Security1 publisher2 min readPublished
Microsoft folds SIEM and threat protection into one Defender foundation it calls the ISOC
Microsoft is building one foundation inside Defender for security operations and native protection, and the reason it gives is that a single operator with an agent framework now does what once took whole teams.
The Watch · Security desk

What happened
- Microsoft has announced ISOC in Microsoft Defender, a foundation that brings its SIEM and its threat protection together so that analysts and agents work from one set of signals, context and controls.
- The stated rationale is that, in Microsoft's words, security cannot operate at AI speed when protection and operations are built as separate systems.
- The post follows Microsoft's July 2026 introduction of an end-to-end cyber stack alongside Project Perception, which covered models, a harness and specialized agents.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams paying for a SIEM alongside a third-party detection stack now face a vendor arguing that the split itself is the cost, and the case for keeping it has to be built on their own coverage numbers; Microsoft's post leaves Sentinel unnamed and the alternative unpriced.
- capability Putting context and actuators in one system means an agent's conclusion becomes an enforced action without a human handoff between them. That raises the cost of a wrong automated call.
- constraint Capabilities that are on by default reduce integration work and also reduce the number of components a buyer can swap out later. Detection-quality risk shifts onto one supplier's roadmap.
- exposure This one competes for budget attention. There is no flaw to patch and no exploitation window attached to it.
Microsoft's case for consolidation is a claim about handoffs. "Every handoff, integration, and boundary slows defenders down. Agents inherit that complexity," the company wrote in the announcement [5]. The premise under it is attacker economics: "What once required entire teams now requires a single operator and an agent framework" [3].
The design is described in three layers. Signals and sensors give the system awareness, context turns those signals into understanding, and actuators turn insight into protective action [6]. The practitioner-facing part is narrower and easier to check at a demo: investigation, hunting, automation, incident management, threat understanding and response actions are brought together and available by default [10].
The proof point Microsoft offers already ships. Attack disruption in Defender detects, predicts and adapts to an attacker while the attack is still unfolding, and disrupts threats in progress [8]. ISOC's contribution, according to the post, is making that loop native and removing the burden of assembling, tuning and maintaining it yourself [9]. The announcement came roughly two months after Microsoft introduced its end-to-end cyber stack alongside Project Perception in July 2026 [7][14].
Microsoft did not publish pricing, licensing terms, SKU names or a general availability date, and the post discusses SIEM generically without naming Sentinel [12][13]. That leaves the procurement question open for anyone paying separately for a SIEM and a third-party detection stack, because the only argument on the table is architectural.
The operational risk sits where the actuators sit. Microsoft's split of labour gives agents the speed and scale to execute continuously and leaves people to set priorities, apply judgment and define outcomes [11]. Remove the boundary between the system that holds context and the system that takes action, and an automated decision becomes an executed action with no handoff in which a human would have seen it. Microsoft says the loop takes on more of the continuous work of detecting and defending as autonomy grows [15].
Nothing in the post is an incident: no vulnerability, no patch, no active exploitation [16]. The decision it forces is a renewal decision, and the comparison that decides it is measured detection coverage on your own telemetry against what a default-on Defender foundation actually catches.
What to watch
- Whether ISOC arrives as a new SKU or as an entitlement folded into existing Defender and Sentinel plans, and whether SIEM ingestion pricing moves with it.
- A general availability date, and whether the integrated loop is available to customers who keep a third-party EDR in place.
- Whether Microsoft publishes measured disruption or detection results for the integrated loop, beyond the architecture description.