This is the Trace Id: 973f485d8e4fd898af1cf786fc6de08d
Skip to main content Microsoft Defender Microsoft Entra Microsoft Intune Project Perception Microsoft Purview Microsoft Sentinel SIEM View all products AI-powered cybersecurity Cloud security Data security & governance Identity & network access Integrated SecOps Security for AI Small and medium business Zero Trust Pricing Services Partners Why Microsoft Security Cybersecurity awareness Customer stories Security 101 Product trials How we protect Microsoft Industry recognition Microsoft Security Insider Microsoft Digital Defense Report Security Response Center Microsoft Security Blog Microsoft Security Events Microsoft Tech Community Documentation Technical Content Library Training & certifications Compliance Program for Microsoft Cloud Microsoft Trust Center Security Engineering Portal Service Trust Portal Microsoft Secure Future Initiative Business Solutions Hub Contact Sales Start free trial Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Software companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap

Discover what's coming to Microsoft Ignite, Nov 17-20, 2026.

Register now
INTEGRATED SECOPS

A new foundation for agentic security

Create a foundation built for agentic security with the integrated security operations center (ISOC) in Microsoft Defender. It brings together leading solutions for SIEM and threat protection, and enables people and agents to see, understand, and act across the environment, without the complexity of operating separate systems.
A woman sitting at a desk looking at her laptop.

Defender is your ISOC.

  • Shared signals, context and controls to see, understand, and act in your environment across first- and third-party data.
    A screenshot of an incident list in Defender.
  • Unified operations, centered on threat-led workflows. Connecting post-breach insight back to pre-breach action.
    Screenshot of a blast radius in Microsoft Defender
  • Simplified experience with one product, system, and data model. Bringing agents and humans together in the flow of work.
    Screenshot of Microsoft Defender homepage
ISOC

The future SOC needs a modern defense stack

Shared signals, context, and controls that are built-in and on by default in Microsoft Defender.
The foundation

Building a shared foundation

Microsoft Defender

Automatically disrupt cyberattacks and accelerate response with extended detection and response.

Microsoft Sentinel

Strengthen operations with a security information and event management (SIEM) that unifies your data and scales intelligently.

Project Perception

Reason across your security data, tools, and workflows with multi-agent workflows for protection that never stops.
BG image
SCENARIOS

Integrated security operations

Disrupt attacks early, continuously harden assets as risk changes, and apply protection wherever it is needed the most.

Workspace set up in just two clicks

Back to tabs

Industry recognition

  • Microsoft is named a Leader in the October 2025 Gartner® Magic Quadrant™ for Security Information and Event Management.1
  • Microsoft Defender is named a Leader in The Forrester Wave™: Extended Detection And Response (XDR) Platforms, Q2 2026.2
  • Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection.3
Customer stories

What our customers are saying

The Total Economic Impact™ of deploying Microsoft Defender

See how unifying your SecOps with Microsoft Defender helps reduce costs and response effort.
PRODUCTS

Explore Microsoft Defender

Microsoft Defender offers comprehensive threat prevention, detection, and response capabilities.

Endpoint Security

Gain comprehensive protection across all devices and platforms for unmatched, cross-domain visibility across your organization.

Identity Security

Prevent, detect, and respond to advanced identity threats across your identity fabric.

Email & Collaboration Security

Safeguard your email and collaboration tools from phishing, and disrupt advanced cyberthreats, such as business email compromise.

SaaS Security

Modernize how you secure apps and generative AI systems, elevate your security posture, and defend against SaaS-based cyberattacks.

Cloud Security

Start protecting your hybrid and multicloud environments with unified security across the full application lifecycle, from code to runtime.

SIEM

Strengthen operations with a security information and event management that unifies your data and scales intelligently.

Elevate your security with expert-led services

Get help to defend against threats, build cyber resilience, and modernize security operations with Microsoft Defender Experts.
FAQ

Frequently asked questions

  • ISOC in Defender expands the value of Microsoft 365 E5 and E7 with security operations capabilities such as workbooks and NL to SOAR, that previously required a separate Sentinel purchase. It brings together leading XDR & SIEM, threat intelligence, automation, and AI capabilities in the Defender experience, helping customers get more value from security investments they already made. ISOC is not a new standalone product.

    • Built for the agentic security: Give analysts and agents the shared signals, context, and controls to see, understand, and act across the environment.
    • Integrated protection loop: Unified operations centered in threat-led workflows. Connecting post breach to pre-breach actions.
    • Designed for practitioners: An experience built as one product, system and data model. Bringing agents and humans together in the flow of work. 
  • ISOC eligibility requires an active Microsoft Defender Suite, Microsoft 365 E5 or E7 license, and an Azure subscription. This includes eligible customers in government and sovereign cloud environments.

    The following are not eligible for ISOC:

    • Security mini suites and standalone security suites 
    • Education (EDU) and Frontline (F) SKUs
  • Included Defender data sources are:

    • Microsoft Defender for Endpoint
    • Microsoft Defender for Office 365
    • Microsoft Defender for Identity
    • Microsoft Defender for Cloud Apps
    • Microsoft Defender for Cloud
    • Microsoft Entra Identity Protection logs
    • Azure Activity / audit logs (via connector)
  • No. There is no minimum seat threshold for eligible Microsoft 365 E5 and E7 customers. Standard product terms apply.

  • There is no change for customers currently using Microsoft Sentinel. The current Microsoft Sentinel offering will continue to exist as is. Existing Microsoft Sentinel customers will have the choice to move to ISOC starting November 15, 2026 if they meet the relevant licensing eligibility criteria. 

Get started

Protect everything

Make your future more secure. Explore your security options today.
  1. [1]
    Gartner Magic Quadrant for Security Information and Event Management, Andrew Davies, Eric Alhm, Angel Berrios, Darren Livingstone, 8 October 2025.

    GARTNER is a registered trademark and service mark and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.

    Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
  2. [2]
    The Forrester Wave™: Extended Detection And Response (XDR) Platforms, Q2 2026, Allie Mellen et al, June 2026.
  3. [3]
    Gartner Magic Quadrant for Endpoint Protection, Deepak Mishra, Evgeny Mirolyubov, Nikul Patel, 26 May 2026.

    GARTNER is a registered trademark and service mark and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.

    Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
  4. [4]
    The Total Economic Impact™ Of Microsoft Defender, a commissioned study conducted by Forrester Consulting, June 2025.

Follow Microsoft Security

English (United States) Consumer Health Privacy Sitemap Contact Microsoft Privacy Manage cookies Terms of use Trademarks Safety & eco Recycling About our ads