<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ISOC on Nicola Suter</title><link>https://nicolasuter.ch/tags/isoc/</link><description>Recent content in ISOC on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Mon, 05 Oct 2026 17:37:03 +0000</lastBuildDate><atom:link href="https://nicolasuter.ch/tags/isoc/rss.xml" rel="self" type="application/rss+xml"/><item><title>What is ISOC in Microsoft Defender?</title><link>https://nicolasuter.ch/microsoft-defender-isoc/</link><pubDate>Mon, 05 Oct 2026 17:37:03 +0000</pubDate><guid>https://nicolasuter.ch/microsoft-defender-isoc/</guid><description>&lt;p&gt;Gartner describes ISOC (Integrated Security Operations Center) as a converged technology approach that combines threat detection, investigation, and response (TDIR) in a single-vendor suite or cloud service.&lt;sup id="fnref:1"&gt;&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref"&gt;1&lt;/a&gt;&lt;/sup&gt; For Microsoft, that means Defender XDR and Microsoft Sentinel. This shift started a while ago with the move towards the unified security operations platform (USOP).&lt;/p&gt;
&lt;p&gt;With ISOC, Microsoft 365 E5/E7 customers without Sentinel can now use features previously available only to customers using both Defender XDR and Microsoft Sentinel.&lt;/p&gt;

 



&lt;div
 
 class="flex px-4 py-3 rounded-md shadow bg-primary-100 dark:bg-primary-900"
 
 &gt;
 &lt;span
 
 class="text-primary-400 pe-3 flex items-center"
 
 &gt;
 &lt;span class="relative block icon"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512"&gt;&lt;path fill="currentColor" d="M506.3 417l-213.3-364c-16.33-28-57.54-28-73.98 0l-213.2 364C-10.59 444.9 9.849 480 42.74 480h426.6C502.1 480 522.6 445 506.3 417zM232 168c0-13.25 10.75-24 24-24S280 154.8 280 168v128c0 13.25-10.75 24-23.1 24S232 309.3 232 296V168zM256 416c-17.36 0-31.44-14.08-31.44-31.44c0-17.36 14.07-31.44 31.44-31.44s31.44 14.08 31.44 31.44C287.4 401.9 273.4 416 256 416z"/&gt;&lt;/svg&gt;
&lt;/span&gt;
 &lt;/span&gt;

 &lt;span
 
 class="dark:text-neutral-300"
 
 &gt;This post covers the ISOC in Microsoft Defender &lt;strong&gt;preview&lt;/strong&gt;. Capabilities and availability may change during the preview. See the &lt;a href="https://learn.microsoft.com/defender-xdr/isoc-overview" target="_blank" rel="noreferrer"&gt;official ISOC in Microsoft Defender documentation&lt;/a&gt; and &lt;a href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/integrated-security-operations-center-in-microsoft-defender/4559097" target="_blank" rel="noreferrer"&gt;Microsoft&amp;rsquo;s announcement&lt;/a&gt;.&lt;/span&gt;
&lt;/div&gt;


&lt;h2 class="relative group"&gt;Why Microsoft is doing this
 &lt;div id="why-microsoft-is-doing-this" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#why-microsoft-is-doing-this" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;You could already be a Sentinel customer without paying for the SIEM features: Sentinel lets you ingest some first-party Microsoft data, mainly alerts, as part of &lt;a href="https://learn.microsoft.com/en-us/azure/sentinel/billing?tabs=simplified%2Ccommitment-tiers#free-data-sources" target="_blank" rel="noreferrer"&gt;free data sources&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In my view, Microsoft is following the industry&amp;rsquo;s direction while also helping shape it. ISOC is now its own category in Gartner&amp;rsquo;s 2026 Hype Cycle for Security Operations, alongside security data lakes.&lt;sup id="fnref:2"&gt;&lt;a href="#fn:2" class="footnote-ref" role="doc-noteref"&gt;2&lt;/a&gt;&lt;/sup&gt; Both are newer alternatives to a classic SIEM.&lt;/p&gt;</description></item></channel></rss>