2 Sources
[1]
Microsoft unveils Integrated Security Operations Center in Defender for AI agents
Microsoft unveils Integrated Security Operations Center in Defender for AI agents Microsoft Corp. today unveiled Integrated Security Operations Center in Microsoft Defender as it rebuilds its security operations products around artificial intelligence agents. The service moves security information
[2]
Microsoft's Rob Lefferts On New Capabilities Unifying Defender, Sentinel: The 'Foundation You Need' For Agentic Security
The launch of integrated security operations center (ISOC) capabilities in Microsoft Defender 'is one of those game changers that I think can actually shift the game board a little bit,' Lefferts tells CRN. Microsoft's debut Wednesday of new capabilities in Microsoft Defender for security
Share
Copy Link
Microsoft launched its Integrated Security Operations Center in Microsoft Defender, merging Sentinel SIEM capabilities with threat protection features to help security teams combat AI-accelerated attacks. The move addresses a growing challenge as attackers deploy AI agents that require entire teams to counter, while defenders struggle with fragmented tools and manual processes.
Microsoft has launched its Integrated Security Operations Center in Microsoft Defender
1
, a significant shift in how the company approaches security operations as organizations face increasingly sophisticated AI-powered threats. The service directly integrates security information and event management features from Microsoft Sentinel into Defender, creating a unified platform designed to help defenders match the speed of AI agents deployed by attackers.The launch comes as attackers accelerate their use of AI agents to conduct operations that previously required entire teams. Rob Lefferts, corporate vice president of Microsoft Threat Protection, emphasized the urgency of the situation, pointing to recent examples like China nation-state actors using Anthropic's models to drive attacks and JadePuffer, a fully automated AI ransomware attack and exploitation framework
2
. "What once required entire teams now requires a single operator and an agent framework," Lefferts wrote1
. The problem intensifies when protection and day-to-day security operations run as separate systems, forcing analysts to manually piece together incidents across multiple tools.
Source: CRN
The Integrated Security Operations Center brings several critical capabilities from Sentinel directly into the Defender portal. Case management, workbooks, and a feature that writes automation playbooks from plain-language instructions work without any setup
1
. However, advanced features like user and entity behavior analytics and the ability to ingest data from Azure and third-party sources require creating a dedicated ISOC workspace linked to an Azure subscription. Microsoft offers more than 500 connectors for external sources, though ingestion charges may apply1
.The platform introduces what Microsoft calls an integrated protection loop, where telemetry, exposure data, and threat intelligence feed directly into Defender's controls. The existing attack disruption feature in Defender demonstrates this loop in action by acting on intrusions while they're still underway
1
.AI agents in ISOC receive the same signals, context, and controls as human analysts, with core security workflows wired in by default. This enables agents to investigate incidents and take action without requiring a separate operating model. The agents "depend on the rest of the stack working as one," Lefferts explained
1
. Despite the automation, human oversight remains central to Microsoft's approach. Project Perception agents still require human approval for high-stakes actions, and people set strategic priorities—an approach Lefferts summarized as "strategy stays human"1
.
Source: SiliconANGLE
ISOC builds on Project Perception, the system Microsoft introduced in July alongside MAI-Cyber-1-Flash, its first in-house developed security model
1
.Related Stories
Lefferts told CRN that ISOC provides "the foundation that you need" to take concrete steps against AI-accelerated attacks
2
. He expressed concern that many organizations aren't moving quickly enough to prepare for attackers gaining access to frontier AI-level capabilities on par with models like Anthropic's Claude Mythos and OpenAI's GPT Cyber models. "I think people have been very interested in moving and wanting to move. I'm not sure they are moving fast enough in practice yet," he said2
.The unified approach combining Microsoft Sentinel SIEM capabilities with Defender's threat protection and XDR features aims to shift the traditional dynamic where defenders must know everything perfectly while attackers need only exploit one vulnerability. "With AI, whoever's got the most data and the best context, wins—and we want to make sure that that is the defensive team," Lefferts stated
2
.The ISOC public preview opened on September 23 to customers with Microsoft Defender Suite, Microsoft 365 E5, or Microsoft 365 E7 licenses. Organizations currently running an active Microsoft Sentinel workspace are excluded from the preview
1
. Defender data is stored for 30 days at no extra charge during the preview period, though Microsoft has not yet disclosed final pricing. A Tech Community ask-me-anything session on the service is scheduled for October 61
.The launch signals Microsoft's recognition that fragmented tools and separate data sources will limit the effectiveness of agentic security frameworks. By providing a unified platform for AI-driven security operations, Microsoft aims to help defenders regain the advantage as automated attacks become more sophisticated and widespread.
Summarized by
Navi
1
Technology

2
Policy and Regulation

3
Technology
