Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Integrated Security Operations Center (ISOC) in Microsoft Defender brings leading XDR and SIEM capabilities, threat intelligence, automation, and AI together in the Microsoft Defender portal. ISOC gives security teams shared security signals, context, and workflows to detect, investigate, and respond to threats faster from one integrated experience.
Note
ISOC is in preview. Capabilities and availability might change during the preview period.
ISOC advantages
ISOC helps security teams:
- Integrated security operations - Leading SIEM capabilities are available out of the box in Microsoft Defender, delivering immediate security operations value from day one without requiring a traditional SIEM deployment as a starting point.
- Value from Microsoft 365 investments - Eligible customers receive 30 days of included retention for Defender data during this phase of the preview. For broader visibility, bring in additional Microsoft and non-Microsoft data through more than 500 data connectors. Additional ingestion charges might apply depending on the data you ingest.
- Path for agentic security - Security teams and Perception agents work together on a common set of signals, context, and workflows, enabling faster investigations, coordinated response, and improved security outcomes.
Who can use ISOC?
During this phase of the preview, ISOC is available to eligible customers with Microsoft Defender Suite, Microsoft 365 E5, or Microsoft 365 E7 that don't have an active Microsoft Sentinel workspace.
If your organization has an active Microsoft Sentinel workspace, continue using your existing Microsoft Sentinel experience during this phase. Don't disconnect a production Microsoft Sentinel workspace only to qualify for the ISOC preview.
Prerequisites
To use ISOC, you need an active, eligible Microsoft Defender Suite, Microsoft 365 E5, or Microsoft 365 E7 license.
To create an ISOC workspace and use workspace-dependent capabilities, you also need an Azure subscription with the required permissions.
Licensing and pricing
For Microsoft 365 E5 plan details and pricing, see Microsoft 365 E5 for Enterprise.
To compare the security capabilities included with Microsoft 365 enterprise plans, see Microsoft 365 Security Enterprise Plans.
ISOC capabilities
ISOC lets eligible customers start with security operations capabilities built into Microsoft Defender and expand with additional data and capabilities when needed.
- Start immediately with case management, workbooks, and natural-language playbook generation.
- Add an ISOC workspace when you need additional Microsoft and non-Microsoft data ingestion, UEBA, Content hub connectors, repositories (CI/CD), threat intelligence, and other workspace-dependent capabilities.
The following table summarizes the workspace requirements for the capabilities covered in this preview.
| Capability | ISOC workspace required | Learn more |
|---|---|---|
| Case management | No | Case management in the Microsoft Defender portal |
| Natural-language playbook generation | No | Generate playbooks using AI with ISOC |
| Enhanced automation rule | No | Create automation rules with ISOC in Microsoft Defender |
| Workbooks | No | Create and manage workbooks with ISOC in Microsoft Defender |
| User and Entity Behavior Analytics (UEBA) | Yes | Add UEBA to Microsoft 365 E5 data |
| Content hub | Yes | Use Content hub with ISOC in Microsoft Defender |
| CI/CD | Yes | Deploy content as code from your repository for an ISOC workspace |
| Threat intelligence | Yes | Threat intelligence in Microsoft Defender |
| Azure and third-party security data | Yes | Data ingestion and billing for ISOC |
Note
This table shows whether an ISOC workspace is required for each capability during this preview. It doesn't indicate licensing or availability for the same capabilities in other Microsoft security experiences.
Get started
If the capabilities you want to use require an ISOC workspace, see Create an ISOC workspace in the Microsoft Defender portal.
For information about ingesting additional security data and understanding billing, see Data ingestion and billing for ISOC.