Integrated Security Operations, built into Defender
ManagementISOC turns an existing Microsoft 365 E5, E7 or Microsoft Defender Suite licence into a full security operations platform. SIEM capabilities come included, investigations can look back three times further, and third-party logs get cheaper to bring in. No new product to buy.
TechnicalISOC delivers Sentinel's SIEM capabilities natively in the Defender portal for tenants with E5, E7 or Defender Suite. Defender telemetry is used without re-ingestion, an ISOC workspace handles non-Microsoft data at a new $2.40/GB meter, and the built-in data lake provides low-cost long-term storage, with Microsoft Fabric for advanced analytics.
The physics of security have changed
Attackers use AI to move at machine speed, SOC tooling is still split across products, and costs keep rising because the same data is stored and paid for several times.
Agents inherit complexity
AI agents dropped into fragmented systems inherit the same silos, gaps and duplicated data as humans do. They can't reason across what they can't see.
Operations stay fragmented
Separate tools, workflows and owners for XDR, SIEM, threat intel, SOAR and ticketing slow down every investigation.
Data gets duplicated
Security data is stored, moved and paid for multiple times across disconnected systems. That's cost without extra protection.
Before: siloed tools, copied data
Every tool keeps its own copy. The analyst stitches the story together by hand.
From linear workflows to a continuous loop
With signals, context and controls working as one, what defenders learn during an attack feeds straight back into stronger protection before the next one. ISOC makes this loop native, so you don't have to assemble, tune and maintain it yourself. Click a step.
Built for agentic security
Agents get the shared signals, context and controls to see, understand and act across the environment.
Integrated protection loop
Threat-led workflows that connect post-breach findings to pre-breach protection.
Designed for the practitioner
Investigate, hunt, automate, manage cases and act by default, organised around outcomes rather than tools.
SIEM and XDR on one foundation
ISOC is not a new SKU. It is a benefit added to Microsoft Defender Suite, Microsoft 365 E5 and Microsoft 365 E7, for tenants without an active Sentinel workspace during this preview phase (Microsoft Learn). Switch the audience at the top to see business or technical detail.
Describe it. AI writes the automation.
Two data paths, one experience
Microsoft Defender data is used where it already lives. Non-Microsoft data goes into an ISOC workspace in your own Azure subscription. Click any step for details.
Select a step
Each step shows what it does, when it's available and what it costs.
Works without a workspace day one
Available to eligible E5, E7 and Defender Suite tenants straight away.
Needs an ISOC workspace Azure subscription
Create one in your own Azure subscription to unlock more capabilities.
What does it mean for this customer?
Answer two or three questions to get a verdict, the relevant dates and recommended actions.
Impact at a glance
| Situation | Impact | What to do |
|---|---|---|
| E5/E7/Defender Suite, no SIEM | Largest gain | Start using cases, workbooks and playbooks now. Add a workspace for third-party data. |
| E5/E7/Defender Suite, Sentinel in Defender portal | Opt-in from Ignite | Keep running as normal. Build a cost comparison and talk to the account team before opting in. |
| E5/E7/Defender Suite, Sentinel in Azure portal | Deadline | Move to the Defender portal before 31 March 2027, regardless of ISOC. |
| E3, standalone Defender plans | Cases only | ISOC strengthens the business case for the Defender Suite add-on or E5. |
A phased rollout
Phase 1 is for E5, E7 and Defender Suite tenants without Sentinel. Phase 2, from Ignite, adds existing Sentinel customers and the 90-day retention benefit.
What will it cost?
Defender data is included. You pay for non-Microsoft data, retention beyond what's included, and Fabric if you use it. Prices below are US list prices from the announcement; regional pricing may differ.
Indicative monthly estimate at US list prices (30.4 days per month). Excludes Fabric, analytics-tier retention beyond 90 days and any regional price differences. Preview information, subject to change.
Pros, cons and watch-outs
A strong offer for E5, E7 and Defender Suite tenants without a SIEM. Existing Sentinel customers need a careful cost model before they opt in.
Six-question quiz
Useful before a customer conversation.
What to do this quarter
Go deeper
Microsoft's own announcement material, plus the companion Perception explainer.
Reimagining the SOC for the agentic era in Microsoft Defender
Rob Lefferts, CVP Microsoft Threat Protection, introduces ISOC and the integrated protection loop.
Read the announcement → RecordingISOC launch event
Watch the full announcement recording.
Watch the launch → WhitepaperAgentic SOC: The new operating model for continuous defense
Microsoft's whitepaper on operating a SOC where people and agents work as one system.
Download the whitepaper → Companion explainerProject Perception Explained
The agents, harness and models that run on top of ISOC, with a session simulator.
Open the Perception explainer →