Microsoft Corp. today unveiled Integrated Security Operations Center in Microsoft Defender as it rebuilds its security operations products around artificial intelligence agents.
The service moves security information and event management features from Microsoft Sentinel directly into Defender. ISOC is aimed at a problem Microsoft says is getting worse as attackers put agents to work.
“What once required entire teams now requires a single operator and an agent framework,” Rob Lefferts, corporate vice president of Microsoft Threat Protection, wrote in a blog post. Defenders fall behind, he argued, when protection and day-to-day operations run as separate systems and analysts have to piece incidents together by hand across several tools.
Several of the features ISOC brings over from Sentinel, including case management and workbooks, work in the Defender portal without any setup, according to Microsoft’s documentation. So does a feature that writes automation playbooks from plain-language instructions. However, some parts of ISOC, such as user and entity behavior analytics and the ability to bring in data from Azure and third-party sources, need extra setup.
Customers first have to create a dedicated ISOC workspace linked to an Azure subscription. More than 500 connectors are available for those outside sources, and Microsoft warns that ingestion charges may apply.
Microsoft is also pitching what it calls an integrated protection loop, where telemetry, exposure data and threat intelligence feed straight into Defender’s controls. Lefferts pointed to the existing attack disruption feature in Defender, which acts on an intrusion while it is still underway, as an example of that loop at work.
Much of the redesign is about agents, which in ISOC get the same signals, context and controls as a human analyst. Core security workflows are wired in by default, so an agent can investigate an incident and act on it without a separate operating model. The agents “depend on the rest of the stack working as one,” Lefferts wrote.
ISOC builds on Project Perception, the system Microsoft introduced in July together with MAI-Cyber-1-Flash, its first security model developed in-house. Project Perception agents still need human approval for high-stakes actions. People also set the priorities in Microsoft’s design, an approach Lefferts summed up as “strategy stays human.”
The ISOC public preview opens today to customers with Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 licenses. Organizations that already run an active Microsoft Sentinel workspace are excluded for now. Defender data is kept for 30 days at no extra charge during the preview, and Microsoft has not disclosed pricing. A Tech Community ask-me-anything session on the service is scheduled for Oct. 6.




