#Tech & AI

Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff


Microsoft is closing the legacy Microsoft Threat Intelligence portal on August 1, leaving security teams only days to verify that their investigation workflows survived the move. Existing Defender Threat Intelligence customers can continue using the current product experience until the cutoff.

Microsoft says all Microsoft Threat Intelligence capabilities are now available through the Defender portal, where they support Defender XDR and Microsoft Sentinel workflows. Before the retirement, security teams should verify their licenses, permissions, investigation projects and automated integrations to avoid losing access to important workflows during an incident.

The portal closes, but the intelligence remains

Microsoft’s retirement guidance confirms that the legacy portal and Intel Explorer experience will retire August 1.

The retirement does not remove every function associated with Intel Explorer. Microsoft still directs users to Intel profiles, Intel explorer and Intel projects within the integrated portal.

Access varies by license and feature. Microsoft’s Defender TI access guide requires a Premium license for full functionality but says users without one can use a free offering. Administrators should identify which analysts need premium intelligence, tenant-specific information or other licensed capabilities.

The transition is one of several Microsoft support deadlines IT teams face in 2026. A successful portal login alone does not confirm that every analyst, project or automated workflow is ready.

Four checks before August 1

  1. Confirm licenses and permissions

Test the accounts used by analysts and threat hunters instead of relying on an administrator login. Confirm that each account can reach the Intel profiles, Intel explorer, Intel projects and entity-enrichment features and open its assigned projects.

Review Conditional Access and authentication policies for the affected accounts. A recent campaign involving an Azure CLI authentication gap showed how individual sign-in paths can fall outside narrowly configured controls.

Document the licenses and roles each workflow requires so support teams can distinguish entitlement problems from incorrect permissions.

  1. Test investigations and projects

Run common investigations in the Defender portal, including searches for IP addresses, domains, URLs and files. Confirm that analysts can reach threat profiles, enrichment data and active projects.

Microsoft’s Intel projects documentation says the projects page displays projects a user owns or that other users in the tenant have shared. Project owners should verify collaborator access and export critical indicators or notes when organizational policy requires a separate copy.

  1. Audit APIs and integrations

Inventory every script, connector, enrichment job and SOAR playbook that consumes Defender TI data. Include AI-connected tools in that review; Microsoft has separately warned that MCP tool descriptions can redirect agents into unintended actions.

Record each integration’s endpoint, authentication method, Microsoft Graph permissions, licensing requirements and owner. Then test a representative request.

Microsoft continues to publish Defender Threat Intelligence API documentation, but the page still lists an active Defender Threat Intelligence Portal license and API add-on as prerequisites. API owners should confirm post-retirement licensing with Microsoft rather than assume current access will continue unchanged.

  1. Update runbooks and training

Revise runbooks, onboarding guides, bookmarks and screenshots that point analysts to the standalone portal. Replace obsolete directions with the corresponding Defender portal location.

Integration records should identify the endpoint, permissions, license and owner for every automated workflow. Teams that have not completed the move should test access and integrations before August 1, when an unverified dependency could become an incident-response delay.

Read next: Review how BitLocker, passkeys and Microsoft Defender work together and where enterprise protections require separate licensing.



Source link

Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff

Why Solana Could Be Heading for a

Leave a comment

Your email address will not be published. Required fields are marked *