Microsoft announced an Integrated Security Operations Center (ISOC) in Defender on September 23, 2026. The preview brings security information and event management (SIEM), extended detection and response (XDR), automation, and AI-assisted work into a shared Defender experience. Microsoft wants analysts and agents to have the same signals and context when they investigate and respond to threats.
For now, access is narrower than that vision might suggest. This phase is for eligible Microsoft Defender Suite and Microsoft 365 E5 or E7 customers without an active Microsoft Sentinel workspace. Some capabilities work without creating an ISOC workspace; others require one. Included retention applies to Defender data, while additional data may incur ingestion charges.
The preview does not offer a fully autonomous SOC. The practical question for security teams is which investigations and response workflows they can move into Defender now, and what it takes to run them.
ISOC Gives Analysts and Agents a Shared Starting Point
SIEM tools bring security data together for investigation, while XDR connects detections and response across protected systems. ISOC puts those functions closer together in the Defender portal, alongside threat intelligence, automation, and AI-assisted workflows.
Microsoft describes a continuous protection loop: signals inform investigations, and what defenders learn can feed protective action. That is the company’s intended operating model, not a measured outcome established by the preview announcement. A shared interface may reduce handoffs between tools, depending on the data a team can access and the actions its analysts can safely take.
The initial feature set is more concrete than the agentic framing. Eligible teams can start with case management, workbooks, natural-language playbook generation, and enhanced automation rules without first creating an ISOC workspace. These give analysts a way to organize work and build supported response workflows. They do not mean every SIEM function or data source is available by default.
An Active Sentinel Workspace Changes Eligibility
Microsoft’s ISOC preview eligibility guidance names three qualifying licenses: Microsoft Defender Suite, Microsoft 365 E5, and Microsoft 365 E7. During this phase, the organization must also lack an active Microsoft Sentinel workspace.
For established security operations centers, that is a firm boundary. Microsoft tells organizations with an active Sentinel workspace to continue using their existing Sentinel experience and explicitly warns them not to disconnect a production workspace merely to qualify for the preview. ISOC is not a migration instruction or a reason to dismantle a working deployment.
Licensing alone does not make every capability ready to use. Teams that want to create an ISOC workspace also need an Azure subscription and the required permissions. Because ISOC remains in preview, Microsoft says its capabilities and availability may change. Administrators should confirm eligibility and current requirements before planning a rollout around a preview feature.
The Workspace Boundary Determines What You Can Do
ISOC has two practical starting points. Without an ISOC workspace, eligible customers can use case management, workbooks, natural-language playbook generation, and enhanced automation rules. A team can explore those supported workflows using Microsoft security data without making a traditional SIEM deployment its first step.
An ISOC workspace enables the workspace-dependent capabilities listed in Microsoft’s preview documentation: User and Entity Behavior Analytics (UEBA), Content hub, repository-based content deployment, the listed threat-intelligence capability, and ingestion of additional Azure and third-party security data. It is also the route to more than 500 available data connectors. That connector count does not mean the data appears automatically.
Automation has another boundary. Microsoft’s documentation says automation on Microsoft data does not require a Microsoft Sentinel workspace, but automation on third-party data ingested through Log Analytics does require one. Teams evaluating external feeds need to check their specific automation scenarios. Connecting a source does not necessarily provide the same response options as a Microsoft-native alert.
Thirty Days of Defender Retention Is Included, Not All Ingestion
The key pricing distinction is between data already available in Defender and data a team chooses to connect. Microsoft’s ISOC data and billing guidance says native Defender data is available directly in the Defender experience; it does not need to be separately ingested into an ISOC workspace. During this preview phase, eligible customers receive 30 days of included retention for Defender data.
That does not extend included retention to every connected source. Additional Microsoft and non-Microsoft security data can be brought in through an ISOC workspace and data connectors, and Microsoft says additional ingestion charges might apply depending on what is ingested. The cited guidance provides neither a single all-inclusive ISOC price nor an estimate of what a particular organization will spend on external feeds.
A trial could start with supported Defender data, then estimate volume and applicable charges before enabling connectors for other systems. That would let a team weigh the extra visibility against ingestion cost instead of treating the connector count as a measure of included value.
AI Generates Playbooks, but People Still Validate Them
ISOC’s natural-language Playbook Generator can turn a description of a response workflow into a code-based playbook. According to Microsoft’s preview automation documentation, a user can review, test, save, and activate the result. Microsoft says users must manually review and validate generated code.
A generated playbook can carry out supported actions once configured and triggered. It does not show that an AI agent can independently decide how to handle any incident. Automation rules specify when actions run, while Unified RBAC permissions govern who can manage automation. Playbooks that call external services need the relevant integration profiles configured.
There are operational limits, too. Generated playbooks support Python only, cannot use external libraries, and have a maximum runtime of 10 minutes per execution. Microsoft limits generated playbooks to 100 per tenant. Enhanced alert-trigger rules do not support priority ordering, and their available actions are limited to running generated playbooks and updating alerts. A team designing a response process, particularly one with dependencies between steps, needs to account for those limits.
The Preview Needs an Operational Test, Not an Autonomy Claim
Frequently Asked Questions
5 questions
1What Is ISOC in Microsoft Defender?
ISOC is Microsoft’s preview of an integrated security operations experience in the Defender portal. It brings SIEM and XDR capabilities together with shared security signals, context, automation, and AI-assisted workflows. Eligible teams can begin with features such as case management and workbooks, then add an ISOC workspace for certain data and capabilities.
2
Sources
- announced an Integrated Security Operations Centermicrosoft.com
- ISOC preview eligibility guidancelearn.microsoft.com
- ISOC data and billing guidancelearn.microsoft.com
- preview automation documentationlearn.microsoft.com



