Microsoft Sentinel
Hunting and detection

Work with STIX objects and indicators to enhance threat intelligence and threat hunting in Microsoft Sentinel (Preview)

In brief

The article now documents migration to the ThreatIntelIndicators and ThreatIntelObjects schemas and states that ingestion into the legacy ThreatIntelligenceIndicator table stops after July 31, 2025.

What Defender admins need to know

Update custom queries, analytics and detection rules, workbooks, and automation to use the new tables by the deadline to avoid losing threat intelligence data.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.