Skip to content
DnsLister Forum

Where domain hunters compare notes

Microsoft Defender Threat Intelligence APIs are now available without a separate MDTI license

As of August 1, 2026, Microsoft Threat Intelligence APIs in Microsoft Graph are available to customers with Microsoft Defender XDR and/or Microsoft Sentinel licensing. No separate Microsoft Defender Threat Intelligence API license is required.

This means we can bring Microsoft Threat Intelligence directly into SOC investigation and response workflows instead of keeping threat intelligence as something analysts only consume manually in the portal.

The available playbooks cover enrichment scenarios such as:
๐Ÿ”น Automated triage
๐Ÿ”น IP/domain reputation enrichment
๐Ÿ”น Passive DNS
๐Ÿ”น Reverse DNS
๐Ÿ”น Web components
๐Ÿ”น Trackers
๐Ÿ”น Cookies

The playbooks use Microsoft Graph to query threat intelligence data and can authenticate using Managed Identity with the ThreatIntelligence.Read.All application permission.

https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Defender%20Threat%20Intelligence/Playbooks/readme.md

Docs: https://learn.microsoft.com/en-us/graph/api/resources/security-threatintelligence-overview?view=graph-rest-1.0

Source: r/AzureSentinel · by /u/EduardsGrebezs

Leave a Reply

Your email address will not be published. Required fields are marked *