Microsoft unveils Integrated Security Operations Center in Defender for AI agents
Microsoft launched ISOC in Defender, moving SIEM features from Sentinel into the Defender portal with support for AI agents. Public preview is open to Defender Suite, Microsoft 365 E5 and E7 customers; Defender data is retained for 30 days at no charge, with pricing undisclosed.
- ISOC brings case management and workbooks from Sentinel into Defender with no setup
- Automation playbooks are generated from plain-language instructions
- More than 500 connectors are available for third-party data sources
- Preview open to Defender Suite, M365 E5 and E7; existing Sentinel customers excluded
Read next
Security