Microsoft on Wednesday announced Integrated Security Operations Center, or ISOC, capabilities in Microsoft Defender, describing a preview foundation that combines security information and event management features associated with Microsoft Sentinel with Defender threat protection so people and software agents can work from a shared set of signals, context, and controls.

In a Microsoft Security Blog (opens in new tab) post, Corporate Vice President Rob Lefferts wrote that attackers are using agents to automate execution at scale and that protection and operations cannot stay separate systems if defenders are to keep pace. ISOC, he said, is meant to make investigation, hunting, automation, incident management, threat intelligence, and action available in one Defender experience rather than requiring teams to stitch tools together. Microsoft said ISOC is available in preview and pointed readers to a white paper and announcement recording.

In a separate CRN (opens in new tab) interview published the same day, Lefferts said ISOC combines Sentinel SIEM capabilities with Defender’s threat protection and XDR, calling it “the foundation that you need” for agentic security and arguing that agent frameworks inherit whatever fragmentation defenders leave in place. He told CRN (opens in new tab) that Sentinel features such as user-entity behavioral analytics, SOAR, and case management become part of the integrated SOC and can run over native Defender data as well as other data ingested into ISOC.

Microsoft’s materials frame ISOC as enabling an “integrated protection loop” that turns investigation into stronger pre-breach controls, citing attack disruption in Defender as an example. The Event Record treats performance and “game board” shifting language from the blog and CRN (opens in new tab) interview as vendor positioning; independent customer outcome data were not included in the retrieved stories.