MICROSOFT has announced the integrated security operations centre (ISOC) in Microsoft Defender, describing it as a foundation for security operations in an era of AI-enabled, or “agentic”, attacks. The company says attackers can now use agents to automate activity at a scale previously requiring entire teams, while defenders are slowed when protection and security operations run as separate systems.
ISOC combines Microsoft’s security information and event management (SIEM) and threat-protection capabilities so people and agents can use shared signals, context and controls across an environment. Microsoft says this supports an “integrated protection loop” that can detect and disrupt attacks while they are under way, anticipate potential attacker movement, and use exposure information and threat intelligence to improve protection in near real time.
The company also says practitioners can investigate, hunt, automate, manage incidents and act from the same foundation, rather than stitching together multiple tools. People remain responsible for priorities, judgement and desired outcomes, while agents handle more continuous work at speed and scale.
Microsoft introduced the ISOC announcement on 23 September 2026, and said the capability is available in preview. It has not described a specific incident or confirmed exploitation in the announcement. The company directed organisations to its ISOC information page, a recording of the launch announcement and a white paper titled “Agentic SOC: The new operating model for continuous defence”.