Microsoft Defender Threat Intelligence APIs are now available without a separate MDTI license
As of August 1, 2026, Microsoft Threat Intelligence APIs in Microsoft Graph are available to customers with Microsoft Defender XDR and/or Microsoft Sentinel licensing. No separate Microsoft Defender Threat Intelligence API license is required.
This means we can bring Microsoft Threat Intelligence directly into SOC investigation and response workflows instead of keeping threat intelligence as something analysts only consume manually in the portal.
The available playbooks cover enrichment scenarios such as:
πΉ Automated triage
πΉ IP/domain reputation enrichment
πΉ Passive DNS
πΉ Reverse DNS
πΉ Web components
πΉ Trackers
πΉ Cookies
The playbooks use Microsoft Graph to query threat intelligence data and can authenticate using Managed Identity with the ThreatIntelligence.Read.All application permission.
[link] [comments]