Cases Overview
In brief
The documentation now states that MDTI projects are deprecated and directs users to link threat indicators to cases in the Microsoft Defender portal.
What Defender admins need to know
Administrators using projects should plan to organize and investigate indicators through cases instead.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
description: Learn about the case management capabilities in the Defender portal for managing and standardizing unified security operations.
author: mberdugo
ms.author: monaberdugo
ms.date: 05/04/202507/31/2026
ms.collection:
- M365-security-compliance
- tier1
Link indicators (preview)
Linking a case to relevant indicators of compromise (IOCs) helps your SecOps teams understand the broader context of a threat.
To link the case to IOCs, go to the Linked Objects tab in the Case page and select Indicators. Then, select the Add button and the workspace the TI Indicator is in. Select the wanted TI Indicator and click on Link.
Linking a case to relevant indicators of compromise (IOCs) helps your SecOps teams understand the broader context of a threat.
To link the case to IOCs, go to the Linked Objects tab in the Case page and select Indicators. Then, select the Add button and the workspace the TI Indicator is in. Select the wanted TI Indicator and click on Link.
@@ -3,7 +3,7 @@ title: Manage security operations cases natively in the Microsoft Defender porta description: Learn about the case management capabilities in the Defender portal for managing and standardizing unified security operations. author: mberdugo ms.author: monaberdugo-ms.date: 05/04/2025+ms.date: 07/31/2026 ms.collection: - M365-security-compliance - tier1@@ -129,6 +129,9 @@ Alternatively, if the IR team needs to escalate one or more incidents to the hun #### Link indicators (preview) +> [!IMPORTANT]+> Projects in Microsoft Defender Threat Intelligence are deprecated. To organize and investigate threat indicators, link indicators to a case in the Microsoft Defender portal.+ Linking a case to relevant indicators of compromise (IOCs) helps your SecOps teams understand the broader context of a threat. To link the case to IOCs, go to the **Linked Objects** tab in the Case page and select **Indicators**. Then, select the **Add** button and the workspace the TI Indicator is in. Select the wanted TI Indicator and click on **Link**. 