Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel
Microsoft Defender Threat Intelligence is integrating with Microsoft Defender and Microsoft Sentinel by January 8, 2026, offering unified threat insights, enhanced analytics, and IoC integration. Organizations must transition to these platforms and update licensing and documentation to maintain access. Introduction Microsoft Defender Threat Intelligence (MDTI) is converging with Microsoft Defender and Microsoft Sentinel to deliver integrated threat intelligence capabilities directly within your SecOps environment. This change simplifies access to threat insights, improves detection and response workflows, and aligns with customer feedback for a unified experience. When this will happen Full convergence will be completed by January 8, 2026. New capabilities are available now, and as of August 2025, all MDTI data has been published via the free connector, with new Threat Analytics APIs replacing retired MDTI APIs. How this affects your organization Who is affected: Organizations using Microsoft Defender Threat Intelligence, Microsoft Defender, or Microsoft Sentinel. What will happen: Threat Intelligence Library will be accessible via the Microsoft Defender portal, including exclusive threat reports, intel profiles, and Indicators of Compromise (IoCs) integrated into Threat Analytics. Enhanced Threat Analytics reports will include: Indicators of Compromise (IoCs) embedded in reports. MITRE ATT&CK mapping for tactics, techniques, and procedures. Insights on targeted industries and actor origins. Related intelligence and aliases for cross-referencing. IoCs will be linked to cases for Sentinel customers. After January 8, 2026, MDTI capabilities will require an active Microsoft Defender or Microsoft Sentinel license. What you can do to prepare Plan your transition to Microsoft Defender or Microsoft Sentinel before January 8, 2026, to maintain uninterrupted access. Review licensing requirements for MDTI capabilities. Update internal documentation to reflect new Threat Analytics APIs and connector availability. Compliance considerations No compliance considerations identified, review as appropriate for your organization. Message ID: MC1192257
The post Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot
Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...
Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role
Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...
Microsoft 365 Copilot: new guided Copilot onboarding experience
Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....
Microsoft Purview |Unified Classification Management Experience
Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...
Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot
Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...
Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)
Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...
Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering
We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...
Microsoft Teams: Impersonation Protection for Teams meetings
Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...
Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent
Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...