Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    I’ve Waited 8 Years for Overwatch’s D.Mon. Her Gameplay Didn’t Disappoint

    August 7, 2026

    Our Favorite Fans Are on Sale to Help With Summer Heat Waves (2026)

    August 7, 2026

    What Chocolate Finance got right about S’pore’s changing savings habits

    August 7, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff
    Cybersecurity

    Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff

    InfoForTechBy InfoForTechAugust 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Microsoft is closing the legacy Microsoft Threat Intelligence portal on August 1, leaving security teams only days to verify that their investigation workflows survived the move. Existing Defender Threat Intelligence customers can continue using the current product experience until the cutoff.

    Microsoft says all Microsoft Threat Intelligence capabilities are now available through the Defender portal, where they support Defender XDR and Microsoft Sentinel workflows. Before the retirement, security teams should verify their licenses, permissions, investigation projects and automated integrations to avoid losing access to important workflows during an incident.

    The portal closes, but the intelligence remains

    Microsoft’s retirement guidance confirms that the legacy portal and Intel Explorer experience will retire August 1.

    The retirement does not remove every function associated with Intel Explorer. Microsoft still directs users to Intel profiles, Intel explorer and Intel projects within the integrated portal.

    Access varies by license and feature. Microsoft’s Defender TI access guide requires a Premium license for full functionality but says users without one can use a free offering. Administrators should identify which analysts need premium intelligence, tenant-specific information or other licensed capabilities.

    The transition is one of several Microsoft support deadlines IT teams face in 2026. A successful portal login alone does not confirm that every analyst, project or automated workflow is ready.

    Four checks before August 1

    1. Confirm licenses and permissions

    Test the accounts used by analysts and threat hunters instead of relying on an administrator login. Confirm that each account can reach the Intel profiles, Intel explorer, Intel projects and entity-enrichment features and open its assigned projects.

    Review Conditional Access and authentication policies for the affected accounts. A recent campaign involving an Azure CLI authentication gap showed how individual sign-in paths can fall outside narrowly configured controls.

    Document the licenses and roles each workflow requires so support teams can distinguish entitlement problems from incorrect permissions.

    1. Test investigations and projects

    Run common investigations in the Defender portal, including searches for IP addresses, domains, URLs and files. Confirm that analysts can reach threat profiles, enrichment data and active projects.

    Microsoft’s Intel projects documentation says the projects page displays projects a user owns or that other users in the tenant have shared. Project owners should verify collaborator access and export critical indicators or notes when organizational policy requires a separate copy.

    1. Audit APIs and integrations

    Inventory every script, connector, enrichment job and SOAR playbook that consumes Defender TI data. Include AI-connected tools in that review; Microsoft has separately warned that MCP tool descriptions can redirect agents into unintended actions.

    Record each integration’s endpoint, authentication method, Microsoft Graph permissions, licensing requirements and owner. Then test a representative request.

    Microsoft continues to publish Defender Threat Intelligence API documentation, but the page still lists an active Defender Threat Intelligence Portal license and API add-on as prerequisites. API owners should confirm post-retirement licensing with Microsoft rather than assume current access will continue unchanged.

    1. Update runbooks and training

    Revise runbooks, onboarding guides, bookmarks and screenshots that point analysts to the standalone portal. Replace obsolete directions with the corresponding Defender portal location.

    Integration records should identify the endpoint, permissions, license and owner for every automated workflow. Teams that have not completed the move should test access and integrations before August 1, when an unverified dependency could become an incident-response delay.

    Read next: Review how BitLocker, passkeys and Microsoft Defender work together and where enterprise protections require separate licensing.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

    August 7, 2026

    ChatGPT Atlas Shuts Down Aug. 9: What Users Must Save Before Migrating

    August 7, 2026

    CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

    August 6, 2026

    Apple briefly removes Telegram from App Store over reported CSAM violation

    August 6, 2026

    Detect East-West Traffic Threats with Fidelis Network

    August 5, 2026

    Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

    August 5, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026196 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202619 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.