MDTI end of life: your security SKU can vanish
Microsoft Defender Threat Intelligence dies August 1, 2026, and its features fold into Defender and Sentinel. Know which of your tools are products, not features.
Microsoft Defender Threat Intelligence reaches end of life on August 1, 2026. Every active MDTI subscription terminates that day. The capabilities don't disappear — they've been absorbed into Defender and Sentinel at no extra cost — but the SKU you're paying for stops existing in five days, and that distinction is the whole lesson.
What actually happened
Microsoft confirmed the final dates on July 23, 2026: the standalone MDTI SKU is retired, and all MDTI subscriptions end August 1, 2026. The product had already been pulled from the price list preview a year earlier.
The migration story is unusually painless. Every MDTI capability is now available through the Microsoft Defender portal to any customer with Microsoft Defender or Microsoft Sentinel, at no additional cost, and Microsoft states customers don't need to take migration action — the features are converging into Sentinel and Defender XDR. The money moves too: for CSP customers, Microsoft issues a credit memo to the partner account for any remaining subscription term past August 1, and the partner is responsible for passing that credit through. Enterprise Agreement customers get refunded directly by Microsoft.
Read that last part again if you buy through a reseller. Your refund routes through someone else's billing team.
Why vendor end-of-life matters for your business
This is the friendly version of a sunset — features preserved, money returned, a year of warning. Most aren't. The pattern underneath is the one to internalize: a capability you rely on can be a standalone product one quarter and a bundled feature the next, and the vendor decides which.
That has three practical consequences for a small operation. Your renewal calendar is not your risk register. MDTI subscribers who only look at spend would see a line item vanish and assume savings. The real question is whether the entitlement that replaces it — Defender or Sentinel — is one you actually hold. If you were an MDTI-only customer, "available to any customer with Defender or Sentinel" means you now need one of those. Bundled features get bundled roadmaps. A retired standalone product no longer has its own release cadence or its own support path; it inherits the parent's. And credits don't chase you. If a reseller sits between you and Microsoft, the credit memo is an action item on their side. Ask for it in writing before August 1.
The generalizable move is dull and effective: keep a list of every paid tool, what it does, and what the fallback is if it's discontinued tomorrow. Ten lines in a spreadsheet. It converts a surprise into a scheduled decision.
Key takeaways
- Microsoft Defender Threat Intelligence reaches end of life August 1, 2026 — the standalone SKU is retired and all subscriptions end that day
- MDTI capabilities are already available at no extra cost in the Defender portal to customers holding Microsoft Defender or Microsoft Sentinel; no migration action required
- CSP customers get a credit memo issued to their partner, who must pass it through — EA customers are refunded directly by Microsoft
- If a feature you depend on now requires a parent entitlement you don't own, the "free" absorption is a new purchase
Every tool in your stack is a bet that the vendor keeps selling it. We inventory what you're paying for, what it's actually doing, and what breaks if it's discontinued — then build the parts that matter on things you control. See how we approach it, or send us your tool list.
Sources: Microsoft Partner Center announcements, July 2026, Microsoft Defender Threat Intelligence blog.
- #vendor-risk
- #microsoft-defender
- #security-tools
- #eol
- #licensing
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
SGLang CVE-2026-86793: unauthenticated RCE on your GPU box
SGLang's SafeUnpickler can be bypassed through an unauthenticated endpoint for full RCE. No patch at disclosure. How to close it on a self-hosted inference server.
Read itAn AI agent swarm took 440 PaperCut servers
GreyNoise traced hundreds of AI agents compromising 440 PaperCut servers at 395 organizations in 48 countries. First RCE in under four hours. What it changes.
Read it