Microsoft Brings SIEM to Defender, Simplifies Security Operations
Microsoft has integrated security information and event management (SIEM) capabilities into its Defender platform for enterprises, making it available to Microsoft 365 E5 and E7 customers at no extra license cost.
The company has rolled out the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with existing XDR, threat intelligence, automation, and AI tools in a single portal.
Microsoft says that attackers now use AI agents to automate attacks at scale, and that every handoff between separate tools slows defenders down. This is why the company has chosen to integrate ISOC into its Defender platform.
The data ingested from third-party security tools and other outside sources will be metered at $2.40 per GB on a pay-as-you-go basis, starting October 1st.