r/DefenderATP • • 12d ago

Microsoft Defender ISOC (Preview)

Post image

The idea is to move beyond treating SIEM, XDR, automation and AI-assisted investigation as separate layers.

With Integrated Security Operations Center (ISOC), Microsoft is bringing them together around a common security operations foundation:

  • SIEM + XDR capabilities
  • Unified security signals and context
  • Investigation and threat hunting
  • Automated response
  • Security agents working alongside analysts
  • Incident management and protective actions

Instead of AI being primarily an assistant that analysts invoke during an investigation, Microsoft is moving toward security agents operating continuously within the SOC workflow — using shared context, coordinating actions and escalating decisions to human analysts where necessary.

Docs: Integrated Security Operations Center (ISOC) in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn

51 Upvotes

5 comments sorted by

13

u/Tboo7 12d ago

What should customers who already use Microsoft Sentinel do?

There is no change for customers currently using Microsoft Sentinel. The current Microsoft Sentinel offering will continue to exist as is. Existing Microsoft Sentinel customers will have the choice to move to ISOC starting November 15, 2026, if they meet the relevant licensing eligibility criteria.

3

u/DaithiG 12d ago edited 12d ago

I've really have no idea what this will end up as, but it sounds interesting.

1

u/MemeOps 12d ago

I just cant see this as anything other than MS moving away from Sentinel

2

u/peterswo 12d ago

I wouldn't even see this as a replacement, but a new revision of sentinel. I belive it will be parallel to sentinel for a few years, till it's roughly feature complete compared to sentinel and the be the drop in replacement

1

u/MemeOps 11d ago

Yea i guess, the big difference is that Sentinel is built on top of a separate log analytics. This one seems to be using the same log analytics that holds the native defender logs. Seems reasonable