Microsoft integrates SOC capabilities with Defender for enterprises
Microsoft is previewing Defender ISOC, bundling SIEM into Microsoft 365 E5 and E7 without an extra license.
Microsoft opened a public preview of the Integrated Security Operations Center in Microsoft Defender on September 23, letting Microsoft 365 E5 and E7 customers use SIEM capabilities without a separate Sentinel license. Logs from Microsoft security products, Entra ID Protection, and Azure and Office 365 activity are included without ingestion charges, while third-party data costs $2.40 per GB from October 1. Retention is 30 days during preview and rises to 90 days on November 15; organizations already running Sentinel are excluded until they can opt to move on that date. Analysts said the bundle can simplify Microsoft-centric operations but increases vendor dependency, and warned that future SOC agents could be targeted through telemetry manipulation or prompt injection.