Microsoft’s retirement of the Microsoft Deployment Toolkit (MDT) caught many IT teams off guard. No transition timeline. No direct replacement. Just a support end date and a growing security problem for organisations still relying on it.
If MDT is still part of your deployment workflow, this is worth your attention. Running unsupported software doesn’t just create operational headaches – it opens the door to real, exploitable vulnerabilities. And in Australia’s current threat environment, that’s a risk worth taking seriously.
What happened with MDT?
MDT was a widely used, free Microsoft tool that helped IT teams automate operating system and application deployments. It was powerful, flexible, and deeply embedded in the workflows of organisations large and small.
Then, in early 2026, Microsoft quietly confirmed what many had suspected: MDT was being retired. No patches. No updates. No ongoing support. As The Register reported, the news landed with a thud for IT administrators who had built years of deployment processes around the tool.
The problem wasn’t just losing a familiar tool. TechRadar noted that MDT had a loyal following precisely because it worked well. But loyalty to a tool doesn’t protect you from what happens when that tool stops receiving security updates.
The security risk hiding in your deployment workflow
MDT’s vulnerability is simple: It communicates sensitive data – including credentials – in plain text during the deployment process.
When MDT was actively maintained, Microsoft could patch vulnerabilities as they emerged. Now that support has ended, any new weakness that surfaces will stay there. Permanently.
A malicious actor who intercepts MDT traffic during a deployment could capture credentials and use them to move laterally across your environment. That’s not a theoretical risk. It’s a well-understood attack vector, and it’s now sitting unpatched in any organisation still running MDT.
This matters even more when you consider the speed at which attackers operate. According to the CrowdStrike 2026 Global Threat Report, the fastest recorded eCrime breakout time is just 27 seconds – the time it takes an attacker to move from initial access to lateral movement across a network.
On top of that, 82% of detections in 2025 were malware-free, meaning attackers are increasingly using legitimate credentials and tools rather than malware. A plain-text credential exposure during an MDT deployment is exactly the kind of foothold they’re looking for.
Why this is especially urgent for Australian organisations
Australia is a high-value target. According to the Microsoft Digital Defence Report, Australia ranked among the countries most frequently impacted by cyber activity globally – tenth overall, and fourth across Asia and the Pacific.
The volume of incidents reflects this. In FY2024–25, the Australian Signals Directorate (ASD) handled over 84,700 reports of cybercrime – approximately one every six minutes – and addressed more than 1,200 cybersecurity incidents.
The ASD’s Annual Cyber Threat Report puts the average self-reported cost of cybercrime to Australian businesses at $80,850, up 50% overall. For large businesses, that figure jumped to $202,700 – a 219% increase year on year.
These aren’t distant statistics. They reflect what’s happening to organisations like yours, right now.
What you should do about it
Running an unsupported tool in your environment is a compliance risk as much as a security one. If your organisation is subject to frameworks like the Essential Eight, ISO 27001, or industry-specific regulations, continuing to use MDT without mitigation could put you in breach.
The good news is that there are solid alternatives. Microsoft’s recommended path forward is Windows Autopilot combined with Microsoft Intune – a cloud-native approach to device provisioning that removes the plain-text credential risk entirely.
For organisations with more complex on-premises requirements, Microsoft Configuration Manager (SCCM) remains a supported option.
The good news is that there are solid alternatives. Microsoft’s recommended path forward is Windows Autopilot combined with Microsoft Intune – a cloud-native approach to device provisioning that removes the plain-text credential risk entirely.
That said, migrating away from MDT isn’t always straightforward. If your deployment workflows are heavily customised, the transition takes planning. It’s worth auditing your current MDT usage, identifying which deployment tasks still depend on it, and mapping those tasks to supported alternatives before you hit a security incident that forces your hand.
A reminder: Effective cybersecurity also goes beyond patching high-risk vulnerabilities. Legacy tools like MDT represent exactly the kind of overlooked gap that attackers exploit – not because the vulnerability is high-profile, but because it’s sitting quietly in the background while your team focuses on more visible threats.
The tension between security and operational continuity
We understand the hesitation. Replacing an embedded tool mid-cycle is disruptive. Teams are busy. Budgets are constrained. And MDT still technically works – it just won’t be patched if something goes wrong
As we’ve written before, the tension between security and usability is one of the biggest challenges in the modern workplace. But staying on an unsupported tool because migration feels complex is a short-term calculation with long-term consequences. The costs of a breach – financial, operational, and reputational – far outweigh the cost of a planned transition.
Staying across these shifts is genuinely difficult, especially when changes happen without much warning. That’s where having a partner who tracks these updates becomes valuable. You shouldn’t need to monitor every Microsoft announcement to know when your deployment stack becomes a liability.
Time to move forward
If you’re still running MDT, now is the time to assess your exposure and start planning the migration. The risk is real, the alternatives are mature, and the threat environment isn’t getting quieter.
The team at Endpoint Focus works with organisations across Australia to manage exactly these kinds of transitions – from legacy tool dependencies to fully cloud-managed device deployment. If you’d like a practical conversation about what moving away from MDT looks like for your environment, get in touch.




