The Pulse
Microsoft Puts Agentic Security Operations Inside Defender
Microsoft is introducing an Integrated Security Operations Center, or ISOC, inside Microsoft Defender. The preview combines SIEM, threat protection, shared security context, and controls for human analysts and AI agents.

AI.info Team ·
Microsoft is putting an Integrated Security Operations Center, or ISOC, inside Microsoft Defender, bringing security information and event management and threat protection into a shared system designed for human analysts and AI agents.
The company announced the preview on September 23, 2026, in a post by Rob Lefferts, corporate vice president of Microsoft Threat Protection. Microsoft presents ISOC as the foundation for an agent-enabled security operations center rather than as a separate AI product layered on top of existing tools.
“Today we are announcing ISOC in Microsoft Defender,” Microsoft says in the announcement. The system gives people and agents a common base for seeing, understanding, and acting across an organization’s environment without requiring teams to maintain separate operational boundaries between security tools.
Microsoft joins SIEM and threat protection
Microsoft’s argument is that security operations cannot move at machine speed when detection, investigation, and protection sit in separate systems. Each handoff forces analysts or software agents to transfer data, reconstruct context, and connect controls before taking action.
ISOC combines those functions around three layers: signals and sensors that provide visibility, context that turns events into an explanation of what is happening, and actuators that carry decisions into protective action. Microsoft describes the arrangement as a shared foundation for both operators and agents.
The company introduced a related end-to-end cyber stack in July alongside Project Perception. That stack includes models, a harness, and specialized agents, but Microsoft’s September announcement argues that orchestration alone is not enough. The surrounding security data and controls must also work together before agents can operate across a full environment.
From linear workflows to a protection loop
Microsoft says ISOC is designed to replace a sequence of isolated tasks with an integrated protection loop. Telemetry and controls can help Defender detect and disrupt an attack while it is underway, then use what the system learns to improve protection against the next move.
The company points to attack disruption in Microsoft Defender as an example. Exposure insights can inform protection decisions in near real time, while threat intelligence focuses the response on activity Microsoft considers most relevant to the organization.
Microsoft does not describe ISOC as a fully autonomous replacement for security teams. Its model assigns agents continuous work involving detection, investigation, and defense, while people set priorities, apply judgment, and define the outcomes the system should pursue.
Analysts get one operating surface
Security practitioners have traditionally moved among separate tools to investigate incidents, hunt for threats, automate responses, manage cases, and understand attacker behavior. Microsoft says ISOC brings those capabilities together and makes them available by default within Defender.
The change is intended to let teams organize their work around security outcomes instead of the boundaries between products. Agents can investigate and reason with the same context and controls available to analysts, reducing the need to build a separate agent layer or connect each agent to a different set of systems.
Microsoft’s related documentation already describes agents for tasks such as alert triage and attack investigation. The Attack Investigation Agent, for example, starts from an alert or incident and correlates signals in Defender to reconstruct an attack’s story, scope, and impact. Microsoft identifies that capability as part of Project Perception and as a limited public preview.
ISOC enters preview as Microsoft expands agentic defense
ISOC in Microsoft Defender is available in preview as of September 23. Microsoft also points users to a whitepaper titled Agentic SOC: The new operating model for continuous defense and a recording of the full announcement.
The preview places Microsoft’s agent strategy inside the company’s existing security platform instead of presenting autonomous operations as a standalone product. Its practical test will be whether shared telemetry, context, and controls can help agents perform more of the continuous work without weakening the human decisions that govern a security program.