Cybersecurity

Microsoft Brings ISOC to Defender, Uniting SIEM and Threat Protection

mm
Add Unite.AI to your preferred sources on Google

Microsoft on September 23, 2026, announced the integrated security operations center (ISOC) in Microsoft Defender, a foundation for agentic security that brings security information and event management (SIEM) and threat protection together in one system, available in preview as of the announcement.

Rob Lefferts, Corporate Vice President of Microsoft Threat Protection, announced ISOC in a Microsoft Security Blog post, describing it as a shared foundation on which people and agents can see, understand, and act across the environment without running separate systems.

Why Microsoft Says the SOC Must Change

The rationale in Lefferts’ post starts with offense. Cyberattackers are using agents to automate execution at scale, he wrote, and work that once required entire teams now requires a single operator and an agent framework. Because of that shift, security cannot operate at AI speed when protection and operations are built as separate systems: each handoff, integration, and boundary between them slows defenders, and agents built on top inherit that complexity.

For agentic security to work, he wrote, the industry needs a modern cyber stack with environment-wide visibility and the depth to investigate and act, with security operations and native protection functioning as one system.

The Six-Layer Cyber Stack Behind ISOC

ISOC builds on architecture Microsoft introduced on July 27, 2026, when it presented the end-to-end cyber stack alongside Project Perception, an agentic security system. The Official Microsoft Blog described Project Perception as coordinating three classes of specialized agents: red team agents that map potential paths to compromise before attackers can exploit them, blue team agents that investigate and weigh context to determine what constitutes meaningful risk, and green team agents that take corrective action and harden defenses across the environment.

The stack has six layers: signals and sensors, context, models, a harness, agents, and actuators. In Microsoft’s July description, signals and sensors provide awareness across the digital estate, context converts those signals into token-efficient understanding agents can consume, models supply intelligence and reasoning, the harness coordinates models and agents across security workflows, and actuators translate decisions into protection. Microsoft also said Project Perception uses a multi-model architecture combining frontier and specialized cyber models, and that the system would enter public preview on August 3, 2026.

Within ISOC, Lefferts wrote, signals and sensors supply awareness, context converts those signals into understanding, and actuators convert insights into protective action. Agents contribute the speed and scale for continuous execution, while people set priorities, exercise judgment, and define outcomes.

The Integrated Protection Loop and Practitioner Design

Microsoft said ISOC makes signals, context, and controls work as one, replacing linear security workflows with an integrated protection loop that continually feeds what defenders learn back into stronger pre-breach protection. Attack disruption in Microsoft Defender illustrates the model, according to the post: rich telemetry and controls let the system detect, predict, and adapt to an attacker as the attack unfolds, interrupting active threats and anticipating where an attacker may move next. The loop uses exposure insights to strengthen protection in near real-time, Microsoft said, with threat intelligence focusing it on the threats that matter most.

ISOC brings together the capabilities needed to make that loop native, Microsoft said, removing the need for customers to assemble, tune, and maintain it themselves, and as protection advances, additional capabilities can join the loop.

For practitioners, Lefferts wrote, ISOC changes a starting point in which they have long had to compensate for the boundaries in their security architecture, manually correlating signals, reconstructing context, and moving between tools to assemble the information and controls needed to act. Investigation, hunting, automation, incident management, threat understanding, and response are brought together and available by default, so teams can organize around security outcomes rather than the boundaries between tools. As autonomy grows, he wrote, the loop can absorb more of the ongoing detection and defense work, while agents assist practitioners’ investigation, reasoning, and response with the same context and controls already at their disposal. The design requires no separate agentic layer to assemble and no new operating model to stitch together.

ISOC in Microsoft Defender is available in preview as of September 23, 2026. Microsoft also released a recording of the full announcement and a whitepaper, “Agentic SOC: The new operating model for continuous defense,” alongside the post.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.