You get a single team handling cybersecurity, IT, AI consulting, and data integration services like EDI, filling the gaps in your team.
“Corsica is a one-stop shop for us. If I have a problem, I can go to my vCIO or a number of people, and you take care of it. That’s an investment in mutual success.”
– Greg Sopcak | Southern Michigan Bank & Trust
From 24/7 SOC services to MDR/SIEM, penetration testing and training, we’ve got you covered.
Get the expert support you need for your network, on-premises devices, VoiP, M365, Google Workplace, and everything in between.
Full support of compliance frameworks, including CJIS, HIPAA, CMMC, NIST, SOC 2, and more
Cut through the hype with smart strategies and right-fit AI solutions for your organization.
Take strategic steps with confidence as you collaborate with our expert business and vCIO consultants.
Get cloud security, integration, server virtualization, and optimization strategies to reduce your cloud costs.
Connect any data source to any other with robust solutions and managed services.
Stay ahead of the curve, eliminate waste, and grow revenue with next-generation technologies.
Expert consulting, implementation, integration, managed services, and cybersecurity for Microsoft products.
One program. One partner. Complete AI transformation.
It takes dedicated experience to use technology strategically in your industry. That’s why we specialize in certain verticals while offering comprehensive technology services.
From webinars and video tutorials to guides and blogs, we’ve got resources to help you and your team address any technology challenge.
On September 23, 2026, Microsoft announced a new Defender feature set called ISOC (integrated security operations center). This feature set allows Microsoft 365 E5 and E7 customers to access advanced security operations capabilities in Defender—without requiring a separate Sentinel purchase.
How do you enable ISOC in Defender?
Will ISOC replace Sentinel?
Does ISOC include Microsoft XDR capabilities?
We’ve got all the answers below.
Key takeaways
ISOC stands for “integrated security operations center.” It’s not a standalone product; rather, it’s a collection of interconnected SIEM (security information and event management) and XDR (extended detection and response) features that Microsoft has made available to Microsoft 365 E5 and E7 customers directly within Defender.
ISOC brings together these features in the Defender experience, some of which previously required a separate Sentinel purchase:
ISOC in Microsoft Defender gives eligible Microsoft 365 E5 and E7 customers a more accessible way to extend security operations inside the Defender experience. Its strongest practical benefit is expanded Microsoft security data retention, which helps organizations investigate and hunt across a longer historical window than standard Defender XDR retention allows. ISOC is best suited for organizations that primarily rely on Microsoft security tools and have limited third-party data ingestion needs, rather than those requiring a full enterprise SIEM deployment.
ISOC in Microsoft Defender is not a replacement product for Microsoft Sentinel. It’s better understood as a lighter-weight security operations experience for eligible Microsoft 365 E5/E7 customers that are primarily invested in Microsoft security tools, need expanded retention, and have limited third-party data ingestion needs.
Sentinel remains Microsoft’s full SIEM platform for larger or more complex deployments, including environments with custom log sources, broad third-party ingestion, advanced automation, and deeper Azure-dependent configuration needs. While Sentinel capabilities are increasingly surfaced through the Microsoft Defender/XDR portal experience, Sentinel still plays a distinct role for organizations that need more than the ISOC feature set provides.
Category | ISOC in Microsoft Defender | Microsoft Sentinel |
Primary purpose | Unified security operations experience combining XDR and SIEM in Defender. | Microsoft’s standalone SIEM solution. |
User experience | One product, one system, one data model, with analysts and agents working together in a single Defender experience. | Full SIEM platform with an analyst experience increasingly presented through the Microsoft Defender/XDR portal, while ingestion, automation, and configuration can still depend on Azure platform components. |
SIEM capabilities | Includes selected SIEM-like capabilities such as workbooks, case management, threat intelligence, automation, and additional features surfaced in Defender. | Provides the full SIEM feature set as Microsoft’s market-leading SIEM platform. |
XDR integration | Native integration with Defender XDR as a shared foundation for protection and operations. | Integrates with Defender but is positioned primarily as the SIEM layer. |
Eligible customers | Available as a benefit for Microsoft 365 E5 and E7 customers. It is not a separate product. | Available as a standalone, Azure-based purchase. |
Data retention benefit | Included Defender data retention increases to 90 days as the rollout progresses. | Retention is managed through Sentinel storage and retention options. |
Third-party data | Supports limited non-Microsoft data ingestion for organizations with modest third-party data needs. | Supports broader third-party ingestion, custom log sources, and more complex SIEM data requirements. |
Agentic security vision | Designed as the foundation for agentic security, enabling people and AI agents to operate from shared signals, context, and workflows. | Continues as a leading SIEM but is not positioned as the core agentic-security experience. |
No. Based on Microsoft’s guidance and the current capabilities, ISOC should not be viewed as a full Sentinel replacement. ISOC brings a lighter security operations experience into Defender for eligible Microsoft 365 E5 and E7 customers, with extended retention as the most meaningful new capability. Sentinel remains Microsoft’s full SIEM platform for organizations that need broad third-party ingestion, custom data sources, complex automation, and deeper deployment flexibility.
Some current Sentinel customers may eventually find that ISOC is sufficient, especially if their environment is heavily Microsoft-centric and does not require extensive third-party or custom data ingestion. However, organizations should evaluate that fit carefully once Microsoft provides clearer transition guidance. For now, Sentinel remains the right choice for more complex security operations programs, while ISOC creates a more accessible option for customers that need more than standard Defender XDR but less than a full SIEM deployment.
Microsoft is rolling out ISOC in Microsoft Defender through a phased release that began with a public preview on September 23, 2026, for eligible E5/E7 customers without Sentinel. Microsoft will expand capabilities and eligibility throughout Fall 2026 until the ISOC feature set reaches general availability on January 15, 2027. Existing Sentinel customers are brought into the rollout during Phase 2 and are not expected to migrate during the initial phase.
Date | Milestone | Key Capabilities / Changes |
September 23, 2026 | Phase 1 Public Preview | E5/E7 customers without Sentinel gain access to initial ISOC capabilities, including Case Management, Natural Language Playbook Generator, Workbooks, Content Hub connectors, and UEBA. Workspace creation initially limited to a small number of customers. |
October 1, 2026 | Third-party data ingestion available | New $2.40/GB pricing becomes available for ingesting non-Microsoft security data. |
October 4, 2026 | Expanded onboarding capacity | ISOC workspace creation expands to up to 1,500 customers. |
October 15, 2026 | Private previews begin | Private preview for 90-day Defender retention, 180-day retention option, SOC Optimization, Threat Intelligence Platform, and Full Content Hub capabilities. |
November 4, 2026 | Broad workspace availability | Workspace creation limits are removed and become broadly available. |
November 15, 2026 (Ignite) | Phase 2 Public Preview | Existing E5/E7 Sentinel customers can opt into ISOC. Additional SIEM capabilities become available, including Threat Intelligence Platform, SOC Optimization, Full Content Hub solutions, built-in data lake functionality, and 90-day retention benefits. |
January 15, 2027 | General Availability (GA) | ISOC reaches general availability for both Phase 1 and Phase 2 audiences. |
Customer Type | September 23 | November 15 | January 15 |
E5/E7 without Sentinel | Phase 1 Public Preview begins. | Additional capabilities and retention benefits become available. | General Availability. |
E5/E7 with Sentinel | Continue using Sentinel; not eligible for ISOC in Phase 1. | Can opt into ISOC during Phase 2 Public Preview. | General Availability. |
Standalone Defender / Mini Suites | Case Management only. | No major ISOC benefit changes announced. | No change annou |
Implementing ISOC in Microsoft Defender should start with confirming whether the organization’s requirements for security operations fit ISOC or still require Sentinel. ISOC is best suited for Microsoft-centric environments that need extended retention, case management, basic workbook visibility, and selected automation capabilities. Organizations with significant third-party data, custom sources, or advanced automation requirements should continue planning around Sentinel.
While it’s not a replacement for Sentinel, the ISOC feature set in Microsoft Defender offers an easy on-ramp for E5 and E7 customers who need basic SIEM capabilities with limited ingestion of non-Microsoft data and more than 30 days’ data retention. For companies with more robust SIEM requirements, Sentinel remains the gold standard. If you need help choosing the right approach to SIEM—or managing your path throughout the ISOC rollout—get in touch with us. We’ve helped 1,000+ customers on their technology journey. Let’s take the next step in securing your environment.
Contact us today to get the outside perspective you need for the next step on your journey.
We’ll respond within 1 business day, or you can grab time on our calendar.