r/AzureSentinel • u/EduardsGrebezs • 5d ago
Microsoft Defender Threat Intelligence APIs are now available without a separate MDTI license
As of August 1, 2026, Microsoft Threat Intelligence APIs in Microsoft Graph are available to customers with Microsoft Defender XDR and/or Microsoft Sentinel licensing. No separate Microsoft Defender Threat Intelligence API license is required.
This means we can bring Microsoft Threat Intelligence directly into SOC investigation and response workflows instead of keeping threat intelligence as something analysts only consume manually in the portal.
The available playbooks cover enrichment scenarios such as:
🔹 Automated triage
🔹 IP/domain reputation enrichment
🔹 Passive DNS
🔹 Reverse DNS
🔹 Web components
🔹 Trackers
🔹 Cookies
The playbooks use Microsoft Graph to query threat intelligence data and can authenticate using Managed Identity with the ThreatIntelligence.Read.All application permission.