September 23, 2026September 23, 2026 Microsoft ISOC – Integrated Security Operations Center AI-powered attacks are increasing the speed and scale of cyber threats beyond what human-scale security operations can manage. To keep pace, organizations need a modern cyber stack that enables people and AI agents to work towards shared outcomes.Today Sep 23rd 2026 Microsoft is announcing Integrated Security Operations Center (ISOC) in Microsoft Defender, bringing together industry-leading SIEM and XDR on a shared foundation across protection and operations and supports the shift from human-scale security to agent-scale security. ISOC enables people and agents to investigate, reason, and respond as one system, helping organizations strengthen security today and build the foundation for the agentic SOC.Get started with ISOC with Microsoft DefenderISOC enables people and agents to investigate, reason, and respond as one system, to drive shared security outcomes and defend effectively against AI-powered attacks. It is the foundation for the agentic SOC.This is phase 1 which is available all E5 and E7 customers who does not have Sentinel in use. What this means to your organization? Out-of-the-box Here are five core SOC jobs whitc ISOC covers and what customer gets if using ISOC. Integrated protection loop With ISOC enabling signals, context, and controls to work as one, it breaks the pattern of linear security workflows. The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.Attack disruption in Microsoft Defender disrupts threats in progress and anticipates where attackers may move next. It’s a protection loop that uses exposure insights to strengthen protection in near real-time with threat intelligence focusing the loop on the threats that matter most.ISOC brings together the capabilities needed to make this loop native, eliminating the burden of assembling, tuning, and maintaining it yourself. And as protection advances, new capabilities can become part of that loop. The result is stronger protection and a different way of working, where practitioners spend less time chasing individual signals and more time applying judgment, setting priorities, and driving security outcomes. Designed for the practitioner For too long, practitioners have had to compensate for the boundaries in their security architecture, stitching together signals, rebuilding context, and moving between tools just to get the information and controls needed to act.ISOC changes their starting point. The capabilities practitioners need to investigate, hunt, automate, manage incidents, understand threats, and take action are brought together and available by default. Instead of organizing their work around the boundaries between tools, teams can organize around the security outcome they are trying to achieve.And that foundation gets more powerful as autonomy grows. The integrated protection loop can take on more of the continuous work of detecting and defending against threats, while agents help practitioners investigate, reason, and act using the same context and controls already available to them.There’s no separate agentic layer to assemble or new operating model to stitch together. Practitioners can multiply their expertise where they already work, shifting more of their time from operating the security stack to directing the defense. ISOC capabilities & features ISOC lets eligible customers start with security operations capabilities built into Microsoft Defender and expand with additional data and capabilities when needed.The following table summarizes the workspace requirements for the capabilities covered in this preview. Capability set from MS Learn ISOC pricing and data retention Some pricing and retention info what will the cost be. Note:Most of these come alive at Ignite as the slide says so. ISOC features by Microsoft Security ISOC enablement When logging in to Defender (security.microsoft.com) you can see a new menu if (you don’t have Sentinel in use). There are new functions in the menu (1):Automation and Workbooks.To enable ISOC you need to create a (Defender) workspace for it (2). For the workspace you need Azure subscription. ISOC enablement SOURCE: Microsoft Security ISOC enablement SOURCE: Microsoft Security ISOC enablement SOURCE: Microsoft Security ISOC Workbooks You can create and use workbooks with Integrated Security Operations Center (ISOC) in Microsoft Defender to create interactive dashboards that visualize and monitor security data by using advanced hunting queries.Link for creating workbooks. MDE workbook SOURCE: Microsoft Security ISOC Automation Use automation with Integrated Security Operations Center (ISOC) in Microsoft Defender to streamline security operations workflows and automate response actions.Automation includes automation rules, Logic Apps-based playbooks, Playbook Generator, integration profiles, and enhanced alert trigger support.First you need to create integration profiles which let you connect to Microsoft and third party solutions.Link for automation overview. ISOC Automation SOURCE: Microsoft Security If you create AI generated playbooks the portal opens built-in vs code with cline.When you give prompt with natural language the system then generates python file, documentation mark down file and json file for actual playbook which then can be edited and create a workflow logic. ISOC playbook generation SOURCE: Microsoft Security Editing automation logic SOURCE: Microsoft Security What's next Try this if you have E5 or E7 license and you don’t have Sentinel in your environment AND if you are eligible for it. (I really don’t know who are). This will be published to public preview for ALL customers with or without Sentinel in use. Links Microsoft Defender products and servicesReimaging the SOC for the agentic era in Microsoft DefenderRethinking security for the age of AIMS Learn documentationAI SOC Whitepaper Jussi Metso Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. Share on Social Mediaxfacebooklinkedinwhatsapp Discover more from Jussi Metso Subscribe to get the latest posts sent to your email. Type your email… Subscribe SOC #defenderxdr#sentinel#soc