Skip to content
Jussi Metso
Jussi Metso

It's all about The Cloud and The Security

  • Posts
  • About the blog
  • Activity
  • Connect!
  • Privacy Policy
Jussi Metso

It's all about The Cloud and The Security

September 23, 2026September 23, 2026

Microsoft ISOC – Integrated Security Operations Center

AI-powered attacks are increasing the speed and scale of cyber threats beyond what human-scale security operations can manage. To keep pace, organizations need a modern cyber stack that enables people and AI agents to work towards shared outcomes.

Today Sep 23rd 2026 Microsoft is announcing Integrated Security Operations Center (ISOC) in Microsoft Defender, bringing together industry-leading SIEM and XDR on a shared foundation across protection and operations and supports the shift from human-scale security to agent-scale security. ISOC enables people and agents to investigate, reason, and respond as one system, helping organizations
strengthen security today and build the foundation for the agentic SOC.

Get started with ISOC with Microsoft Defender

ISOC enables people and agents to investigate, reason, and respond as one system, to drive shared security outcomes and defend effectively against AI-powered attacks. It is the foundation for the agentic SOC.

This is phase 1 which is available all E5 and E7 customers who does not have Sentinel in use.

What this means to your organization?

Out-of-the-box

Here are five core SOC jobs whitc ISOC covers and what customer gets if using ISOC.

Integrated protection loop

With ISOC enabling signals, context, and controls to work as one, it breaks the pattern of linear security workflows. The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.

Attack disruption in Microsoft Defender disrupts threats in progress and anticipates where attackers may move next. It’s a protection loop that uses exposure insights to strengthen protection in near real-time with threat intelligence focusing the loop on the threats that matter most.

ISOC brings together the capabilities needed to make this loop native, eliminating the burden of assembling, tuning, and maintaining it yourself. And as protection advances, new capabilities can become part of that loop. The result is stronger protection and a different way of working, where practitioners spend less time chasing individual signals and more time applying judgment, setting priorities, and driving security outcomes.

Designed for the practitioner

For too long, practitioners have had to compensate for the boundaries in their security architecture, stitching together signals, rebuilding context, and moving between tools just to get the information and controls needed to act.

ISOC changes their starting point. The capabilities practitioners need to investigate, hunt, automate, manage incidents, understand threats, and take action are brought together and available by default. Instead of organizing their work around the boundaries between tools, teams can organize around the security outcome they are trying to achieve.

And that foundation gets more powerful as autonomy grows. The integrated protection loop can take on more of the continuous work of detecting and defending against threats, while agents help practitioners investigate, reason, and act using the same context and controls already available to them.

There’s no separate agentic layer to assemble or new operating model to stitch together. Practitioners can multiply their expertise where they already work, shifting more of their time from operating the security stack to directing the defense.

ISOC capabilities & features

ISOC lets eligible customers start with security operations capabilities built into Microsoft Defender and expand with additional data and capabilities when needed.

The following table summarizes the workspace requirements for the capabilities covered in this preview.

Capability set from MS Learn

ISOC pricing and data retention

Some pricing and retention info what will the cost be. Note:

Most of these come alive at Ignite as the slide says so.

ISOC features by Microsoft Security

ISOC enablement

When logging in to Defender (security.microsoft.com) you can see a new menu if  (you don’t have Sentinel in use). There are new functions in the menu (1):

Automation and Workbooks.

To enable ISOC you need to create a (Defender) workspace for it (2). For the workspace you need Azure subscription.

ISOC enablement SOURCE: Microsoft Security
ISOC enablement SOURCE: Microsoft Security
ISOC enablement SOURCE: Microsoft Security

ISOC Workbooks

You can  create and use workbooks with Integrated Security Operations Center (ISOC) in Microsoft Defender to create interactive dashboards that visualize and monitor security data by using advanced hunting queries.

Link for creating workbooks.

MDE workbook SOURCE: Microsoft Security

ISOC Automation

Use automation with Integrated Security Operations Center (ISOC) in Microsoft Defender to streamline security operations workflows and automate response actions.

Automation includes automation rules, Logic Apps-based playbooks, Playbook Generator, integration profiles, and enhanced alert trigger support.

First you need to create integration profiles which let you connect to Microsoft and third party solutions.

Link for automation overview.

ISOC Automation SOURCE: Microsoft Security

If you create AI generated playbooks the portal opens built-in vs code with cline.

When you give prompt with natural language the system then generates python file, documentation mark down file and json file for actual playbook which then can be edited and create a workflow logic.

ISOC playbook generation SOURCE: Microsoft Security
Editing automation logic SOURCE: Microsoft Security

What's next

Try this if you have E5 or E7 license and you don’t have Sentinel in your environment AND if you are eligible for it. (I really don’t know who are). 

This will be published to public preview for ALL customers with or without Sentinel in use.

Links

Microsoft Defender products and services

Reimaging the SOC for the agentic era in Microsoft Defender

Rethinking security for the age of AI

MS Learn documentation

AI SOC Whitepaper

Picture of Jussi Metso
Jussi Metso

Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future.

Share on Social Media
xfacebooklinkedinwhatsapp

Discover more from Jussi Metso

Subscribe to get the latest posts sent to your email.

SOC #defenderxdr#sentinel#soc

Post navigation

Previous post

Link to my MVP profile:

Subscribe my blog to get updates!

Join 42 other subscribers

Recent Posts

  • Microsoft ISOC – Integrated Security Operations Center
  • The PAW, PIM and the Conditional Access setup and some Entra ID attack vectors
  • Descriptions (& some instructions) for the Red Tenant
  • Enterprise Access Model (EAM) – part of Red tenant story
  • Red Forest: The predecessor of EAM

Top posts:

Defender for Cloud – Part 10: Cloud Workload protection (CWP)
NextGen Defender for Cloud: Phase 1 - public preview
Malware automated remediation in Defender for Storage
Defender for Cloud - Part 6: Attack Path Analysis
Defender for Cloud – Part 5: Security Alerts

Categories

  • AI (7)
  • AUTHOR (1)
  • BOOKREVIEW (1)
  • CSPM (2)
  • DATA SECURITY (1)
  • DEFENDER FOR CLOUD (19)
  • DEFENDER FOR DEVOPS (1)
  • entraid (1)
  • IDENTITY_ACCESS (3)
  • LEARNING (1)
  • MVP (1)
  • RED (3)
  • SECURITY (14)
  • SECURITYCOPILOT (1)
  • SENTINEL (5)
  • SOC (1)
  • THREAT INTELLIGENCE (1)
  • XDR (3)

Tags

#activedirectory (1) #architecture (1) #azure (1) #bookreview (2) #cloudsecurity (18) #condiftionalaccess (1) #defenderforcloud (2) #defenderforstorage (1) #defenderxdr (4) #entraid (1) #identityaccess (2) #malwarescan (1) #mdcseries (13) #mitreattack (1) #redforest (1) #redtenant (4) #securitycopilot (1) #sentinel (4) #siem (3) #soc (4) entraid (1) identityaccess (1)

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • June 2024
  • April 2024
  • January 2024
  • December 2023
  • October 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • January 2023
  • December 2022
  • November 2022

Visits on my site

27,735 hits

©2022-2026 Jussi Metso. All rights reserved.