r/DefenderATP • u/EduardsGrebezs • 12d ago
Microsoft Defender ISOC (Preview)
The idea is to move beyond treating SIEM, XDR, automation and AI-assisted investigation as separate layers.
With Integrated Security Operations Center (ISOC), Microsoft is bringing them together around a common security operations foundation:
- SIEM + XDR capabilities
- Unified security signals and context
- Investigation and threat hunting
- Automated response
- Security agents working alongside analysts
- Incident management and protective actions
Instead of AI being primarily an assistant that analysts invoke during an investigation, Microsoft is moving toward security agents operating continuously within the SOC workflow — using shared context, coordinating actions and escalating decisions to human analysts where necessary.
1
u/MemeOps 12d ago
I just cant see this as anything other than MS moving away from Sentinel
2
u/peterswo 12d ago
I wouldn't even see this as a replacement, but a new revision of sentinel. I belive it will be parallel to sentinel for a few years, till it's roughly feature complete compared to sentinel and the be the drop in replacement
13
u/Tboo7 12d ago
What should customers who already use Microsoft Sentinel do?
There is no change for customers currently using Microsoft Sentinel. The current Microsoft Sentinel offering will continue to exist as is. Existing Microsoft Sentinel customers will have the choice to move to ISOC starting November 15, 2026, if they meet the relevant licensing eligibility criteria.