Microsoft Integrates ISOC into Microsoft Defender for Unified Security Operations
Microsoft has integrated its Security Operations Center (ISOC) into Microsoft Defender, aiming to bring together security information and event management (SIEM) and threat protection in one system. This move is part of Microsoft's agentic security approach, which seeks to make security operations and native protection function as one system.
The company announced the integration on September 23, 2026, with Corporate Vice President of Microsoft Threat Protection Rob Lefferts stating that ISOC brings a shared foundation for people and agents to see, understand, and act across the environment without running separate systems. Lefferts emphasized that traditional security approaches are no longer effective, as cyberattackers use agents to automate execution at scale, making it difficult for defenders to operate at AI speed.
Microsoft's agentic security approach is built on a six-layer cyber stack: signals and sensors, context, models, a harness, agents, and actuators. Within ISOC, this stack provides awareness, understanding, and protective action through the integrated protection loop. This loop continually feeds what defenders learn back into stronger pre-breach protection, making it possible to detect, predict, and adapt to attacks in near real-time.
The integration of ISOC into Microsoft Defender is available in preview as of September 23, 2026. According to Lefferts, this move will change the starting point for practitioners, allowing them to organize around security outcomes rather than the boundaries between tools.