MC1220762 High Major change
(Updated) Retirement notice: MDE and XDR Advanced Hunting APIs retiring; migrate to Microsoft Graph Security API
Summary AI-generated
MDE and Defender XDR Advanced Hunting APIs retire Feb 2027; migrate workflows to Microsoft Graph Security API by Jan 31, 2027 to avoid disruption.
Suggested actions AI-generated
- Identify uses of retiring APIs
- Update scripts and automations to Graph Security API
- Notify security and development teams
- Validate queries with new API
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1077861 (Updated) Microsoft Defender for Cloud Apps: SIEM agents will retire
- MC1187386 Microsoft Defender for Identity alerts transitioning to XDR-based detection platform
- MC1227454 Exchange Web Services (EWS) retirement update
- MC1192257 (Updated) Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel
- MC1217649 Endpoint DLP-sensitive data alerting retiring in Defender; use Purview DLP
- MC1254554 Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps
Original post from Microsoft
Updated January 26, 2026: We have updated the content. Thank you for your patience.
[Introduction]
We’re retiring the Microsoft Defender for Endpoint (MDE) Advanced Hunting API and Microsoft Defender XDR Advanced Hunting API and transitioning customers to the Microsoft Graph Security API. This update aligns our security integrations with a unified interface and schema across Microsoft Defender products. The Microsoft Graph Security API provides broader data coverage, improved consistency, and better scalability for automation and security workflows.
[When this will happen]
- Retirement start: February 6, 2026
- Full retirement: February 1, 2027
- After February 1, 2027, the MDE and XDR APIs will no longer function.
[How this affects your organization]
Who is affected:
- Organizations using the MDE or XDR Advanced Hunting API for automation, integration, or custom workflows.
- You are receiving this message because our reporting indicates your organization may be using these APIs.
What will happen:
- The MDE and XDR Advanced Hunting APIs will stop functioning after February 1, 2027.
- Existing scripts, automations, and workflows that rely on these APIs will fail if not updated.
- The Microsoft Graph Security API will be the supported API for accessing Microsoft security data.
- No automatic migration will occur; manual updates will be required.
[What you can do to prepare]
- Migrate all existing API workflows to the Microsoft Graph Security API by January 31, 2027.
- Update internal documentation, automation scripts, and integration endpoints to use the Microsoft Graph Security API.
- Communicate these changes to your security operations, engineering, and development teams.
- Review Microsoft documentation to plan your migration: Use the Microsoft Graph security API.
- If your organization uses custom solutions, validate that new queries and response schemas work as expected before the retirement date.
Learn more:
- Advanced hunting - Use the Microsoft Graph security API | Microsoft Graph | Microsoft Learn
- Migrate from the older APIs - Use the Microsoft Graph security API | Microsoft Graph | Microsoft Learn
- (to be retired) Advanced Hunting API - Microsoft Defender for Endpoint | Microsoft Learn
- (to be retired) Microsoft Defender XDR advanced hunting API - Microsoft Defender XDR | Microsoft Learn
[Compliance considerations]
No compliance considerations identified. Review as appropriate for your organization.
Additional details from Microsoft
- Summary
- Microsoft is retiring the Microsoft Defender for Endpoint and Defender XDR Advanced Hunting APIs by February 1, 2027. Organizations must manually migrate workflows to the Microsoft Graph Security API by January 31, 2027, to ensure continued functionality and improved security integration.