Microsoft Unveils Integrated Security Operations Center in Defender
Microsoft has unveiled an Integrated Security Operations Center (ISOC) in its Defender for AI agents, aiming to combat increasingly sophisticated cyber threats. According to Rob Lefferts, corporate vice president of Microsoft Threat Protection, attackers are now using artificial intelligence agents to carry out attacks, which can be difficult for security teams to detect and respond to.
ISOC moves key features from Microsoft Sentinel directly into Defender, including case management and workbooks, which can be used without setup. However, some parts of ISOC require extra configuration, such as user and entity behavior analytics and data ingestion from outside sources.
The service builds on Project Perception, a system introduced in July that allows agents to investigate incidents and act on them without human intervention. Lefferts noted that the design prioritizes human strategy and approval for high-stakes actions, with agents depending on the rest of the stack working as one.