Reimagining the SOC for the agentic era in Microsoft Defender
Summary
Microsoft is announcing an Integrated Security Operations Center (ISOC) in Microsoft Defender that combines SIEM (security information and event management, which collects and analyzes security data from across a network) and threat protection into one unified system. This design addresses the challenge that cyberattackers now use AI agents to automate attacks at massive scale, requiring defenders to operate faster by eliminating delays caused by separate, disconnected security tools. ISOC enables both human security teams and AI agents to work together using shared signals, context, and controls to detect threats, predict attacks, and respond in real-time.
Classification
Affected Vendors
Related Issues
Original source: https://www.microsoft.com/en-us/security/blog/2026/09/23/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender/
First tracked: September 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%