Microsoft integrates SOC capabilities with Defender for enterprises
Summary
Microsoft has integrated SIEM (security information and event management, a tool that collects and analyzes security logs from across an organization) capabilities into Microsoft Defender through a new feature called the Integrated Security Operations Center (ISOC), available at no extra cost to Microsoft 365 E5 and E7 customers. ISOC combines SIEM with Defender's existing XDR (extended detection and response, a unified security platform), threat intelligence, and AI tools into one portal to help security teams respond faster to attacks. The feature launched as a public preview on September 23 and currently includes 30 days of data retention from Microsoft's own security products, with additional data sources available on a pay-as-you-go basis starting October 1.
Classification
Original source: https://www.csoonline.com/article/4226195/microsoft-integrates-soc-capabilities-with-defender-for-enterprises.html
First tracked: September 24, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%