Microsoft ISOC: What Changes for Defender and Sentinel

Phil Kinsley

Field CTO, Security

Microsoft ISOC changes the starting point for Microsoft security operations by bringing more SIEM-style workflows directly into Defender. The bigger question is not whether Sentinel disappears, but which SOC functions still need the SIEM data plane.


Microsoft announced its Integrated Security Operations Center (ISOC) last week, and after spending some time working through the public documentation, I think the more significant change is where Microsoft expects security operations to start.

ISOC Changes The Starting Point For Security Operations

ISOC isn’t Sentinel renamed, it isn’t Microsoft replacing Sentinel, and it isn’t a managed SOC service. What Microsoft appears to be doing is changing the starting point for security operations.

For years, Defender and Sentinel have generally served different purposes. Defender was where analysts worked with Microsoft’s native detections, investigations and response capabilities, while Sentinel extended security operations into broader data ingestion, analytics, UEBA, automation and more traditional SIEM use cases.

ISOC brings those models much closer together. For eligible Microsoft 365 E5, E7 and Defender Suite customers, capabilities including case management, workbooks built around Defender data and new automation can now operate directly inside Defender. That means organizations can start using those capabilities without first standing up what most of us would consider a traditional Sentinel deployment.


What Microsoft ISOC Actually Changes

Microsoft ISOC does not replace Sentinel. In its current preview, ISOC lets eligible organizations use capabilities such as case management, workbooks, and automation directly in Microsoft Defender, then add workspace-backed SIEM capabilities when they need broader data ingestion, UEBA, Content Hub, threat intelligence, or other advanced functions.

During the current preview, Microsoft is targeting eligible customers that don’t already have an active Sentinel workspace, so existing Sentinel customers shouldn’t interpret this as an immediate migration requirement.


A Defender-First Adoption Path

For a Microsoft-centric security team, that changes the adoption path. Defender can increasingly become the operational starting point, with workspace-backed SIEM capabilities added when the organization actually needs broader telemetry, UEBA, Content Hub, threat intelligence or other functions that still depend on that layer.

That also means the workspace hasn’t gone away, nor have Log Analytics and ingestion costs. The difference is that organizations can be more deliberate about what genuinely needs to be brought into the SIEM rather than treating it as the mandatory destination for every Defender data set.

Start With Defender, Add SIEM Where Needed
The opportunity is to use Defender as the operational starting point, then introduce workspace-backed capabilities where broader telemetry, analytics, retention, or workflow requirements justify them.


The Bigger Challenge Is Operationalizing ISOC

Where I think this becomes much more important is operationalizing it. Turning on capabilities is relatively easy compared with deciding where analysts should investigate, what data genuinely needs to be ingested, which actions can safely be automated and who owns the response when something doesn’t go as expected.

I could easily see organizations recreating their existing Sentinel architecture inside this new model and assuming the operating model has meaningfully changed. In doing so, they may miss much of the value Microsoft is trying to create.

A more practical approach may be to understand what the team can already investigate and respond to natively in Defender, then add workspace-backed functionality where the team actually needs the telemetry, analytics, retention or workflow that comes with it.

Automation Still Requires Governance

The same applies as automation and agentic capabilities expand. The question isn’t simply whether Microsoft can automate an action, but when that action should occur, how much authority the organization is prepared to delegate, and where human approval still belongs.

Automation Is a Governance Decision
The question is not simply whether Microsoft can automate an action. It is when that action should occur, how much authority the organization is prepared to delegate, and where human approval still belongs.


Keep The Boundaries Clear

ISOC isn’t an MDR service, and it isn’t the same thing as Project Perception, which remains a separate multi-agent capability in limited preview. Automatic Attack Disruption already exists in Defender XDR as well, so the significance of ISOC is less about creating these capabilities from scratch and more about bringing existing and emerging security operations functions into a more integrated model.

Continue the Security Operations Conversation

What happens when threats keep growing, but your security team doesn’t?

Join eGroup for a live discussion on Microsoft ISOC, SIEM and XDR, automation, AI, and how security teams can evolve their operating model without simply adding more headcount.

Explore the full agenda, session details, and registration information on the event page.


The Better Question Isn’t Whether ISOC Replaces Sentinel

I don’t think the most useful conversation is whether ISOC replaces Sentinel. I’d be looking instead at which parts of the SOC still require the SIEM data plane, which can now be handled directly in Defender, and whether that creates an opportunity to simplify how the security team actually operates.

That’s the conversation I’m planning to have with my customers right now.


Modernize Your Security Operations

Evaluate where Defender, Sentinel, automation, and SIEM capabilities fit in your operating model and identify opportunities to simplify security operations.

Get in Touch with Us

Connect with an expert to learn what we can do for your business.

One More Step!

Your Win Wires registration is complete. Request Microsoft access to open the customer documents.

Use the same work email you registered with. Microsoft access is only requested once, unless it expires or is revoked.

Get Access to Win Wires

Enter your name and work email to set up your Win Wires account.

Next, you’ll request access to the Win Wires documents through Microsoft. You’ll only need to complete registration once.

October 21, 2026 • Cloud, AI, and Security Virtual Workshop • 1–5 PM ET