Microsoft Merges Sentinel and Defender for Unified AI-Driven Attack Response
Microsoft has brought together its Sentinel and Defender security tools to create an Integrated Security Operations Center (ISOC) that can handle AI-driven attacks. The ISOC combines Sentinel's SIEM functionality with Defender's extended detection and response capabilities in a shared operational environment.
The new system is designed to give security analysts and AI agents access to the same set of signals, context, and controls without requiring teams to switch between separate security systems. This integrated approach aims to address the challenges posed by AI-executed operations, where automated systems handle most of an attack while people provide limited direction.
According to Microsoft, ISOC supports over 500 connectors, allowing organizations to bring in third-party security data alongside Microsoft telemetry. The system is positioned as a prerequisite for using AI agents effectively, which require access to the same telemetry, threat intelligence, and security controls used by analysts.