Microsoft Previews Defender ISOC: SIEM-AI Agent Fusion Free for E5/E7, but Sentinel Users Wait Until Nov. 15
Microsoft's Integrated Security Operations Center, in public preview since Sept. 23, unifies SIEM and Defender threat protection so human analysts and AI agents work from one shared context; it ships at no extra license cost to Microsoft 365 E5/E7 customers.
Microsoft opened the Integrated Security Operations Center (ISOC) in public preview in Microsoft Defender on September 23, 2026, combining SIEM with native threat protection so human analysts and AI agents share signals, context, and actuators in a single system rather than rebuilding context across separate tools. ISOC runs a continuous 'integrated protection loop,' including Defender attack disruption that uses telemetry to interrupt threats in progress, with agents investigating continuously while practitioners set priorities; high-impact autonomous actions remain gated behind human approval. The platform builds on the Project Perception framework introduced in July 2026, which orchestrates red agents for attack-path discovery, blue agents for investigation, and green agents for remediation and hardening. Microsoft published a whitepaper on the agentic SOC model but gave no measured response-time or breach-reduction figures, no third-party connector list, and no general-availability date; the announcement is not tied to any specific breach or malware campaign. Commercially, ISOC is available to Microsoft 365 E5 and E7 customers without a separate Sentinel license: logs from Microsoft security products, Entra ID Protection, and Azure and Office 365 activity are ingested without charge, while third-party data costs $2.40 per GB from October 1. Retention is 30 days during preview, rising to 90 days on November 15; organizations already running Sentinel workspaces are excluded until they can optionally migrate on that date. Analysts said the bundle can simplify Microsoft-centric operations but increases vendor dependency, and warned that future SOC agents could be targeted through telemetry manipulation or prompt injection. The ISOC news appeared within Microsoft's broader September 2026 security roundup, which covered AI agent governance with new Microsoft Purview and Entra Global Secure Access protections for sensitive data in agentic traffic, and added Intune Enterprise Application Management, PKI, and remote help to GCC High and DoD environments.
- ISOC entered public preview in Microsoft Defender on September 23, 2026, unifying SIEM with native threat protection.
- Humans and AI agents share signals, context, and actuators in one operating foundation; high-impact agent actions require human approval.
- Builds on Project Perception (July 2026): red agents for attack-path discovery, blue for investigation, green for remediation.
- Integrated protection loop uses telemetry to disrupt attacks in progress; whitepaper 'Agentic SOC' accompanies the preview.
- Included for Microsoft 365 E5 and E7 customers with no separate Sentinel license.
- First-party logs (Microsoft security products, Entra ID Protection, Azure and Office 365 activity) ingested free; third-party data $2.40/GB from October 1, 2026.
- Retention is 30 days during preview, rising to 90 days on November 15, 2026; existing Sentinel customers excluded until an optional migration that day.
- No measured outcomes, connector list, or GA date published; not tied to a specific breach or malware campaign.
Coverage timelineoldest first · each row is one article
- · 3d agoReimagining the SOC for the agentic era in Microsoft Defender
Microsoft Security Blog· 46
Microsoft previews an integrated SOC in Defender that unifies SIEM and protection for agentic defense.
- · 3d agoMicrosoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
GBHackers· 46
Microsoft previews Defender ISOC, an AI-agent security operations platform for machine-speed attacks.
- · 2d agoMicrosoft Rebuilds the SOC with AI Agents, SIEM Integration and Machine-Speed Defense
Cyber Security News· 36