Microsoft is closing the legacy Microsoft Menace Intelligence portal on August 1, leaving safety groups solely days to confirm that their investigation workflows survived the transfer. Current Defender Menace Intelligence prospects can proceed utilizing the present product expertise till the cutoff.
Microsoft says all Microsoft Menace Intelligence capabilities are actually out there by way of the Defender portal, the place they assist Defender XDR and Microsoft Sentinel workflows. Earlier than the retirement, safety groups ought to confirm their licenses, permissions, investigation tasks and automatic integrations to keep away from dropping entry to essential workflows throughout an incident.
The portal closes, however the intelligence stays
Microsoft’s retirement steerage confirms that the legacy portal and Intel Explorer expertise will retire August 1.
The retirement doesn’t take away each perform related to Intel Explorer. Microsoft nonetheless directs customers to Intel profiles, Intel explorer and Intel tasks inside the built-in portal.
Entry varies by license and have. Microsoft’s Defender TI entry information requires a Premium license for full performance however says customers with out one can use a free providing. Directors ought to establish which analysts want premium intelligence, tenant-specific info or different licensed capabilities.
The transition is certainly one of a number of Microsoft assist deadlines IT groups face in 2026. A profitable portal login alone doesn’t verify that each analyst, challenge or automated workflow is prepared.
4 checks earlier than August 1
- Verify licenses and permissions
Check the accounts utilized by analysts and risk hunters as a substitute of counting on an administrator login. Verify that every account can attain the Intel profiles, Intel explorer, Intel tasks and entity-enrichment options and open its assigned tasks.
Overview Conditional Entry and authentication insurance policies for the affected accounts. A current marketing campaign involving an Azure CLI authentication hole confirmed how particular person sign-in paths can fall outdoors narrowly configured controls.
Doc the licenses and roles every workflow requires so assist groups can distinguish entitlement issues from incorrect permissions.
- Check investigations and tasks
Run frequent investigations within the Defender portal, together with searches for IP addresses, domains, URLs and information. Verify that analysts can attain risk profiles, enrichment knowledge and energetic tasks.
Microsoft’s Intel tasks documentation says the tasks web page shows tasks a consumer owns or that different customers within the tenant have shared. Venture house owners ought to confirm collaborator entry and export essential indicators or notes when organizational coverage requires a separate copy.
- Audit APIs and integrations
Stock each script, connector, enrichment job and SOAR playbook that consumes Defender TI knowledge. Embody AI-connected instruments in that assessment; Microsoft has individually warned that MCP device descriptions can redirect brokers into unintended actions.
Document every integration’s endpoint, authentication technique, Microsoft Graph permissions, licensing necessities and proprietor. Then check a consultant request.
Microsoft continues to publish Defender Menace Intelligence API documentation, however the web page nonetheless lists an energetic Defender Menace Intelligence Portal license and API add-on as conditions. API house owners ought to verify post-retirement licensing with Microsoft reasonably than assume present entry will proceed unchanged.
- Replace runbooks and coaching
Revise runbooks, onboarding guides, bookmarks and screenshots that time analysts to the standalone portal. Substitute out of date instructions with the corresponding Defender portal location.
Integration information ought to establish the endpoint, permissions, license and proprietor for each automated workflow. Groups that haven’t accomplished the transfer ought to check entry and integrations earlier than August 1, when an unverified dependency might turn out to be an incident-response delay.
Learn subsequent: Overview how BitLocker, passkeys and Microsoft Defender work collectively and the place enterprise protections require separate licensing.
