Uses Microsoft's threat intelligence feed to flag traffic involving known malicious domains and IP addresses. Every Azure Firewall SKU can raise alerts; only Standard and Premium can block the traffic as well.
Also called Threat intelligence.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Threat intelligence-based filtering in context, with comparison tables and the common traps.
Terms in this definition
- Azure Artifacts feed
Holds packages (Cargo, Universal, Python, Maven, npm, NuGet) in Artifacts; it belongs to a project or the organisation and supports views, feed roles and upstreams.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- SKU
The size or tier of a service, for example a VM size or the Premium tier of ACR.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
Related terms
- AZFWThreatIntel
Log Analytics table, in resource-specific mode, where Azure Firewall writes events raised by threat intelligence.
- Azure Firewall Standard
Mid-level Azure Firewall SKU: it filters with application and network rules, can block known-bad addresses using threat intelligence and acts as a DNS proxy. Inspecting TLS traffic and IDPS are Premium-only.
- Ingestion rules
Threat intelligence rules that drop or modify objects as they arrive and before they're saved, such as discarding indicators with low confidence or lengthening how long they stay valid.
- Intel explorer
Where analysts in the Microsoft Defender portal go to search threat intelligence by type, whether a threat actor, campaign, indicator, tool or vulnerability. Threat analytics reports can be opened from there as well.
- Microsoft Defender for AI Services
Plan within Defender for Cloud that uses threat intelligence and Prompt Shields to alert in real time when generative AI applications come under attack.
- Microsoft Defender Threat Intelligence
Also called MDTI: Microsoft's library of threat actors, articles and indicators. Since its own portal and SKU were retired on 1 August 2026, you get the same features at no extra charge under Threat intelligence in the Defender portal, and Sentinel can ingest its indicators through a connector.
- Microsoft Sentinel graph
Treats your security data as a web of connected entities, such as users, devices, resources and activities, alongside threat intelligence. Blast radius and the hunting graph are built on it, and custom graphs produced by an on-demand job are kept for 30 days.
- Microsoft Threat Intelligence Analytics
A Microsoft Sentinel rule built from a template that cannot be edited. It checks Windows DNS, CEF and Syslog data for matches with indicators from Microsoft's threat intelligence and raises high-fidelity alerts when it finds them.
See Threat intelligence-based filtering in the full glossary