Microsoft previews ISOC in Defender as shared runtime for AI-driven security operations


Agentic SOC
Microsoft is positioning ISOC as a shared operational foundation where analysts and AI agents use the same signals, context and controls.
Preview limits
The ISOC preview is available to eligible Defender Suite, Microsoft 365 E5 and Microsoft 365 E7 customers without an active Sentinel workspace.
Cost check
Defender data gets 30 days of included retention in this preview, but broader ingestion through more than 500 connectors requires an ISOC workspace and may add charges.
Microsoft is moving more of the security operations center into Microsoft Defender with the September 23 preview of Integrated Security Operations Center, or ISOC. The product experience is designed to combine SIEM, threat protection, case management, automation and AI-agent workflows on a shared foundation for analysts and machines.1
The launch is Microsoft’s clearest attempt yet to recast the SOC as an integrated runtime for agentic security, rather than a collection of dashboards, queues and handoffs. The company said ISOC brings security information and event management and threat protection together so people and agents can use the same signals, context and controls to detect, investigate and respond across an environment.1
The preview is available to eligible customers with Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 that do not already have an active Microsoft Sentinel workspace. Microsoft’s documentation cautions customers with an active Sentinel workspace to continue using their existing Sentinel experience during the preview, rather than disconnecting production workspaces to qualify.2
The preview includes several Defender-native security operations capabilities that do not require an ISOC workspace, including case management, workbooks, enhanced automation rules and natural-language playbook generation.2 Workspace-dependent features, including user and entity behavior analytics, Content hub, CI/CD repositories, threat intelligence and ingestion of Azure or third-party security data, require an ISOC workspace.2
That distinction matters for enterprise security teams evaluating the preview. ISOC is not simply a rebrand of a traditional Sentinel deployment inside a new interface. Microsoft says eligible customers can start with security operations capabilities built into Defender, then add data and capabilities when needed.2 Independent coverage described the move as bringing Sentinel capabilities such as case management, threat intelligence, workbooks and automation into Defender, with the goal of giving analysts and AI agents common operational context.8
During the preview, eligible customers receive 30 days of included retention for supported Defender data. Additional Microsoft and non-Microsoft data can be brought in through more than 500 connectors, but Microsoft says an ISOC workspace is required for broader ingestion and that additional ingestion charges may apply.6 SiliconANGLE reported that Microsoft has not disclosed broader ISOC pricing and that organizations with active Sentinel workspaces are excluded from the first public preview phase.7
Microsoft’s argument is that agents cannot work reliably when the underlying security stack is fragmented. In its launch post, the company said agents need signals and sensors, context and actuators that work in unison, rather than separate protection and operations systems connected by handoffs.1
That framing separates ISOC from the more common pattern of adding an AI assistant to an existing dashboard. In a bolt-on model, the agent still has to cross the same product boundaries analysts do: SIEM alerts in one place, endpoint controls in another, case notes somewhere else and automation rules in a separate workflow engine. ISOC’s design instead puts the agent and analyst in the same operational plane, with shared cases, evidence, automation triggers and response actions.135
Case management is central to that model. Microsoft’s documentation describes cases as work items that bring together investigation context, collaboration, tasks, evidence, activity history and workflow tracking inside Defender.3 Incident cases can include attack story, alerts, assets, investigations, evidence, activities and response actions. They can also include agentic sessions whose status and outputs are visible from the case experience.3
Automation is also moving closer to the case and alert model. Enhanced automation rules can run supported actions when alerts or cases match defined conditions. Available triggers include alert creation, case creation and case updates. Available actions can include running generated playbooks, updating cases, sending case emails or creating case tasks, depending on the trigger.5
For SOC leaders, the preview should be treated as an evaluation environment, not a blanket endorsement of automated investigation and response. Microsoft’s documentation emphasizes that preview capabilities and availability can change. The playbook generator also requires users to review, test and activate generated playbooks before using them in automation rules.24
The first proof point should be workflow observability. Teams should confirm that every automated action creates a durable record tied to the case, including which rule fired, which conditions matched, what playbook ran, what identity or integration profile was used and what the result was. Microsoft says case management supports comments, activity history, attachments, RBAC and auditing through Log Analytics, while generated playbook results can be reviewed in activity logs or case artifacts.34
The second proof point should be human control over blast radius. Microsoft’s playbook documentation says generated playbooks are created from natural language, but users must review the plan, approve proposed file changes, test execution and manually validate generated code.4 That is especially important because playbooks can connect to Microsoft and third-party APIs through integration profiles and can perform case actions such as changing status, assigning ownership or adding comments.4
The third proof point should be repeatability under failure. Security teams should test what happens when enrichment APIs fail, connector permissions are missing, identity permissions have not propagated, a playbook times out or an automation rule matches more broadly than intended. Microsoft documents limits including Python-only playbook authoring, no external libraries, a 10-minute runtime limit per playbook, up to 100 playbooks per tenant and up to 500 active automation rules per tenant.4
The fourth proof point should be data coverage and cost visibility. ISOC can begin with Defender data, but broader visibility across cloud, identity, network and third-party telemetry requires workspace-backed ingestion. Microsoft says an ISOC workspace is needed for more than 500 additional connectors and that ingestion charges may apply, making architecture and cost modeling part of any production evaluation.6
The launch is already drawing services around deployment and adoption. BlueVoyant announced a Microsoft Defender XDR ISOC Deployment Service on the same day as the preview, describing ISOC as combining SIEM and XDR in Defender with shared signals, context and controls for security teams and AI agents.9
That partner response points to a practical reality for enterprises: the hardest part may not be turning on the preview, but redesigning operating procedures, access controls, test plans and incident review processes around agents that can participate in investigations. Redmondmag reported that Microsoft is positioning unified telemetry, threat intelligence and controls as prerequisites for effective agentic security, while analysts remain involved in steering work and applying judgment.8
ISOC gives Microsoft customers a preview of a SOC model in which cases, automation and agent sessions are not sidecars to the SIEM, but part of the same operating fabric. That could reduce tool switching and make it easier to prove what happened during an investigation, provided the organization carefully configures retention, RBAC, logging and workflow controls.
But the preview also sets a higher bar for evidence. Before trusting automated investigation and response, enterprise teams should require end-to-end auditability, clear approval boundaries, reproducible test results, connector-level data lineage, measurable false-positive handling and rollback procedures. The operational promise of ISOC is that agents and analysts work from the same foundation. The operational risk is that a shared foundation can also scale mistakes faster if guardrails are weak.
For now, Microsoft has shipped the opening layer of that model: a Defender-based preview that moves core SOC work closer to the controls that can act on threats. Whether it becomes a trusted agentic SOC platform will depend less on the presence of AI features than on the evidence customers can collect that those features behave predictably under real incident conditions.

OpenAI’s ChatGPT Ads app for Shopify expanded internationally on September 23 in supported markets, bringing catalog sync, Shopify-based campaign launch and commerce-event measurement into the ad setup. The rollout comes as Sponsored Agents test a more explicit boundary between ordinary ChatGPT answers and paid, brand-run conversations.

F5 has released fixes for CVE-2026-94127, a critical BIG-IP APM flaw exploited in remote code execution attacks against deployments configured as OAuth Authorization Servers. Operators should verify whether access-policy and OAuth-profile virtual servers are exposed, apply the correct hotfix or F5 iRule mitigation, and review systems for correlated indicators of compromise.

Qualcomm is positioning Snapdragon X2 PCs as a platform for agentic AI that can run locally, span phones and laptops, and expand beyond Windows into Googlebook and Linux systems. The engineering case is credible but incomplete: NPUs, Ubuntu support and device continuity reduce friction, while model limits, software integration and cloud handoffs remain decisive.

At Connect 2026, Meta split its glasses strategy across audio-only AI, camera-equipped capture glasses, display glasses and 100-gram VR glasses. The result is a clearer product ladder, but also a sharper set of tradeoffs around cameras, displays, immersion and privacy.
ISOC
Integrated Security Operations Center, Microsoft’s new Defender preview experience combining SIEM, XDR, automation, case management and AI-agent workflows.
SIEM
Security information and event management, a system for collecting, correlating and analyzing security telemetry and alerts.
XDR
Extended detection and response, a security approach that correlates signals and response actions across endpoints, identity, email, cloud and other controls.
Playbook
An automated response workflow that can enrich alerts, update cases, call APIs or perform other predefined actions when triggered.
Comments