Microsoft Enhances Defender with Integrated Security Operations Center for E5 and E7 Users

Sep 24, 2026 610 views

Microsoft's latest offering allows users of Microsoft 365 E5 and E7 to access security information and event management (SIEM) features through Microsoft Defender without any additional licensing costs. This integration is part of a broader initiative, launching the Integrated Security Operations Center (ISOC), which amalgamates SIEM functionalities with existing capabilities like XDR, threat intelligence, automation, and AI, all within a single user interface.

As highlighted by Rob Lefferts, corporate vice president of Microsoft Threat Protection, security operations must keep pace with AI-driven threats, which often leverage automation for large-scale attacks. The advent of ISOC is a response to the inefficiencies tied to using separate security systems, which can slow down defensive actions.

Previously, while Microsoft 365 E5 and E7 subscriptions included Defender XDR, SIEM features were available only through Microsoft Sentinel, which required separate purchase. The newly integrated platform enables organizations to access logs from Microsoft’s existing security tools without incurring ingestion fees. However, from October 1, data from third-party security sources will be subject to fees, at a rate of $2.40 per GB.

ISOC was made available in public preview on September 23, but Microsoft has not communicated when the full production version will be released. This new functionality is targeted at companies holding the Microsoft Defender Suite and those subscribed to E5 or E7 licenses without prior use of Microsoft Sentinel, requiring no minimum user seat subscription for access.

A Value Proposition

Microsoft clarifies that ISOC functions as an enhancement rather than a standalone product. Many features, including case management and automated playbook generation, previously necessitated purchasing Sentinel separately; they are now rolled into Defender at no additional cost. This transition simplifies the user experience, as the integrated platform encompasses logs from various Microsoft services, including Defender for Endpoint and Office 365. During the preview, data retention is set at 30 days, increasing to 90 days on November 15.

Understanding Operational Costs

While basic functionalities of ISOC draw from existing Microsoft security services, more advanced features require an ISOC workspace along with an Azure subscription, according to Microsoft's product documentation. This setup unlocks access to hundreds of additional data connectors and machine learning analytics capabilities. Organizations not primarily operating within the Microsoft ecosystem may find it necessary to conduct a total cost of ownership analysis against their current SIEM solutions.

The current preview does not extend to organizations already using a Sentinel workspace. For those eligible for ISOC, there’s an option to transition from Sentinel come November 15. This consolidation of identity, endpoints, and security operations can streamline incident handling. Still, it does create an organizational reliance on Microsoft's infrastructure and policies, which security leaders should carefully consider.

CISOs evaluating whether to transition from a separate SIEM must weigh various factors: the complexity of migration, reconfiguration of detection mechanisms, and potential financial implications, including exit costs. Analysts caution that moving to ISOC should not occur without a thorough assessment of high-value cross-vendor detections currently in place.

Strategic Adaptations with Agent Integration

Lefferts positions ISOC as foundational to Microsoft’s intended strategy for security agents unveiled in Project Perception earlier in the year. However, some experts remain skeptical about the necessity of a single-vendor approach for a functional security operations center. Project Perception continues to operate within a limited preview context.

Key concerns persist regarding how ISOC logs and audits actions taken by agents, particularly as they gain capabilities to effect changes. The implications of their access can be significant, heightening the potential for security breaches if mismanaged. Analysts recommend implementing strict controls over agent authority and maintaining transparency around pivotal decisions, emphasizing the importance of strong security frameworks despite increased integration.

There’s recognition that these agents may inadvertently expand the attack surface, creating new vulnerabilities for adversaries to exploit. As Wong pointed out, attackers could manipulate the telemetry streams that agents rely on, thereby influencing their operational decisions.

Ultimately, Microsoft's efforts to streamline security management through ISOC present opportunities for improved efficiency, but the central question remains: will customers maintain adequate control and the right to scrutinize actions taken within this integrated framework?

Microsoft did not respond to requests for further information regarding this new integration at the time of publication.

Source: Richard Miller · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Microsoft integrates SOC capabilities with Defender for e...