Most organisations have invested in a wide range of security tools; what they often lack is a unified environment that brings those tools, data and people together to deliver effective protection.
A threat might be detected in one platform, investigated in another and contained using a third. Each handover adds friction, making analysts piece together evidence, rebuild context and juggle separate controls while an incident is still active.
Adding artificial intelligence does not resolve this core issue. Agents are limited by the architecture, data and permissions they can access. If your security environment is fragmented, agents will inherit those same gaps.
Microsoft ISOC tackles this challenge at its root. Built into Microsoft Defender, it connects security operations and native protection in a single environment. People and agents gain shared signals, context and controls, making it easier to see, understand and act on threats.
The scale of that challenge continues to grow. According to the Microsoft Digital Defense Report 2026, Microsoft now processes more than 165 trillion security signals every day, analyses 31 million identity-risk detections on an average day, and screens approximately 5.2 billion emails daily for malware and phishing. The challenge for security teams is not simply collecting more information, but correlating it quickly enough to distinguish isolated activity from a connected attack.
ISOC stands for integrated security operations centre. It forms the Microsoft foundation for unifying SIEM, XDR, threat intelligence, automation and agentic security within a connected Defender experience.
The model brings together 3 complementary capabilities:
ISOC is not a managed SOC service. It provides the technology foundation, but your organisation or security partner remains responsible for day-to-day operations, risk interpretation and governance. Microsoft Sentinel continues as part of the model and is not replaced.
As a Microsoft Security Elite Partner, CyberOne works closely with Microsoft’s evolving security roadmap. Our experts gain earlier technical insight, priority access to private previews and direct engagement with Microsoft’s product and engineering teams. This enables us to understand emerging capabilities in depth.
This approach helps CyberOne assess how developments like ISOC can complement your existing Microsoft investments and managed security services. We only introduce change when its operational value and governance requirements are clear.
ISOC is especially relevant for organisations with higher-tier Microsoft security licensing, but it is not limited to E5 and E7 customers.
Microsoft currently states that ISOC eligibility requires:
Microsoft also states that there is no minimum seat threshold for eligible Microsoft 365 E5 and E7 customers, although standard product terms apply. Eligible government and sovereign-cloud customers are included in Microsoft’s stated eligibility.
For eligible E5 and E7 customers, Microsoft says ISOC expands the value of their existing investment by adding security-operations capabilities such as workbooks and natural language to Security Orchestration, Automation and Response, or SOAR, that previously required a separate Sentinel purchase.
Not every Sentinel capability, connected data source or unlimited data ingestion is included without extra cost. Organisations should review:
ISOC and Project Perception are currently in preview. Availability, entitlements, pricing and product terms may change before or after general release. Organisations should confirm the latest Microsoft documentation and commercial terms before making long-term decisions.
Project Perception is Microsoft’s agentic security system. It brings together specialised red, blue and green agents that reason across security data, tools and workflows.
Microsoft says the agents are intended to share intelligence through coordinated workflows. Defenders establish objectives and guardrails, while high-impact actions remain under human sign-off.
The distinction is:
A traditional SOC describes an organisational capability. It brings together people, operational processes, security technologies, escalation paths, decision-making authority and accountability for security outcomes.
ISOC within Microsoft Defender delivers the integrated technology foundation that supports and strengthens your organisational SOC.
The distinction matters. A SOC may use technologies from several vendors. It must decide which risks deserve attention, who owns an investigation, when an incident should be escalated and which actions are appropriate for the business. Those remain organisational decisions regardless of where alerts, cases or response controls appear.
Microsoft ISOC is designed to break down the barriers between SIEM, XDR, threat intelligence, automation and agentic workflows. The model is built around shared signals, context and controls, drawing on both first-party and third-party data, with operations focused on threat-led workflows within the Defender platform.
This ability to correlate information across security domains is increasingly important. Microsoft reports that 52.2% of intrusions involving valid accounts led to further credential theft, showing how the compromise of one identity can create the conditions for additional identities and systems to be targeted. An alert viewed in isolation may reveal only the first step; connected identity, endpoint, cloud, application and email signals can help expose the wider attack path.
This ability to correlate information across security domains is increasingly important. Microsoft reports that 52.2% of intrusions involving valid accounts led to further credential theft, showing how the compromise of one identity can create the conditions for additional identities and systems to be targeted. An alert viewed in isolation may reveal only the first step; connected identity, endpoint, cloud, application and email signals can help expose the wider attack path.
ISOC does not replace the SOC. It shifts the technical foundation, enabling the SOC to operate from a more connected and effective starting point.
ISOC does not automatically replace an existing Managed Detection and Response (MDR) or Managed eXtended Detection and Response (MXDR) service.
Instead, it changes the Microsoft technology foundation on which security operations may increasingly be delivered. The practical impact depends on who currently operates your service.
As a Microsoft Security Elite Partner, CyberOne is working closely with Microsoft to evaluate ISOC and maximise the value of its capabilities alongside our MXDR as a Service offering. This collaboration gives our teams a deeper understanding of how Microsoft’s evolving security foundation could support more connected detection, investigation and response.
We are assessing each capability against customers’ existing Microsoft environments, detections, workflows, licensing and governance requirements. Our priority is to introduce improvements where they deliver clear operational value, while maintaining service continuity, appropriate human oversight and customer control.
Internally managed Security Operations Centres will need to assess how ISOC affects their Microsoft architecture, licensing, analyst workflows, permissions, detection engineering, automation and escalation model. A more integrated platform may simplify parts of security operations, but the organisation remains responsible for configuring, operating and governing the environment.
Organisations working with another Managed Detection and Response or Managed eXtended Detection and Response provider should understand how that provider is preparing for ISOC and agentic security. This includes confirming whether the organisation’s current licensing meets Microsoft’s eligibility requirements, how existing detections and response workflows could be affected, and who will evaluate preview capabilities before they are considered for production use.
The provider should also be able to explain how consumption-based agent costs would be monitored, which actions would remain subject to customer approval, and how any service changes would be tested, communicated and audited.
Microsoft connects ISOC directly to the development of agentic security. The logic is that intelligence and orchestration are not enough on their own. Agents also need the surrounding security environment to function coherently.
This shift is happening at considerable scale. The Microsoft Digital Defense Report 2026 states that 88% of enterprises are already experimenting with AI agents, while 82% of leaders plan broader deployments within the next 12 to 18 months. It also cites industry projections suggesting that approximately 1.3 billion AI agents could be in production by 2028. As the number of agents and automated actions grows, security teams need a consistent foundation for identity, data access, permissions, telemetry and response governance.
Microsoft describes three essential layers:
These layers determine what an agent can perceive, how it interprets a situation and what it is permitted to do next.
This creates a key operational principle: as organisations introduce more autonomy, fragmented context becomes increasingly unacceptable.
A human analyst can recognise that an asset name is misleading, contact a system owner or question an apparently routine event involving a business-critical identity. An agent works with the context, objectives, permissions and controls made available to it.
The real value of ISOC is not simply adding another AI capability, but establishing a common operational foundation that enables agentic capabilities to be used and governed effectively.
A common platform can remove technical barriers, but it cannot by itself resolve unclear ownership, weak detection logic, poor data quality, excessive permissions, inconsistent escalation or disagreement over risk. These are organisational factors that determine whether platform integration leads to real operational integration.
A SOC is not truly integrated just because its tools are in one portal. Real integration happens when signals, responsibilities and decisions move through the organisation without losing context or accountability.
Security leaders should therefore ask:
This is also why detection engineering becomes more important as autonomy grows. Greater operating speed increases the value of reliable detection logic, well-defined thresholds and controlled response paths. It does not remove the need for them.
The opportunity is to free analysts from repetitive information gathering, so they can focus on applying judgement, setting priorities and improving security outcomes. Achieving this requires more than a shared portal. It demands clear processes for how work, decisions and accountability flow across the organisation.
As a Microsoft Security Elite Partner, CyberOne has earlier technical insight, structured access to Microsoft teams and closer engagement with the Microsoft Security roadmap.
CyberOne’s published description of the programme includes direct technical engagement with Microsoft Security engineering teams, access to product managers, early roadmap insight and priority access to private previews.
This relationship helps CyberOne understand emerging capabilities earlier and assess how they may affect existing Microsoft security environments, licensing decisions and managed services.
That insight is combined with CyberOne’s established MXDR capability. Its 24×7 Global SOC operates within customers’ Microsoft environments, providing continuous monitoring, investigation and response, supported by tuned detections, threat intelligence, customer collaboration and auditable reporting.
Microsoft develops the security foundation. CyberOne helps customers understand the eligibility, operational impact and potential value of relevant capabilities before introducing them into live security services.
Technology alone is not enough. Detections need tuning, investigations require validation and significant actions must be governed by clear processes.
The SOC of the future may use more agentic capabilities, but it must remain human-led, governed and focused on measurable business risk.
If you want to strengthen your detection and response, speak to a CyberOne expert. Our MXDR as a Service helps protect your business, reduce risk and build lasting cyber resilience.
Reimagining the SOC for the agentic era in Microsoft Defender | Microsoft Security Blog
What Is Microsoft Project Perception? The Red, Blue and Green Security Agents Explained