Microsoft Sentinel
Developer and API

Connect Mdti Data Connector

In brief

The documentation now explicitly identifies intelligence ingested from the Defender Threat Intelligence connector, while updating related links and page metadata.

What Defender admins need to know

Administrators have clearer guidance for using ingested intelligence in analytics rules and locating it in the ThreatIntelIndicators table.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. When the data starts to flow into your Microsoft Sentinel workspace, the connector status changes to Connected.

After the connector status displays Connected, threat intelligence ingested from the ingested intelligenceDefender Threat Intelligence data connector is available for use in the TI map... analytics rules. For more information, see Use threat indicators in analytics rules.

Find the newthreat intelligence ingested from the Defender Threat Intelligence connector in the management interface or directly in Logs by querying the ThreatIntelIndicators table. For more information, see Work with threat intelligence.

Related content

After you connect the Defender Threat Intelligence data connector, explore these resources to learn more: