What is ISOC in Microsoft Defender?
Gartner describes ISOC (Integrated Security Operations Center) as a converged technology approach that combines threat detection, investigation, and response (TDIR) in a single-vendor suite or cloud service.1 For Microsoft, that means Defender XDR and Microsoft Sentinel. This shift started a while ago with the move towards the unified security operations platform (USOP).
With ISOC, Microsoft 365 E5/E7 customers without Sentinel can now use features previously available only to customers using both Defender XDR and Microsoft Sentinel.
This post covers the ISOC in Microsoft Defender preview. Capabilities and availability may change during the preview. See the official ISOC in Microsoft Defender documentation and Microsoft’s announcement. Why Microsoft is doing this # You could already be a Sentinel customer without paying for the SIEM features: Sentinel lets you ingest some first-party Microsoft data, mainly alerts, as part of free data sources.
In my view, Microsoft is following the industry’s direction while also helping shape it. ISOC is now its own category in Gartner’s 2026 Hype Cycle for Security Operations, alongside security data lakes.2 Both are newer alternatives to a classic SIEM.