Microsoft Reimagines the SOC for the Agentic Era With Defender
Microsoft is bringing SIEM and threat protection together in Microsoft Defender with its new ISOC approach, designed to help security teams and AI agents detect, investigate and respond across an environment from a shared foundation.
Xcademia Team
Xcademia Research Team

Microsoft is reshaping its vision for security operations as AI agents become increasingly involved in both cyberattacks and defensive workflows.
Microsoft introduced the integrated security operations center (ISOC) in Microsoft Defender, a foundation designed to bring security information and event management (SIEM) and threat protection together. Microsoft says the approach is intended to give both people and agents a shared foundation for seeing, understanding and acting across an environment.
The announcement reflects a broader change in how Microsoft views the security operations centre (SOC). Rather than treating security operations and protection as separate systems connected through multiple integrations, Microsoft is proposing a more integrated model for agentic security.
Why Microsoft says the SOC needs to change
Microsoft argues that AI is changing the speed and scale of cyber operations.
According to the company, attackers are increasingly using agents to automate execution. In this environment, Microsoft says security teams can face delays when protection and security operations depend on separate systems, because handoffs, integrations and boundaries can add complexity.
Microsoft's proposed answer is ISOC.
The concept is based on bringing security operations and native protection together so that security teams and agents can work with the same underlying signals, context and controls.
This is important because an AI agent cannot operate effectively from intelligence alone. It needs access to information about what is happening, enough context to understand those signals and controls capable of translating decisions into protective action.

ISOC brings SIEM and threat protection together
At the centre of Microsoft's announcement is the integration of SIEM and threat protection within Microsoft Defender.
Microsoft describes ISOC as a foundation for agentic security that enables people and agents to operate from a shared system instead of requiring separate security environments.
The company says this foundation is designed around several layers:
Signals and sensors provide visibility into the environment.
Context turns security signals into understanding.
Agents use that information to help investigate and act.
Models and orchestration support reasoning and coordinated activity.
Actuators and controls translate decisions into protective action.
Microsoft says these layers need to work together because agents depend on the broader security stack rather than operating as an isolated AI capability.
The announcement builds on Microsoft's earlier work on an end-to-end cyber stack and Project Perception, which Microsoft introduced in July 2026. That initiative focused on models, a harness and specialised agents designed to help defenders perceive, reason and act at machine speed.

From linear workflows to an integrated protection loop
Microsoft also describes ISOC as a way to move away from linear security workflows.
Traditional security processes can require teams to collect signals, investigate them, gather additional context and then move between systems before taking action.
Microsoft's proposed model is an integrated protection loop in which signals, context and controls work together continuously.
The company points to attack disruption in Microsoft Defender as an example of what this approach is intended to enable.
According to Microsoft, telemetry and controls can help the system detect, predict and adapt to an attacker while an attack is still unfolding. Exposure insights can then contribute to strengthening protection, while threat intelligence helps focus the protection loop on relevant threats.
The important concept is not simply automated detection. It is the connection between what the security environment observes, what defenders learn from those observations and how that information can feed back into protection.
Microsoft says ISOC is intended to make this loop native rather than requiring organisations to assemble, tune and maintain the complete workflow themselves.

A different operating model for security practitioners
Microsoft also positions ISOC as a change to how security practitioners interact with security technology.
The company says practitioners have historically had to compensate for boundaries between security systems by connecting signals, rebuilding context and moving between tools.
Microsoft says ISOC brings capabilities for investigation, threat hunting, automation, incident management, threat understanding and response together within the same foundation.
The intended effect is to allow security teams to organise their work around security outcomes rather than around the boundaries between individual tools.
This does not mean Microsoft is removing people from the security process.
Instead, the company explicitly describes a division of responsibilities in which agents provide speed and scale while people establish priorities, apply judgement and define the outcomes that matter.
That distinction is particularly relevant as organisations consider how much autonomy to give security agents.
An agentic SOC still requires humans to determine what should be protected, which risks matter most and what outcomes are acceptable.
AI agents become part of the security workflow
Microsoft's announcement also highlights a shift from AI as an individual security feature toward AI agents operating across a broader security environment.
In Microsoft's model, agents can use the same context and controls available to practitioners to investigate, reason and act.
The company says the integrated protection loop can also take on more continuous detection and defence activity as autonomy increases.
Microsoft therefore presents the agentic SOC as a combination of human expertise and machine-scale execution.
The announcement's central message is that adding AI to an existing collection of disconnected security tools may not be sufficient. The underlying security architecture also needs to provide the signals, context and controls that agents require.
What this means for enterprise security teams
For enterprises, the development highlights several areas that are likely to become increasingly important as AI becomes part of security operations.
First, security architecture matters alongside AI capability. An intelligent agent still depends on access to reliable signals, relevant context and appropriate controls.
Second, integration can become an operational concern. If agents need to move across disconnected systems, the complexity that already affects human analysts can also affect automated workflows.
Third, human oversight remains central. Microsoft's model places people in control of priorities, judgement and desired security outcomes while agents provide additional speed and scale.
These points are Microsoft’s stated approach rather than an independent assessment of how the technology will perform in every enterprise environment.
Specific deployment requirements, performance measurements and customer results were not provided in the announcement. Additional details were not disclosed in the announcement.
Microsoft makes ISOC available in preview
Microsoft says Integrated Security Operations Center (ISOC) in Microsoft Defender is available in preview.
The company has also made available a recording of the full announcement and a whitepaper titled "Agentic SOC: The new operating model for continuous defense."
The preview status means the announcement describes Microsoft's current direction and available preview capability rather than a final assessment of the technology across all enterprise environments.
The broader direction of the SOC
The announcement points to a larger shift in security operations.
As AI agents become capable of carrying out increasingly complex tasks, security teams are considering how agents can participate in detection, investigation and response. At the same time, organisations need to determine where human judgement should remain central.
Microsoft's ISOC concept attempts to address both sides by combining the underlying security stack with agentic capabilities while keeping human priorities and judgement in the operating model.
The broader industry question is therefore moving beyond "How can AI help the SOC?"
It is increasingly becoming "How should the SOC itself be designed when both attackers and defenders can use AI agents?"
Microsoft's answer is an integrated model in which people and agents operate from shared signals, context and controls.
The effectiveness of that model will depend on how organisations implement it, govern agent activity and integrate it into their existing security operations.
Source: Microsoft Security Blog
About the Author