Microsoft's Integrated Security Operations Center (ISOC) in Defender started rolling out September 23, unifying XDR, SIEM, threat intelligence, automation and AI in one portal. This WWT brief explains what changed, how it completes the picture Project Perception and MDASH started, and what it means jumpstarting your security roadmap to be frontier ready. 

 

Two months ago, we wrote about Project Perception and made the case that the critical advantage of an AI-era defense isn't just the AI model, but the ecosystem built around it. It is the signals, the context layer, and the governance that decides what an agent is allowed to do and creates the operational experience to elevate your teams. Perception answered the "who does the work" question with red, blue and green agents. MDASH answered the "how do we find exposures affordably" question with a purpose-built model and harness to keep costs practical while retaining leading results. 

 

Starting September 23rd, Microsoft is answering the third question: where does all of this actually run and synergize? The Integrated Security Operations Center (ISOC) in Microsoft Defender is now in preview for eligible Microsoft 365 E5 and E7 (including G5) customers who don't have an active Sentinel workspace. ISOC folds XDR, SIEM, threat intelligence, automation, AI, and other enhancements; like Case Management, Playbook generator, UEBA;  into a single portal experience. This sets the Microsoft  platform up to support end-to-end defensibility of AI co-work, AI engineering, and defense with AI. For a meaningful slice of the mid-market and lower-enterprise base, this is the first time unified security operations is reachable without standing up Sentinel first. For the rest this is an easier path to being a frontier firm than a patchwork of point solutions. 

 

What changed 

 

Until now, "unified SecOps" in the Defender portal meant bringing Sentinel into Defender, which meant a Log Analytics workspace, workspace architecture decisions, and a cost model built around ingestion. ISOC changes the on-ramp. Eligible E5 and E7  customers can get XDR, SIEM-style investigation, threat intelligence and automation in one place inside Defender itself, without a Sentinel workspace. Case management, workbooks, natural-language playbook generation and enhanced automation rules work in Defender without any workspace. UEBA, threat intelligence, Content hub, CI/CD and Azure and third-party data require an ISOC workspace, with more than 500 connectors available. 

 

Microsoft's research puts a number on the cost of a fragmented SOC: 41% of alerts go uninvestigated due to capacity, according to the Microsoft and Omdia State of the SOC Report 2025. A lot of that capacity loss isn't analysts being slow, it's analysts moving between tools, queues, and consoles. ISOC is Microsoft's attempt to streamline your security operations foundation for your human team and eventually your human-agent team. 

 

Microsoft is explicit that agents depend on the rest of the stack working as one: signals and sensors for visibility, context that turns signals into understanding, and actuators that turn decisions into protection. Attack disruption in Defender is the working example. It acts on an attack while it is still unfolding and anticipates where the attacker may move next. ISOC's goal is to make that protection loop native. 

 

The new ISOC foundation ensures connectedness across people, agents, intelligence and controls. Without that, Perception's red, blue and green agents, and MDASH's vulnerability findings, are just more signals arriving in an already fragmented and oversaturated SOC. Microsoft describes this as a shift from a sequence of handoffs to a living system where the protect-detect-respond cycle has one operational experience.  

 

Why the data layer decides the economics 

Agents are only as good as the data they can reason over, and in a 24/7 SOC the cost of keeping that data is limited. The ISOC preview includes 30 days of retention for Defender data on the first phase and to be extended to 90 days in November. That is enough to evaluate, but it is not an enterprise retention policy. 

 

 Microsoft's answer is a tiered data model. Starting at Microsoft Ignite in November, the Sentinel data lake becomes a built-in, low-cost tier inside ISOC, with no separate onboarding. Teams will be able to send security data straight to the lake, or use Table Management in the Defender portal to extend retention on selected tables, so they can keep more history without paying analytics-tier rates for all of it. For advanced analytics such as jobs, notebooks and graphs, Microsoft is directing customers to Microsoft Fabric. Fabric connects to the lake through data mirroring rather than a second copy, and Fabric compute is billed separately. 

 

How ISOC brings the WWT Mythos response to life 

 

Microsoft's moves align with and help bring our WWT Mythos response (a twelve-point framework for defending at the speed of AI) to life. Four of those recommendations are no longer aspirational once Perception, MDASH and ISOC are running together. 

 

 WWT Mythos framework Recommendation four - compress remediation SLAs. Compressing an SLA without more headcount usually means the same people moving faster under more pressure. Today, agentic operations can change the math. Perception's red team agents and MDASH can help find and validate which exposures matter so defenders reduce the time spent validating or acting on findings. That improved focus frees time for your existing team to compress SLAs 

 

WWT Mythos framework Recommendation nine - shift from vulnerability management to exploit prevention. A vulnerability list ranked by CVSS score tells you what's theoretically exploitable in a vacuum. Perception's red team agents, continuously probing your actual environment the way an attacker would, helps clarify what's exploitable today, given your specific configurations and context. This enables security teams to shift from a general backlog of findings to deliberately closing real attack paths. 

 

WWT Mythos Recommendation seven, improve logging to empower AI for defense, and recommendation ten, use AI for defense, are where ISOC shines. ISOC unifies the signals, cases, data, and detections all while pricing optimizing cost. This is the context that Microsoft intends to unify human-agent teams to defend enterprises at scale and speed.  

 

Where to act now 

In most engagements, we have seen readiness, not technology, decide the outcome. If you are eligible, pilot ISOC against a bounded scenario: case management and generated playbooks on Defender data first, then one third-party source. If you currently run Sentinel, use this window for readiness. Phase 2 of this preview in Nov 2026 will incorporate eligibility for existing Sentinel instances to consider migrating to ISOC. 

 

Let's get started on your Microsoft Security transformation 

Preview is not the same as readiness. ISOC gives agentic defense a place to run, but the outcome still depends on three things: the signals you can feed it, the actions you are willing to let automation take, and how fast your team can act on what it finds. If your signals are fragmented, your agents will be too. 

The first step is a conversation. Reach out to your WWT account team to schedule an ISOC readiness session.

 

 

Sources: What's new in Microsoft Defender XDR (Microsoft Learn); Microsoft Security,

Reimagining the SOC for the agentic era in Microsoft Defender | Microsoft Security Blog

 

Omdia. State of the SOC: Unify Now or Pay Later: What New Research Reveals. Commissioned by Microsoft, 2025.

 

 

Technologies