To use a part of MDTI data to analyze our customers log in our SIEM is acceptable in Microsoft terms?

nuta 0 Reputation points
2026-09-17T02:11:12+00:00

We would like to extract MDTI indicators (malicious IPs/domains) through Microsoft Graph API, store them in our SIEM not on Azure, and correlate them with customer logs for threat detection. We will not redistribute or resell the MDTI indicator feed itself. Is this usage permitted under the MDTI license terms?

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.