# Separate expired threat indicators from current action candidates in Defender threat analytics

> Why does the preview Indicators tab retain expired IOCs?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:09+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity
- Reading time: 2 minutes

## What you need to know

Why does the preview Indicators tab retain expired IOCs?

## Potentially affected

Verified tenants using the preview Indicators tab in Microsoft Defender threat analytics.

## DSE recommendation

Preserve an indicator's historical investigation purpose separately from any proposed current blocking decision.

## Article

## Source facts

The preview Indicators tab in Defender threat analytics lists indicators associated with a tracked threat. Microsoft researchers update the list as new evidence appears, but it also retains expired indicators to support investigation of past threats. Access to the tab requires tenant verification. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-xdr/threat-analytics).

## Applicability

Use this distinction when taking indicators from a threat report into an investigation or action review. Presence in that retained list should not be presented as an assertion that every entry has the same current operational status.

## DSE recommendation

Preserve an indicator’s historical investigation purpose separately from any proposed current blocking decision. Record the associated report, the indicator’s available status and the period the analyst intends to examine. Keep historical hunting inputs separate from the list awaiting present-day enforcement approval. Do not automatically promote every retained entry into a blocking configuration simply because it appears beside newer intelligence.

## Verification

Inspect the selected indicator and its report context before running a bounded historical query. Compare any result with the relevant observation time and document what the match actually establishes. If a current action is proposed, obtain the additional current context and approval needed for that decision instead of recycling the historical match as sufficient justification. Retain nonmatches and access limitations honestly; neither an expired entry nor an empty search is evidence that the environment was never affected. No hunt result or enforcement change is claimed here.

## Official references

[Microsoft Learn: Threat analytics Indicators preview](https://learn.microsoft.com/en-us/defender-xdr/threat-analytics). Source reviewed September 9, 2026.

## Primary reference

- Name: Threat analytics in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-xdr/threat-analytics
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate expired threat indicators from current action candidates in Defender threat analytics,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
