Microsoft launched its Integrated Security Operations Center in Microsoft Defender, merging Sentinel SIEM capabilities with threat protection features to help security teams combat AI-accelerated attacks. The move addresses a growing challenge as attackers deploy AI agents that require entire teams to counter, while defenders struggle with fragmented tools and manual processes.

Microsoft has launched its Integrated Security Operations Center in Microsoft Defender

1

, a significant shift in how the company approaches security operations as organizations face increasingly sophisticated AI-powered threats. The service directly integrates security information and event management features from Microsoft Sentinel into Defender, creating a unified platform designed to help defenders match the speed of AI agents deployed by attackers.

Addressing the Growing Threat of AI Agents

The launch comes as attackers accelerate their use of AI agents to conduct operations that previously required entire teams. Rob Lefferts, corporate vice president of Microsoft Threat Protection, emphasized the urgency of the situation, pointing to recent examples like China nation-state actors using Anthropic's models to drive attacks and JadePuffer, a fully automated AI ransomware attack and exploitation framework

2

. "What once required entire teams now requires a single operator and an agent framework," Lefferts wrote

1

. The problem intensifies when protection and day-to-day security operations run as separate systems, forcing analysts to manually piece together incidents across multiple tools.

Source: CRN

Source: CRN

Unified Security Operations Through ISOC

The Integrated Security Operations Center brings several critical capabilities from Sentinel directly into the Defender portal. Case management, workbooks, and a feature that writes automation playbooks from plain-language instructions work without any setup

1

. However, advanced features like user and entity behavior analytics and the ability to ingest data from Azure and third-party sources require creating a dedicated ISOC workspace linked to an Azure subscription. Microsoft offers more than 500 connectors for external sources, though ingestion charges may apply

1

.

The platform introduces what Microsoft calls an integrated protection loop, where telemetry, exposure data, and threat intelligence feed directly into Defender's controls. The existing attack disruption feature in Defender demonstrates this loop in action by acting on intrusions while they're still underway

1

.

AI Agents with Human Oversight

AI agents in ISOC receive the same signals, context, and controls as human analysts, with core security workflows wired in by default. This enables agents to investigate incidents and take action without requiring a separate operating model. The agents "depend on the rest of the stack working as one," Lefferts explained

1

. Despite the automation, human oversight remains central to Microsoft's approach. Project Perception agents still require human approval for high-stakes actions, and people set strategic priorities—an approach Lefferts summarized as "strategy stays human"

1

.

Source: SiliconANGLE

Source: SiliconANGLE

ISOC builds on Project Perception, the system Microsoft introduced in July alongside MAI-Cyber-1-Flash, its first in-house developed security model

1

.

Shifting the Attacker-Defender Dynamic

Lefferts told CRN that ISOC provides "the foundation that you need" to take concrete steps against AI-accelerated attacks

2

. He expressed concern that many organizations aren't moving quickly enough to prepare for attackers gaining access to frontier AI-level capabilities on par with models like Anthropic's Claude Mythos and OpenAI's GPT Cyber models. "I think people have been very interested in moving and wanting to move. I'm not sure they are moving fast enough in practice yet," he said

2

.

The unified approach combining Microsoft Sentinel SIEM capabilities with Defender's threat protection and XDR features aims to shift the traditional dynamic where defenders must know everything perfectly while attackers need only exploit one vulnerability. "With AI, whoever's got the most data and the best context, wins—and we want to make sure that that is the defensive team," Lefferts stated

2

.

Availability and Pricing

The ISOC public preview opened on September 23 to customers with Microsoft Defender Suite, Microsoft 365 E5, or Microsoft 365 E7 licenses. Organizations currently running an active Microsoft Sentinel workspace are excluded from the preview

1

. Defender data is stored for 30 days at no extra charge during the preview period, though Microsoft has not yet disclosed final pricing. A Tech Community ask-me-anything session on the service is scheduled for October 6

1

.

The launch signals Microsoft's recognition that fragmented tools and separate data sources will limit the effectiveness of agentic security frameworks. By providing a unified platform for AI-driven security operations, Microsoft aims to help defenders regain the advantage as automated attacks become more sophisticated and widespread.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved