Skip to content

Product1 publisher2 min readPublished

Microsoft pulls Sentinel's SIEM features into Defender for customers who do not already run Sentinel

The Integrated Security Operations Center preview puts case management and workbooks in the Defender portal with no setup, while behavior analytics and third-party feeds wait on a new Azure-linked workspace. Microsoft has not disclosed pricing.

The Product Desk · Product desk

Illustration accompanying Microsoft pulls Sentinel's SIEM features into Defender for customers who do not already run Sentinel

What happened

  • Microsoft opened a public preview of Integrated Security Operations Center, which moves security information and event management features out of Microsoft Sentinel and into the Defender portal.
  • The preview is available to customers holding Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 licenses.
  • Organizations that already run an active Microsoft Sentinel workspace are excluded from the preview for now.
  • Microsoft lists more than 500 connectors for outside sources and warns that ingestion charges may apply to the data they bring in.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The teams with a Sentinel estate to consolidate are the ones who cannot try the consolidation, so the early feedback on ISOC comes from shops with little or no Sentinel history.
  • cost The free retention in the preview covers Defender's own data, so whoever wires in the outside feeds owns whatever those feeds cost.
  • decision A pilot now spends staff time before there is a price to weigh it against. Buyers defer the purchase decision until after the preview.
  • exposure Agents arrive with an analyst's signals and controls and core workflows already on, so the human-approval step on high-stakes actions is the boundary an admin has to check before rollout.

The first thing a security lead sees after switching this on is a case queue and workbooks already sitting in the Defender portal with nothing to configure, next to a feature that writes automation playbooks from plain-language instructions [4]. What most teams buy a SIEM for is the data from everything that is not Defender, and that part needs setup. User and entity behavior analytics, plus any Azure or third-party feed, wait on a dedicated ISOC workspace linked to an Azure subscription [5]. Of the five capabilities Microsoft named, three arrive ready and two are behind that workspace [17]. During the preview, Defender's own data is retained for 30 days at no extra charge [14].

Microsoft's stated reason for the merge is how fast small attacking teams have become. "What once required entire teams now requires a single operator and an agent framework," Rob Lefferts, corporate vice president of Microsoft Threat Protection, wrote in a blog post [2]. Defenders fall behind, he argued, when protection and day-to-day operations run as separate systems and analysts have to piece incidents together by hand across several tools [3]. He calls the path from telemetry into controls an integrated protection loop, and points to Defender's existing attack disruption, which acts on an intrusion while it is still underway [7].

Inside ISOC, agents get the same signals, context and controls as a human analyst, and core workflows are wired in by default, so an agent can investigate an incident and act on it without a separate operating model [8]. The agents "depend on the rest of the stack working as one," Lefferts wrote [9]. The service builds on Project Perception, which Microsoft introduced in July alongside MAI-Cyber-1-Flash, its first security model developed in-house [10]. Project Perception agents still need human approval for high-stakes actions, an approach Lefferts summed up as "strategy stays human" [11].

A tenant with no Sentinel workspace and mostly Microsoft telemetry can test ISOC now for the price of staff time [12]. Add a heavy third-party estate and that same tenant is standing up a workspace and an ingestion path before it learns anything [5]. Sentinel shops are outside the preview either way [13]. For them the next few weeks are planning time, and the planning question is which of their Sentinel content is native Defender data and which arrives through the more than 500 connectors Microsoft flags as chargeable [6].

Microsoft has a Tech Community ask-me-anything session on the service scheduled for Oct. 6 [16].

What to watch

  • Whether Microsoft lifts the exclusion on tenants with an active Sentinel workspace, and on what migration terms.
  • Published pricing at general availability, including ingestion rates and retention beyond the preview's 30 days.
  • Whether user and entity behavior analytics and connector setup stay gated behind the dedicated ISOC workspace.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories