Microsoft has confirmed that Microsoft Defender Threat Intelligence (MDTI) as a standalone SKU will reach end of life on August 1, 2026. For Cloud Solution Provider partners, the important point is not simply that a product is being retired. The bigger operational issue is that active standalone MDTI subscriptions will end, while the same threat intelligence capabilities are being made available through the Microsoft Defender portal for eligible Defender or Microsoft Sentinel customers.

The immediate partner task is not a technical migration project; it is a customer, billing, and expectation-management exercise. Partners should identify affected customers, explain where the capabilities will live going forward, and prepare billing teams to handle Microsoft credit memos for unused subscription periods after the retirement date.

What is changing

Microsoft is retiring the standalone MDTI SKU. The retirement date is August 1, 2026, when remaining subscriptions for that SKU are scheduled to end. Microsoft had already removed the SKU from price list preview on August 1, 2025, so this announcement effectively confirms the final endpoint for customers that still have active subscriptions.

The functionality itself is not disappearing for customers who use the broader Microsoft security stack. Microsoft says MDTI capabilities are now available at no additional cost in the Microsoft Defender portal for customers with Microsoft Defender or Microsoft Sentinel. In practical terms, this shifts MDTI from a separate commercial subscription into the experience and entitlement model of Microsoft’s integrated security products.

That distinction matters. A product retirement can sound like a loss of capability, but in this case partners should frame the message carefully: the standalone purchasing motion is ending, while the capabilities continue in the Defender and Sentinel ecosystem for eligible customers.

Why this matters for CSP partners

CSP partners need to manage two parallel tracks: service continuity and financial handling.

On the service side, customers may ask whether their security operations teams will lose access to threat intelligence data. Partners should confirm each customer’s current licensing position and help them understand how to access the capabilities through the Defender portal if they already have Microsoft Defender or Microsoft Sentinel. This is also a useful opportunity to review whether the customer’s SOC workflows, bookmarks, documentation, and training materials still point users to the correct experience.

On the commercial side, Microsoft has stated that CSP partners with customers holding active MDTI subscriptions will receive a credit memo for any remaining subscription term after August 1, 2026. The partner is responsible for passing the appropriate credit through to the end customer. That means finance and account teams should not treat this as a purely technical product update. It needs to be tracked like any other subscription retirement that creates downstream customer billing obligations.

For Enterprise Agreement or other Volume Licensing customers, Microsoft says it will handle refunds directly. CSP partners should still be ready to advise customers, but the refund process is different depending on the purchasing channel.

Default behavior and customer impact

The default outcome is straightforward: on August 1, 2026, standalone MDTI subscriptions end. Customers should not expect the standalone SKU to continue beyond that date.

For customers who already have Microsoft Defender or Microsoft Sentinel, Microsoft’s position is that no migration action is required because the capabilities are already available through the Microsoft Defender portal. However, “no migration action” should not be interpreted as “no partner action.” Customers may still need guidance to locate the experience, update internal operating procedures, revise support runbooks, or understand why a separate SKU is no longer being invoiced.

Customers without the relevant Defender or Sentinel entitlement need closer review. If they were relying on standalone MDTI, partners should validate their security requirements and recommend the appropriate Microsoft security licensing path. Do not wait until the retirement date to discover that a customer’s threat intelligence process depends on access patterns that no longer match their licensing.

Partner next steps

Start by building an inventory of all CSP customers with active MDTI subscriptions. Include renewal dates, remaining term, billing owner, customer success owner, and the customer’s current Microsoft Defender or Sentinel footprint. This allows the partner organization to separate customers that only need a communication from customers that may need a licensing or operational review.

Next, prepare a short customer-facing advisory. The message should explain that the standalone MDTI SKU is retiring on August 1, 2026, that MDTI capabilities are available through the Microsoft Defender portal for customers with Microsoft Defender or Microsoft Sentinel, and that any applicable CSP credit will be handled through the partner’s billing process. Keep the language simple and avoid making the retirement sound like an outage.

Billing teams should be briefed before the deprecation date. Microsoft will issue credit memos to the partner account for unused terms after August 1, 2026, and partners are responsible for passing those credits to customers. Define the internal process now: who identifies impacted invoices, who calculates the customer credit, who approves it, and how the adjustment is communicated.

Security and technical teams should review customer enablement materials. If customers have been using MDTI as a separate destination, update screenshots, portal navigation instructions, and SOC procedures to point to the Defender portal experience. Where customers use Microsoft Sentinel or Defender XDR, check whether existing playbooks and analyst workflows already reflect the converged experience.

Finally, use the change as a broader security roadmap conversation. Microsoft’s move reinforces the trend toward integrated threat intelligence inside Defender XDR and Sentinel rather than as a standalone SKU. Partners can help customers evaluate whether their detection, investigation, and response workflows are making full use of the capabilities now included in their security environment.

Bottom line

The MDTI retirement is not a last-minute technical migration, but it does require partner coordination. CSP partners should identify affected customers, explain the new access model, update operational guidance, and prepare to pass through any applicable credits after August 1, 2026. Customers with Microsoft Defender or Microsoft Sentinel should be able to continue using MDTI capabilities through the Defender portal, but clear communication will be essential to avoid confusion when the standalone subscription ends.

Microsoft source: MDTI reaches end of life August 1, 2026