughly 31% below pay-as-you-go |
| 5,000 GB per day | $2.31 | Largest listed reservation discount |
| Archive tier, after 90 days | $0.02 per GB per month | Analytics retention is free for the first 90 days |
| Data lake storage | $0.026 per GB per month | Billed on 6:1 compression |
Three levers matter more than the tier you pick.
The free sources are genuinely free. Azure Activity Logs, Sentinel Health data, Office 365 audit logs covering SharePoint, Exchange administrative actions and Teams activity, and security alerts from Microsoft Defender products all ingest without an ingestion charge. Teams routinely pay to ingest data that was already free.
The per-user data grant is routinely missed. CyberOne's analysis describes a 5 MB per user per day credit for users on Microsoft 365 E5, A5, F5 or G5. On a 2,000-seat E5 estate that is 10 GB a day deducted from the bill before any tuning work starts.
The 31-day rule cuts one way. You can raise a commitment tier immediately to capture a discount, but you cannot lower it for 31 days. Over-reserving is therefore a month-long mistake, which is an argument for tuning ingestion first and reserving second.
Sending the right telemetry to the right tier is the whole game, and the reasoning is the same one that applies to cloud storage pricing across AWS, Azure and GCP: identity logs, threat intelligence and endpoint alerts belong where detection runs, while high-volume proxy and firewall data belongs in cheap retention.
What this looks like inside an already-busy 2026
The MDTI retirement is not an isolated event. It sits inside a wider set of Microsoft security changes that landed in the same quarter, and the operational load compounds.
As of 1 July 2026, Microsoft Intune Suite capabilities were included in Microsoft 365 E5, with selected capabilities in Microsoft 365 E3. On 13 July 2026, Microsoft Entra ID made passkeys the default authentication experience, with Microsoft-provided telecom delivery for SMS and voice retiring in 2027. On 27 July 2026, Microsoft announced Project Perception, a coordinated system of red, blue and green agents intended to run security workflows in continuous loops. Each of those changes generates its own runbook edits.
The practical response is to batch the documentation work rather than treat each announcement as a separate project. One review pass across your SOC runbooks in August 2026 will pick up the threat-intelligence navigation change, the Intune entitlement change and the authentication default change together. Three separate passes across three months will not, because the third pass never gets scheduled.
If your roadmap already includes autonomous or agent-assisted operations, note that the same consolidation logic drives both. The reasoning we set out on agentic SOC and autonomous patching, build versus buy applies directly: a platform that owns detection, intelligence and response in one place is easier to automate against than four products stitched together, which is precisely why Microsoft collapsed the surface.
India-specific considerations
For Indian enterprises and global capability centres in Gurugram, Bengaluru and Hyderabad, three details change the shape of this migration.
Suite pricing is quoted in US dollars on Microsoft's licensing pages, and Microsoft states that this pricelist pricing is subject to change and may vary by country and currency. The $60 per user per month E5 figure is therefore a reference point rather than the number on an Indian invoice. On a 1,000-seat estate, the $3 per user per month E5 increase alone is $36,000 a year at US list before any contracted discount. Convert that at your own rate, add applicable taxes, and confirm the local figure with your reseller. The point is that it is a line item worth naming rather than absorbing.
Data residency deserves a second look. Threat intelligence indicators are operational data rather than personal data in most cases, but Intel projects can accumulate analyst notes that reference individuals under investigation. Under the Digital Personal Data Protection Act 2023, that content is worth classifying deliberately rather than by default, particularly where a project is shared tenant-wide. Our DPDP engineering playbook for Indian startups covers the classification approach; the specific action here is to check what your Intel projects actually contain before you migrate or export them.
Follow-the-sun teams face a scheduling problem. If your Indian SOC covers the overnight window for a European or North American parent, the analysts most likely to hit a broken enrichment path are the ones least able to reach a licensing administrator when it happens. Run the analyst-account test on the India shift specifically, not only during a business-hours change window in the head-office time zone.
What good looks like a week from now
A finished migration is not "the portal opens". It is four artefacts you can hand to an auditor or a new hire.
An integration inventory with an owner, an endpoint, an authentication method and a tested response for every automated consumer of threat-intelligence data. A licence map that says which SKU carries the entitlement for which workflow. A set of runbooks whose screenshots and navigation paths were verified after 1 August 2026. And a decision, written down, on which third-party intelligence subscriptions you are keeping and why.
The real cost of a change like this is rarely the licence. It is the six months of undocumented integrations that nobody re-tested until an incident found them.
FAQ
How eCorpIT can help
eCorpIT is a Gurugram-based technology consultancy, founded in 2021 and ISO 27001:2022 certified, with CMMI Level 5 and MSME certification. Our senior engineering teams work with Microsoft security and cloud estates, and this kind of migration is mostly disciplined inventory work rather than heroics: finding every automated consumer of a data source, testing it against real accounts, and writing down what depends on which licence. We design environments aligned with DPDP Act 2023 requirements and can run the integration audit and runbook rewrite alongside your SOC. If your MDTI dependencies were never fully mapped, talk to us about a short, scoped review.
References
- MC1192257: Microsoft Defender Threat Intelligence convergence with Microsoft Defender and Microsoft Sentinel, Microsoft 365 Message Center Archive, published 5 December 2025, updated 22 December 2025.
- MDTI convergence in Microsoft Sentinel and Defender XDR is complete, Microsoft Community Hub, 28 July 2026.
- Uncover adversaries with threat intelligence across the Defender portal, Microsoft Learn, unified security operations documentation.
- Microsoft Defender Threat Intelligence in Microsoft Defender XDR, Microsoft Learn.
- Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff, TechRepublic, 29 July 2026.
- What's new in Microsoft Security: July 2026, Alym Rayani, Microsoft Security Blog, 30 July 2026.
- Microsoft 365 pricing and packaging updates, Microsoft Licensing Resources, effective 1 July 2026.
- Microsoft Is Merging Defender Threat Intelligence: Here's the Licensing Impact, Thomas Rosquin, TrustedTech, 23 December 2025.
- Microsoft Sentinel pricing explained: Analytics and Data Lake tiers in 2026, Luke Elston, CyberOne, published 25 June 2026, updated 13 July 2026.
- Using projects in Microsoft Defender Threat Intelligence, Microsoft Learn.
- Microsoft Graph security threat intelligence API overview, Microsoft Learn.
- Quickstart: accessing Microsoft Defender Threat Intelligence, Microsoft Learn.
- Microsoft Entra ID security updates: passkeys are the default authentication method, Microsoft Security Blog, 13 July 2026.
Last updated: 3 August 2026.