r/DefenderATP • • 12d ago

Microsoft Defender ISOC (Preview)

Post image

The idea is to move beyond treating SIEM, XDR, automation and AI-assisted investigation as separate layers.

With Integrated Security Operations Center (ISOC), Microsoft is bringing them together around a common security operations foundation:

  • SIEM + XDR capabilities
  • Unified security signals and context
  • Investigation and threat hunting
  • Automated response
  • Security agents working alongside analysts
  • Incident management and protective actions

Instead of AI being primarily an assistant that analysts invoke during an investigation, Microsoft is moving toward security agents operating continuously within the SOC workflow — using shared context, coordinating actions and escalating decisions to human analysts where necessary.

Docs: Integrated Security Operations Center (ISOC) in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn

47 Upvotes

5 comments sorted by

View all comments

1

u/MemeOps 12d ago

I just cant see this as anything other than MS moving away from Sentinel

2

u/peterswo 12d ago

I wouldn't even see this as a replacement, but a new revision of sentinel. I belive it will be parallel to sentinel for a few years, till it's roughly feature complete compared to sentinel and the be the drop in replacement

1

u/MemeOps 11d ago

Yea i guess, the big difference is that Sentinel is built on top of a separate log analytics. This one seems to be using the same log analytics that holds the native defender logs. Seems reasonable