Microsoft Defender Threat Intelligence reaches end of life as a standalone SKU on August 1, 2026. The capabilities are not being withdrawn. They become available at no cost through the Microsoft Defender portal, and CSP partners receive a credit memo covering the remaining subscription term beyond August 1.
This is an unusually customer-favourable retirement: the same capability, no licence, money back. It nonetheless requires action, because a capability that moves location is a capability your team may stop using without noticing.
What to check
First, confirm the credit. Organizations that purchased MDTI through a CSP partner should verify the credit memo appears against the remaining term rather than assuming it will. Credits that are automatic in policy are frequently manual in practice.
Second, confirm access. The relevant analysts need the correct roles in the Defender portal to reach threat intelligence content. Access that was previously governed by a standalone subscription is now governed by portal permissions, and those are not the same thing. A SOC that finds out during an incident that nobody has the role is a bad outcome for a change that is otherwise good news.
Third, confirm integrations. Where MDTI data fed automated enrichment — into Sentinel analytics rules, into a SOAR playbook, into a threat intelligence platform via API — those integrations may reference a subscription-scoped endpoint or an API key issued against the standalone product. Any integration touching MDTI should be tested against the post-August configuration before August 1, not after.
The broader pattern
MDTI joining the Defender portal at no cost fits a consistent direction: Microsoft is consolidating security capability into fewer, larger surfaces and moving the commercial value into the suites rather than into standalone products. The same update cycle moves Security Copilot into Microsoft 365 E5, moves Defender for Office 365 P1 into E3, and introduces Defender Suite and Purview Suite bundles at 12.00 USD each.
The operational implication is that security capability increasingly arrives without a procurement event. Nobody signs a purchase order, nobody runs an implementation project, and the capability sits unconfigured in a portal. The organizations getting value from this consolidation are the ones running a periodic review of what their licences actually entitle them to and comparing that against what is deployed. That gap is consistently large.
A related deprecation to put on the calendar
In the same announcement cycle, Microsoft confirmed that Data Loss Prevention file policy capabilities in Defender for Cloud Apps are deprecated effective January 6, 2027, with those capabilities moving to Microsoft Purview. An automated migration tool is expected. Organizations with DLP file policies configured in Defender for Cloud Apps should inventory them now and plan the Purview transition rather than waiting for the tool, because policy migration is rarely as mechanical as a tool implies and the policies encode business rules that need validating regardless.
How Lorexus engages
We verify credit memos, re-establish analyst access and test every integration touching MDTI ahead of the August 1 date. More broadly, we run entitlement-versus-deployment reviews that identify security capability you already own and are not running — which in the current consolidation cycle is a growing list. Book a free 15-minute call with our senior engineers.