• Home
  • Blog
  • Microsoft ISOC Explained: What Is ISOC and How Is It Different From a Traditional SOC?
Blog Banners
Microsoft ISOC Explained What Is ISOC and How Is It Different From a Traditional SOC?
13:20

Most organisations have invested in a wide range of security tools; what they often lack is a unified environment that brings those tools, data and people together to deliver effective protection.

A threat might be detected in one platform, investigated in another and contained using a third. Each handover adds friction, making analysts piece together evidence, rebuild context and juggle separate controls while an incident is still active.

Adding artificial intelligence does not resolve this core issue. Agents are limited by the architecture, data and permissions they can access. If your security environment is fragmented, agents will inherit those same gaps.

Microsoft ISOC tackles this challenge at its root. Built into Microsoft Defender, it connects security operations and native protection in a single environment. People and agents gain shared signals, context and controls, making it easier to see, understand and act on threats.

The scale of that challenge continues to grow. According to the Microsoft Digital Defense Report 2026, Microsoft now processes more than 165 trillion security signals every day, analyses 31 million identity-risk detections on an average day, and screens approximately 5.2 billion emails daily for malware and phishing. The challenge for security teams is not simply collecting more information, but correlating it quickly enough to distinguish isolated activity from a connected attack.

What Is Microsoft ISOC?

ISOC stands for integrated security operations centre. It forms the Microsoft foundation for unifying SIEM, XDR, threat intelligence, automation and agentic security within a connected Defender experience.

The model brings together 3 complementary capabilities:

  • Microsoft Defender provides threat protection, Extended Detection and Response (XDR) and automated attack-disruption capabilities.
  • Microsoft Sentinel provides SIEM capabilities that unify security data and support wider security operations.
  • Project Perception provides specialised artificial intelligence agents and coordinated multi-agent workflows across security data, tools and processes.

ISOC is not a managed SOC service. It provides the technology foundation, but your organisation or security partner remains responsible for day-to-day operations, risk interpretation and governance. Microsoft Sentinel continues as part of the model and is not replaced.

“Microsoft’s ISOC represents an important step forward for modern security operations, giving teams a more connected foundation across data, protection and AI. By combining that innovation with continuous monitoring, expert judgement and governed response, businesses can make faster, more confident security decisions and strengthen their overall resilience.”
— Ben Harding, Sales & Microsoft Alliance Director, CyberOne

 

As a Microsoft Security Elite Partner, CyberOne works closely with Microsoft’s evolving security roadmap. Our experts gain earlier technical insight, priority access to private previews and direct engagement with Microsoft’s product and engineering teams. This enables us to understand emerging capabilities in depth.

This approach helps CyberOne assess how developments like ISOC can complement your existing Microsoft investments and managed security services. We only introduce change when its operational value and governance requirements are clear.

Who Is Eligible for Microsoft ISOC?

ISOC is especially relevant for organisations with higher-tier Microsoft security licensing, but it is not limited to E5 and E7 customers.

Microsoft currently states that ISOC eligibility requires:

  • An active Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 licence; and
  • An Azure subscription.

Microsoft also states that there is no minimum seat threshold for eligible Microsoft 365 E5 and E7 customers, although standard product terms apply. Eligible government and sovereign-cloud customers are included in Microsoft’s stated eligibility.

For eligible E5 and E7 customers, Microsoft says ISOC expands the value of their existing investment by adding security-operations capabilities such as workbooks and natural language to Security Orchestration, Automation and Response, or SOAR, that previously required a separate Sentinel purchase.

Not every Sentinel capability, connected data source or unlimited data ingestion is included without extra cost. Organisations should review:

  • Their precise licence entitlement;
  • Azure requirements;
  • Included data benefits;
  • Microsoft Sentinel usage;
  • Project Perception consumption;
  • Any additional security-suite requirements.

ISOC and Project Perception are currently in preview. Availability, entitlements, pricing and product terms may change before or after general release. Organisations should confirm the latest Microsoft documentation and commercial terms before making long-term decisions.

Where Does Project Perception Fit?

Project Perception is Microsoft’s agentic security system. It brings together specialised red, blue and green agents that reason across security data, tools and workflows.

  • Red agents probe from an attacker-oriented perspective.
  • Blue agents investigate threats.
  • Green agents remediate and harden.

Microsoft says the agents are intended to share intelligence through coordinated workflows. Defenders establish objectives and guardrails, while high-impact actions remain under human sign-off.

The distinction is:

  • Project Perception provides the agentic system, including specialised agents, models and orchestration.
  • ISOC provides the integrated security foundation of signals, context and controls.
  • The human SOC remains accountable for direction, judgement and critical decisions.

How Is ISOC Different From a Traditional SOC?

A traditional SOC describes an organisational capability. It brings together people, operational processes, security technologies, escalation paths, decision-making authority and accountability for security outcomes.

ISOC within Microsoft Defender delivers the integrated technology foundation that supports and strengthens your organisational SOC.

Traditional SOC vs Microsofts ISOC infographic showing the differences between Traditional SOC and Microsoft's ISOC

The distinction matters. A SOC may use technologies from several vendors. It must decide which risks deserve attention, who owns an investigation, when an incident should be escalated and which actions are appropriate for the business. Those remain organisational decisions regardless of where alerts, cases or response controls appear.

Microsoft ISOC is designed to break down the barriers between SIEM, XDR, threat intelligence, automation and agentic workflows. The model is built around shared signals, context and controls, drawing on both first-party and third-party data, with operations focused on threat-led workflows within the Defender platform.

This ability to correlate information across security domains is increasingly important. Microsoft reports that 52.2% of intrusions involving valid accounts led to further credential theft, showing how the compromise of one identity can create the conditions for additional identities and systems to be targeted. An alert viewed in isolation may reveal only the first step; connected identity, endpoint, cloud, application and email signals can help expose the wider attack path.

This ability to correlate information across security domains is increasingly important. Microsoft reports that 52.2% of intrusions involving valid accounts led to further credential theft, showing how the compromise of one identity can create the conditions for additional identities and systems to be targeted. An alert viewed in isolation may reveal only the first step; connected identity, endpoint, cloud, application and email signals can help expose the wider attack path.

ISOC does not replace the SOC. It shifts the technical foundation, enabling the SOC to operate from a more connected and effective starting point.

What Does ISOC Mean for Your Existing MDR or MXDR Service?

ISOC does not automatically replace an existing Managed Detection and Response (MDR) or Managed eXtended Detection and Response (MXDR) service.

Instead, it changes the Microsoft technology foundation on which security operations may increasingly be delivered. The practical impact depends on who currently operates your service.

If CyberOne manages your MXDR service

As a Microsoft Security Elite Partner, CyberOne is working closely with Microsoft to evaluate ISOC and maximise the value of its capabilities alongside our MXDR as a Service offering. This collaboration gives our teams a deeper understanding of how Microsoft’s evolving security foundation could support more connected detection, investigation and response.

We are assessing each capability against customers’ existing Microsoft environments, detections, workflows, licensing and governance requirements. Our priority is to introduce improvements where they deliver clear operational value, while maintaining service continuity, appropriate human oversight and customer control.

 

“For existing MDR and MXDR customers, ISOC should be viewed as an evolution of the Microsoft security foundation rather than an automatic change to the service they receive. Our responsibility is to understand each new capability, assess where it adds genuine operational value and introduce change in a controlled way that protects service continuity and customer governance.”
— Luke Elston, Microsoft Practice Director, CyberOne

 

If You Manage Your Own SOC

Internally managed Security Operations Centres will need to assess how ISOC affects their Microsoft architecture, licensing, analyst workflows, permissions, detection engineering, automation and escalation model. A more integrated platform may simplify parts of security operations, but the organisation remains responsible for configuring, operating and governing the environment.

If Another Provider Manages Your MDR or MXDR

Organisations working with another Managed Detection and Response or Managed eXtended Detection and Response provider should understand how that provider is preparing for ISOC and agentic security. This includes confirming whether the organisation’s current licensing meets Microsoft’s eligibility requirements, how existing detections and response workflows could be affected, and who will evaluate preview capabilities before they are considered for production use.

The provider should also be able to explain how consumption-based agent costs would be monitored, which actions would remain subject to customer approval, and how any service changes would be tested, communicated and audited.

Why Is Microsoft Introducing ISOC in the Agentic Era?

Microsoft connects ISOC directly to the development of agentic security. The logic is that intelligence and orchestration are not enough on their own. Agents also need the surrounding security environment to function coherently.

This shift is happening at considerable scale. The Microsoft Digital Defense Report 2026 states that 88% of enterprises are already experimenting with AI agents, while 82% of leaders plan broader deployments within the next 12 to 18 months. It also cites industry projections suggesting that approximately 1.3 billion AI agents could be in production by 2028. As the number of agents and automated actions grows, security teams need a consistent foundation for identity, data access, permissions, telemetry and response governance.

Microsoft describes three essential layers:

  • Signals and sensors give the system awareness.
  • Context converts signals into understanding.
  • Actuators turn decisions into protective action.

These layers determine what an agent can perceive, how it interprets a situation and what it is permitted to do next.

This creates a key operational principle: as organisations introduce more autonomy, fragmented context becomes increasingly unacceptable.

A human analyst can recognise that an asset name is misleading, contact a system owner or question an apparently routine event involving a business-critical identity. An agent works with the context, objectives, permissions and controls made available to it.

The real value of ISOC is not simply adding another AI capability, but establishing a common operational foundation that enables agentic capabilities to be used and governed effectively.

Integration Does Not Automatically Create an Integrated SOC

A common platform can remove technical barriers, but it cannot by itself resolve unclear ownership, weak detection logic, poor data quality, excessive permissions, inconsistent escalation or disagreement over risk. These are organisational factors that determine whether platform integration leads to real operational integration.

A SOC is not truly integrated just because its tools are in one portal. Real integration happens when signals, responsibilities and decisions move through the organisation without losing context or accountability.

Security leaders should therefore ask:

  • Who owns a case from detection through remediation?
  • Which source of information is considered authoritative?
  • Which actions may automation or agents perform independently?
  • Which actions require human approval?
  • Can analysts and agents access the business context needed to make an appropriate decision?
  • Can the organisation reconstruct why an action was taken?
  • Who is accountable when an automated action produces an unexpected result?

This is also why detection engineering becomes more important as autonomy grows. Greater operating speed increases the value of reliable detection logic, well-defined thresholds and controlled response paths. It does not remove the need for them.

The opportunity is to free analysts from repetitive information gathering, so they can focus on applying judgement, setting priorities and improving security outcomes. Achieving this requires more than a shared portal. It demands clear processes for how work, decisions and accountability flow across the organisation.

Why CyberOne for the Next Stage of Microsoft Security?

As a Microsoft Security Elite Partner, CyberOne has earlier technical insight, structured access to Microsoft teams and closer engagement with the Microsoft Security roadmap.

CyberOne’s published description of the programme includes direct technical engagement with Microsoft Security engineering teams, access to product managers, early roadmap insight and priority access to private previews.

This relationship helps CyberOne understand emerging capabilities earlier and assess how they may affect existing Microsoft security environments, licensing decisions and managed services.

That insight is combined with CyberOne’s established MXDR capability. Its 24×7 Global SOC operates within customers’ Microsoft environments, providing continuous monitoring, investigation and response, supported by tuned detections, threat intelligence, customer collaboration and auditable reporting.

Microsoft develops the security foundation. CyberOne helps customers understand the eligibility, operational impact and potential value of relevant capabilities before introducing them into live security services.

The SOC Is Not Disappearing, But Its Centre of Gravity Is Changing

Technology alone is not enough. Detections need tuning, investigations require validation and significant actions must be governed by clear processes.

The SOC of the future may use more agentic capabilities, but it must remain human-led, governed and focused on measurable business risk.

If you want to strengthen your detection and response, speak to a CyberOne expert. Our MXDR as a Service helps protect your business, reduce risk and build lasting cyber resilience.

Frequently Asked Questions

Who is eligible for Microsoft ISOC?

 Microsoft currently states that eligibility requires an active Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 licence, together with an Azure subscription. There is no minimum seat threshold for eligible E5 and E7 customers, although standard product terms apply. 

Is ISOC included with Microsoft 365 E5 and E7?

 Microsoft says ISOC expands the value of Microsoft 365 E5 and E7 with security-operations capabilities that previously required a separate Sentinel purchase. This should not be interpreted as every Sentinel capability, connected data source or level of consumption being included without additional cost. Customers should verify their precise entitlement and usage requirements. 

How is Project Perception priced?

 Microsoft describes Project Perception as consumption-based and pay-as-you-go. Usage is measured in Security Compute Units, with different agents consuming units at different rates according to task intensity.  

Does ISOC replace Microsoft Sentinel or an existing MDR service?

 No. Microsoft presents Sentinel as part of the ISOC foundation, and says the existing Sentinel offering will continue. ISOC also does not automatically replace an MDR or MXDR service, which provides the people, processes and continuous operation around the technology.  

Could ISOC eligibility and pricing change?

 ISOC and Project Perception are currently described as preview capabilities. Customers should treat current availability, entitlements and consumption terms as subject to further Microsoft clarification or change, and verify the latest documentation before making contractual or financial decisions. 

 

Sources:

 

 

Share this post

Related Articles