Discover what's coming to Microsoft Ignite, Nov 17-20, 2026.
Defender is your ISOC.
- Shared signals, context and controls to see, understand, and act in your environment across first- and third-party data.
- Unified operations, centered on threat-led workflows. Connecting post-breach insight back to pre-breach action.
- Simplified experience with one product, system, and data model. Bringing agents and humans together in the flow of work.
The future SOC needs a modern defense stack
Building a shared foundation
Microsoft Defender
Microsoft Sentinel
Project Perception
Integrated security operations
Workspace set up in just two clicks
Correlate signals into one case and one complete attack story
Stop active attacks automatically and prevent further movement
Industry recognition
- Microsoft is named a Leader in the October 2025 Gartner® Magic Quadrant™ for Security Information and Event Management.1
- Microsoft Defender is named a Leader in The Forrester Wave™: Extended Detection And Response (XDR) Platforms, Q2 2026.2
- Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection.3
What our customers are saying
The Total Economic Impact™ of deploying Microsoft Defender
Explore Microsoft Defender
Endpoint Security
Identity Security
Email & Collaboration Security
SaaS Security
Cloud Security
SIEM
Elevate your security with expert-led services
Explore more resources
Frequently asked questions
-
ISOC in Defender expands the value of Microsoft 365 E5 and E7 with security operations capabilities such as workbooks and NL to SOAR, that previously required a separate Sentinel purchase. It brings together leading XDR & SIEM, threat intelligence, automation, and AI capabilities in the Defender experience, helping customers get more value from security investments they already made. ISOC is not a new standalone product.
- Built for the agentic security: Give analysts and agents the shared signals, context, and controls to see, understand, and act across the environment.
- Integrated protection loop: Unified operations centered in threat-led workflows. Connecting post breach to pre-breach actions.
- Designed for practitioners: An experience built as one product, system and data model. Bringing agents and humans together in the flow of work.
-
ISOC eligibility requires an active Microsoft Defender Suite, Microsoft 365 E5 or E7 license, and an Azure subscription. This includes eligible customers in government and sovereign cloud environments.
The following are not eligible for ISOC:
- Security mini suites and standalone security suites
- Education (EDU) and Frontline (F) SKUs
-
Included Defender data sources are:
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Cloud
- Microsoft Entra Identity Protection logs
- Azure Activity / audit logs (via connector)
-
No. There is no minimum seat threshold for eligible Microsoft 365 E5 and E7 customers. Standard product terms apply.
-
There is no change for customers currently using Microsoft Sentinel. The current Microsoft Sentinel offering will continue to exist as is. Existing Microsoft Sentinel customers will have the choice to move to ISOC starting November 15, 2026 if they meet the relevant licensing eligibility criteria.
Protect everything
- [1]Gartner Magic Quadrant for Security Information and Event Management, Andrew Davies, Eric Alhm, Angel Berrios, Darren Livingstone, 8 October 2025.
GARTNER is a registered trademark and service mark and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. - [2]The Forrester Wave™: Extended Detection And Response (XDR) Platforms, Q2 2026, Allie Mellen et al, June 2026.
- [3]Gartner Magic Quadrant for Endpoint Protection, Deepak Mishra, Evgeny Mirolyubov, Nikul Patel, 26 May 2026.
GARTNER is a registered trademark and service mark and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. - [4]The Total Economic Impact™ Of Microsoft Defender, a commissioned study conducted by Forrester Consulting, June 2025.
Follow Microsoft Security