Microsoft simplifies MDTI access in Defender XDR | Kocho
Skip to content
Funnel overlay image

Microsoft brings MDTI into Defender XDR to simplify threat intelligence access

Anna Webb profile headshot

Anna Webb

Global Director, Security and Identity Support Services

Published: 06 August 2026

Microsoft Defender Threat Intelligence (MDTI) premium features are now included in the Defender XDR portal, giving Microsoft security customers richer threat intelligence in the tools their analysts already use, with no migration required.

End-of-life announcements often bring security operations teams out in a cold sweat. After all, change can mean more work, more planning, and more cost.

Not this time. On 1 August 2026, Microsoft retired the standalone MDTI subscription, moving its premium threat intelligence features into the Defender XDR portal.

For Microsoft security customers, the capability remains available while the separate licence goes away. There is no migration project to plan, no premium feature loss to manage, and no additional cost for organisations already using the relevant Microsoft security tools.

Lower licence cost, easier access to threat intelligence

Removing a standalone licence gives customers an immediate commercial benefit. Organisations that already use the relevant Microsoft security tools can retain access to premium MDTI capabilities without carrying a separate subscription, procurement process, or renewal decision.

Threat intelligence creates value when analysts can apply it quickly. Busy SOC teams need intelligence they can interpret quickly, connect to genuine risk, filter out low-value noise, and use to decide the next action.

With MDTI inside Defender XDR, those insights sit closer to the alerts, incidents, identities, devices, and assets teams already manage.

Analysts can move from indicator context to investigation and response without switching into a separate intelligence product. That reduces friction, supports faster triage, and makes intelligence easier to embed into everyday security operations.

quote icon

“Security teams need intelligence to make faster, better decisions. Removing barriers to access can only help.”

Nikki Smart, Technical Delivery Analyst Security Operations, Kocho

Credit memos need customer follow-through

CSP partners with active MDTI subscriptions running beyond 1 August 2026 will receive credit memos from Microsoft for the remaining term.

Those credits need to be passed on to end customers. This is a finance and account management action, not a technical migration task.

Turn included intelligence into daily SOC practice

Microsoft’s MDTI change removes a standalone licence and brings premium threat intelligence into platforms many security teams already use. The value now depends on whether organisations turn that intelligence into daily SOC practice.

Security teams should review how MDTI is used in Defender and Sentinel, then update triage, investigation, and threat hunting workflows where the added intelligence improves decisions. The aim is simple: make the data part of everyday analyst behaviour.

tag icon

Become Greater

Keep one step ahead of the cyber attackers

Sign up to the Kocho newsletter to get exclusive news, the latest threat reports, Microsoft tech updates, and expert analysis from our cybersecurity specialists.

Plus invites to webinars and industry events.

Butterfly overlay image
Anna Webb profile headshot

Author

Anna Webb

Global Director, Security and Identity Support Services

Anna has over 20 years’ experience in operations management, major incident management, and cyber security. CISSP qualified, Anna is officially a Security Changemaker (Microsoft Security Excellence Awards).