
What Microsoft ISOC Means for Security Operations
On September 23, 2026, Microsoft announced ISOC in Microsoft Defender, a bundle that adds Microsoft Sentinel's SIEM tools to the Microsoft 365 E5 and E7 licenses. Microsoft presented the launch as a step toward an agentic SOC. For any company already paying for E5, that raises a budget question quickly: if the license now includes a SIEM, does the company also own a SOC platform?
The answer depends on what Microsoft actually shipped, how much of a team's data lives outside Microsoft, and whether the AI that comes with E5 investigates alerts on its own.
{{ebook-cta}}
What Microsoft announced with ISOC in Microsoft Defender
ISOC stands for integrated security operations center. Microsoft uses the name for a setup that brings "XDR, SIEM, threat intelligence, automation, and AI together in Microsoft Defender," according to Microsoft's announcement.
ISOC draws on two products Microsoft already sells: Defender XDR and Microsoft Sentinel. Microsoft's launch post also features Project Perception, its multi-agent system, which Microsoft introduced in July and prices separately. For E5 and E7 customers who never bought Sentinel, features such as case management, threat intelligence, workbooks, and automation now appear in the Defender portal. Sentinel itself is already available in Defender, and its Azure portal version retires on March 31, 2027. Microsoft's FAQ describes ISOC as a license benefit and says plainly: "ISOC is not a new standalone product."
So Microsoft ISOC adds no new security capability. The tools inside it already existed in Sentinel. What changed is which license includes them. The agentic language around the launch describes capabilities Microsoft already sells in Defender, Sentinel, and Project Perception.
ISOC arrives seven weeks after Databricks bought Panther, a deal that closed August 3. Both companies are folding SIEM into a bigger platform.
Who qualifies for Microsoft ISOC
ISOC is open to companies with an active Microsoft Defender Suite, Microsoft 365 E5, or E7 license, and there is no minimum seat count. An Azure subscription is required to create an ISOC workspace, which is needed for connectors, UEBA, and threat intelligence.
ISOC is in public preview, and Microsoft has not announced a general availability date. During the preview, it covers E5 and E7 tenants that don't already have an active Sentinel workspace. Companies already on Sentinel see no change. Starting November 15, 2026, they can choose to move to ISOC if their licenses qualify.
What E5 and E7 customers get
For an E5 or E7 customer that picked Microsoft for XDR but never deployed Sentinel, ISOC adds SIEM tools at no extra license cost. According to Microsoft, the preview includes:
- Cases, which bring incidents, collaboration, task assignment, automation, and AI-powered summaries into one workspace.
- Workbooks for dashboards and reporting.
- Natural-language playbook generation, which turns a plain-English description into an automation workflow.
- Defender data without separate ingestion, kept for 30 days, rising to 90 days on November 15.
For a team running Defender alone, that means incidents, automation, and reporting in one portal, under a license it already pays for.
What non-Microsoft data costs in ISOC
The bundle includes Defender data. For a shop that runs mostly Microsoft, that is a real saving. Data from every other tool is metered. Starting October 1, 2026, ISOC customers can bring in data through more than 500 connectors at $2.40 per gigabyte, pay as you go, though Microsoft notes that regional pricing may vary. Microsoft's FAQ describes no included allowance for non-Microsoft data.
So an E5 customer that kept Okta for identity or CrowdStrike for endpoint pays to ingest that data before ISOC can use it. The same applies if your stack includes any of these tools:
- Identity: Okta, Ping Identity
- Endpoint: CrowdStrike Falcon, SentinelOne
- Web and network: Zscaler, Netskope, Cisco Umbrella
- Email security: Proofpoint, Abnormal Security, Mimecast
- Cloud: AWS and AWS GuardDuty, Google Cloud, Wiz
- SIEMs and data lakes: Splunk, Snowflake, Databricks
The license cost is fixed. The ingestion bill, however, grows with every source a team connects and every gigabyte those sources produce. Any comparison of ISOC against a separate SIEM or SOC platform has to include that second number.
How Microsoft ISOC differs from an agentic SOC
Microsoft frames ISOC as a step toward an agentic SOC. The test for whether a product is agentic is a single question: who decides the next step in an investigation?
Anthropic, which builds the Claude models, gives a clear definition in its guide to building effective agents. It describes workflows as "systems where LLMs and tools are orchestrated through predefined code paths." Agents, by contrast, are systems where LLMs "dynamically direct their own processes and tool usage." In a SOC, that means an agent decides what data to pull based on what it has already found. A workflow runs steps someone wrote in advance, even when an AI helped write them.
By that definition, several features that get called agentic fall short. A chat window that answers an analyst's questions follows the copilot model, because the analyst still decides each step. A case summary describes evidence that an analyst or another tool gathered. A playbook runs a fixed path, even one an AI wrote. Showing every query builds trust, but it doesn't show who chose the queries.
Measured that way, the AI that Microsoft lists as included in the Microsoft ISOC bundle is AI-powered case summaries and natural-language playbook generation. Microsoft calls these "the foundation for agentic AI security." Both are useful, and a playbook can even run automatically when an incident arrives. Once it starts, though, it runs the steps written into it. Neither feature decides what to look at next based on what it found, so in the bundle, the analyst still steers each investigation.
E5 and E7 also include more AI than the ISOC bundle. On September 24, the day after the ISOC launch, Microsoft made Security Copilot part of both licenses, with 400 security compute units a month for every 1,000 users, according to Microsoft's admin notice. That brings Microsoft's task agents, such as the Phishing Triage Agent, which sorts phishing alerts into real threats and false alarms and explains each call. Defender also has automatic attack disruption, which contains devices and disables accounts on its own when Defender detects an attack in progress with high confidence, such as ransomware. Each covers one kind of alert or attack. Microsoft draws the line between these tools and Project Perception itself: its Project Perception page calls Security Copilot "AI that assists" and Project Perception "AI that acts."
Microsoft does sell an agentic system. Project Perception uses teams of red, blue, and green agents that, in Microsoft's words, "hand off to each other automatically," with "every high-impact action" under human sign-off. It is in preview, on its own pay-as-you-go pricing. Microsoft's public pages don't yet say what starts its agents, or whether they can reach data outside Microsoft.
Five questions separate an agentic system from a well-automated one. They apply to any vendor that uses the word agentic, and to any agentic SOC platform on a shortlist. Does it start on its own when an alert fires? Does it decide its next step from what it finds? Can it reach evidence in every tool? Does it finish with a determination? Does it act only within limits the team sets? Applied to what E5 and E7 include, Project Perception, and Prophet AI, the answers look like this:
| Question | Included with E5 and E7 | Project Perception | Prophet AI |
|---|---|---|---|
| Starts on its own when an alert fires? | Playbooks can run automatically when an incident arrives. Attack disruption acts on its own in high-confidence attacks. | Not stated publicly | Investigates 100% of alerts, at every severity, the moment they arrive |
| Decides its next step from what it finds? | Playbooks run the steps written into them. AI helps write the steps. Security Copilot agents each handle one task, such as phishing triage. Microsoft calls Security Copilot "AI that assists." | Agents reason and "hand off to each other automatically" | Plans each investigation dynamically. A risky Entra ID sign-in can lead it to Okta sign-in history, CrowdStrike Falcon activity on the user's laptop, and Zscaler web traffic. |
| Reaches evidence in every tool? | Defender data is included. Okta, CrowdStrike, Zscaler, Proofpoint, AWS, and other outside data cost $2.40 per GB to ingest. | Not stated publicly | Read-only access for investigation to the tools a team already runs, including Okta, CrowdStrike Falcon, Zscaler, Proofpoint, AWS, Splunk, Defender, Entra ID, and Sentinel |
| Finishes with a determination? | The Phishing Triage Agent labels phishing alerts as real threats or false alarms and explains why. Other alerts get AI-powered case summaries. | Blue agents "investigate like your best responder." Output not described. | Reaches a determination, with every question, query, and reasoning step documented |
| Acts only within limits the team sets? | Attack disruption contains devices and disables users on its own, and the team can undo any action. Playbooks act once a team builds and turns them on. | Acts, with "every high-impact action" under human sign-off | Scoped, permissioned remediation, from notifications to quarantining a machine, limited to actions the team has approved |
Sources: Microsoft's ISOC FAQ, automation docs, attack disruption docs, Security Copilot notice, and Project Perception page; Prophet Security's AI SOC Analyst and integrations pages.
For a team with a mixed stack, the third row is the one to read first. An agent can only follow evidence it can reach. If an Okta alert needs CrowdStrike process data to resolve, an agent that only sees Defender data has to stop and hand the case back to an analyst. The same limit applies to detection engineering. A loop that turns investigation results into better detections can only improve detections for the data it sees.
A team can keep ISOC for what E5 and E7 now include and still add an AI SOC platform for investigations that cross Microsoft and non-Microsoft tools.
What to check before Microsoft ISOC becomes the SOC plan
Before finance treats ISOC as the SOC plan, the security team should answer five questions with its own numbers:
- Alert sources. What share of alerts comes from tools outside Microsoft, and how much data do those tools produce each day?
- Ingestion cost. What will $2.40 per gigabyte cost for those sources this year, and at next year's volume?
- Cross-tool investigations. When an alert spans Defender and a non-Microsoft tool, who gathers the evidence from both, and how long does that take?
- Timing. Which agentic features are in the bundle today, which are in preview, and which carry separate pricing?
- Trust. For any AI verdict, can analysts see the queries and evidence behind it? Explainability is a separate test from agency, and both apply.
A proof of value on the team's own alerts answers most of these questions with real numbers.
What Microsoft ISOC means for security operations
Microsoft ISOC changes which license includes SIEM features. For teams that run only Defender, that is useful. For teams with a mixed stack, the cost of non-Microsoft data and the work of investigating across tools stay where they were. Meanwhile, Microsoft's agentic system, Project Perception, is still in preview with its own pricing.
Prophet AI investigates every alert across the tools a team already runs, Microsoft and non-Microsoft alike. See how it works on your own alerts.
Insights
The Roles Your AI-Enabled SOC Will Need
Gartner research on how SOC roles shift as AI SOC agents reduce alert-handling work


.avif)
