On June 30th, 2024, the Microsoft Defender Threat Intelligence (MDTI) standalone portal will reach end-of-life and the Microsoft Defender XDR portal will become MDTI’s exclusive home for both standard and premium users. In this blog, we’ll guide customers using the standalone portal that wish to continue using MDTI in Defender XDR through the simple migration process. We’ll also help customers, and their teams, prepare to take advantage of the benefits MDTI brings to Microsoft’s XDR, SIEM, and AI solutions.
On June 30th, 2024, the MDTI standalone portal at ti.defender.microsoft.com will be decommissioned. However, all existing MDTI licenses will carry over to its permanent home in the Microsoft Defender XDR portal, where customers can seamlessly use the same features and content in in both premium and free capacities. Customers can also access MDTI content and data via natural language prompts by purchasing Copilot for Security.
Within Microsoft Defender XDR, users will see the familiar MDTI homepage under the “Threat Intelligence” blade in the left-hand navigation menu (pictured below).
Customers with an MDTI license may begin using the premium experience within Defender XDR immediately. Those without a license can continue using the standard version at no cost or explore MDTI licensing options to receive unlimited access to Microsoft’s award-winning threat intelligence.
If you do not have Defender XDR but want to continue using MDTI, explore licensing options or set up a trial environment.
Note: Please contact your tenant administrator if you believe you should have access to Defender XDR within your organization, but do not. The Microsoft Entra roles which grant access to Defender XDR can be found here.
Since launching MDTI into the XDR portal early last year and opening the standard version to all Defender XDR customers at Microsoft Ignite in November, thousands of MDTI and Defender XDR customers have experienced the benefits of aligning the high-fidelity threat intelligence in MDTI with their investigation and response tools under a single pane of glass. MDTI complements other products and features in Defender XDR in a number of ways:
MDTI also enhances Microsoft Defender for Cloud and Microsoft Sentinel to help deliver a unified threat intelligence experience for customers:
Microsoft Copilot for Security enables customers to access, operate on, and integrate Microsoft’s raw and finished threat intelligence via natural language. With Copilot for Security, users can leverage MDTI’s data sets and content anytime, anywhere within Defender XDR to provide additional context and aid in investigations:
MDTI powers Copilot for Security via a wide range of Threat Intelligence skills, enabling customers to quickly retrieve information on indicators including IP addresses and domains, and contextualize artifacts with content such as threat articles and intel profiles. Additionally, out-of-the-box promptbooks correlate MDTI content and data with other security information from Defender XDR, such as incidents and hunting activities, to help customers quickly understand the broader scope of an attack. These capabilities will be available within both the standalone and embedded Copilot for Security experiences.
Learn more about the MDTI skills available in Copilot here, and check back to this blog following Microsoft Secure next week to learn more about MDTI’s role in Copilot for Security.
If you are interested in learning more about MDTI and how it can help you unmask and neutralize modern adversaries and cyberthreats such as ransomware, and to explore the features and benefits of MDTI please visit the MDTI product web page. Also, be sure to contact our sales team to request a demo or a quote.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.