As of August 1, 2026, Microsoft Threat Intelligence APIs in Microsoft Graph are available to customers with Microsoft Defender XDR and/or Microsoft Sentinel licensing. No separate Microsoft Defender Threat Intelligence API license is required.
This means we can bring Microsoft Threat Intelligence directly into SOC investigation and response workflows instead of keeping threat intelligence as something analysts only consume manually in the portal.
The available playbooks cover enrichment scenarios such as:
๐น Automated triage
๐น IP/domain reputation enrichment
๐น Passive DNS
๐น Reverse DNS
๐น Web components
๐น Trackers
๐น Cookies
The playbooks use Microsoft Graph to query threat intelligence data and can authenticate using Managed Identity with the ThreatIntelligence.Read.All application permission.
Source: r/AzureSentinel · by /u/EduardsGrebezs