ISOC feature set in Microsoft Defender

ISOC in Microsoft Defender: What You Need to Know

On September 23, 2026, Microsoft announced a new Defender feature set called ISOC (integrated security operations center). This feature set allows Microsoft 365 E5 and E7 customers to access advanced security operations capabilities in Defender—without requiring a separate Sentinel purchase.

How do you enable ISOC in Defender?

Will ISOC replace Sentinel?

Does ISOC include Microsoft XDR capabilities?

We’ve got all the answers below.

Key takeaways

  • ISOC in Microsoft Defender is a lighter-weight security operations feature set for Microsoft 365 E5 and E7 customers who primarily rely on Microsoft security data and need more than 30 days’ data retention.
  • ISOC in Defender does not offer feature parity with Sentinel, especially for organizations with broader third-party data ingestion, custom log sources, or advanced automation needs.
  • Sentinel remains the better fit for larger or more complex deployments, while ISOC may be sufficient for Microsoft-centric organizations with limited third-party data requirements.
  • ISOC in Defender follows a gradual rollout process starting in September 2026 with limited access leading to general availability in January 2027.

Table of Contents

💡 Which solution is right for you? 

Get in touch with us to decide on ISOC vs. Sentinel.

What is ISOC in Microsoft Defender?

ISOC stands for “integrated security operations center.” It’s not a standalone product; rather, it’s a collection of interconnected SIEM (security information and event management) and XDR (extended detection and response) features that Microsoft has made available to Microsoft 365 E5 and E7 customers directly within Defender.

ISOC brings together these features in the Defender experience, some of which previously required a separate Sentinel purchase:

  • Workbooks and NL to SOAR
  • XDR and SIEM
  • Threat intelligence
  • Security automation
  • Limited third-party data ingestion options for organizations with modest non-Microsoft data needs
Benefits of ISOC in Microsoft Defender

What are the benefits of ISOC in Microsoft Defender?

ISOC in Microsoft Defender gives eligible Microsoft 365 E5 and E7 customers a more accessible way to extend security operations inside the Defender experience. Its strongest practical benefit is expanded Microsoft security data retention, which helps organizations investigate and hunt across a longer historical window than standard Defender XDR retention allows. ISOC is best suited for organizations that primarily rely on Microsoft security tools and have limited third-party data ingestion needs, rather than those requiring a full enterprise SIEM deployment.

Benefits of ISOC in Microsoft Defender

  • Built for agentic security with shared signals, context, and controls that allow people and AI agents to see, understand, and act across the environment together.
  • Unified security operations and protection through an integrated protection loop that connects threat detection, investigation, response, and prevention in a single workflow.
  • Selected SIEM-like capabilities for eligible E5/E7 customers, including workbooks, case management, threat intelligence capabilities, automation, and other security operations features surfaced in the Defender experience.
  • Extended Defender data retention, increasing included retention from 30 days to 90 days, which is the most meaningful change for organizations that need a longer investigation and threat-hunting window without moving immediately to a full Sentinel deployment.
  • Limited third-party data ingestion at a lower price point, giving Microsoft-centric organizations a path to add some non-Microsoft data, while recognizing that Sentinel remains the better option for broad third-party ingestion and custom data scenarios.
  • Faster investigations and response through centralized case management, integrated workflows, and shared Defender context for Microsoft security data.
  • Improved automation and operational efficiency with natural language playbook generation, SOAR capabilities, SOC optimization features, and AI-assisted workflows, while more advanced automation and ingestion scenarios may still depend on Sentinel and Azure-based components.
  • A simpler, practitioner-focused experience built around one product, one system, and one data model, bringing analysts and AI agents together in the flow of work.

How does ISOC in Microsoft Defender compare to Sentinel?

ISOC in Microsoft Defender is not a replacement product for Microsoft Sentinel. It’s better understood as a lighter-weight security operations experience for eligible Microsoft 365 E5/E7 customers that are primarily invested in Microsoft security tools, need expanded retention, and have limited third-party data ingestion needs.

Sentinel remains Microsoft’s full SIEM platform for larger or more complex deployments, including environments with custom log sources, broad third-party ingestion, advanced automation, and deeper Azure-dependent configuration needs. While Sentinel capabilities are increasingly surfaced through the Microsoft Defender/XDR portal experience, Sentinel still plays a distinct role for organizations that need more than the ISOC feature set provides.

Comparison table: ISOC in Defender vs. Sentinel

Category

ISOC in Microsoft Defender

Microsoft Sentinel

Primary purpose

Unified security operations experience combining XDR and SIEM in Defender.

Microsoft’s standalone SIEM solution.

User experience

One product, one system, one data model, with analysts and agents working together in a single Defender experience.

Full SIEM platform with an analyst experience increasingly presented through the Microsoft Defender/XDR portal, while ingestion, automation, and configuration can still depend on Azure platform components.

SIEM capabilities

Includes selected SIEM-like capabilities such as workbooks, case management, threat intelligence, automation, and additional features surfaced in Defender.

Provides the full SIEM feature set as Microsoft’s market-leading SIEM platform.

XDR integration

Native integration with Defender XDR as a shared foundation for protection and operations.

Integrates with Defender but is positioned primarily as the SIEM layer.

Eligible customers

Available as a benefit for Microsoft 365 E5 and E7 customers. It is not a separate product.

Available as a standalone, Azure-based purchase.

Data retention benefit

Included Defender data retention increases to 90 days as the rollout progresses.

Retention is managed through Sentinel storage and retention options.

Third-party data

Supports limited non-Microsoft data ingestion for organizations with modest third-party data needs.

Supports broader third-party ingestion, custom log sources, and more complex SIEM data requirements.

Agentic security vision

Designed as the foundation for agentic security, enabling people and AI agents to operate from shared signals, context, and workflows.

Continues as a leading SIEM but is not positioned as the core agentic-security experience.

 

Is Microsoft ultimately replacing Sentinel with ISOC for Defender?

No. Based on Microsoft’s guidance and the current capabilities, ISOC should not be viewed as a full Sentinel replacement. ISOC brings a lighter security operations experience into Defender for eligible Microsoft 365 E5 and E7 customers, with extended retention as the most meaningful new capability. Sentinel remains Microsoft’s full SIEM platform for organizations that need broad third-party ingestion, custom data sources, complex automation, and deeper deployment flexibility.

Some current Sentinel customers may eventually find that ISOC is sufficient, especially if their environment is heavily Microsoft-centric and does not require extensive third-party or custom data ingestion. However, organizations should evaluate that fit carefully once Microsoft provides clearer transition guidance. For now, Sentinel remains the right choice for more complex security operations programs, while ISOC creates a more accessible option for customers that need more than standard Defender XDR but less than a full SIEM deployment.

Is ISOC in Defender replacing Sentinel?

What is the ISOC release schedule?

Microsoft is rolling out ISOC in Microsoft Defender through a phased release that began with a public preview on September 23, 2026, for eligible E5/E7 customers without Sentinel. Microsoft will expand capabilities and eligibility throughout Fall 2026 until the ISOC feature set reaches general availability on January 15, 2027. Existing Sentinel customers are brought into the rollout during Phase 2 and are not expected to migrate during the initial phase.

ISOC in Microsoft Defender release schedule

Date

Milestone

Key Capabilities / Changes

September 23, 2026

Phase 1 Public Preview

E5/E7 customers without Sentinel gain access to initial ISOC capabilities, including Case Management, Natural Language Playbook Generator, Workbooks, Content Hub connectors, and UEBA. Workspace creation initially limited to a small number of customers.

October 1, 2026

Third-party data ingestion available

New $2.40/GB pricing becomes available for ingesting non-Microsoft security data.

October 4, 2026

Expanded onboarding capacity

ISOC workspace creation expands to up to 1,500 customers.

October 15, 2026

Private previews begin

Private preview for 90-day Defender retention, 180-day retention option, SOC Optimization, Threat Intelligence Platform, and Full Content Hub capabilities.

November 4, 2026

Broad workspace availability

Workspace creation limits are removed and become broadly available.

November 15, 2026 (Ignite)

Phase 2 Public Preview

Existing E5/E7 Sentinel customers can opt into ISOC. Additional SIEM capabilities become available, including Threat Intelligence Platform, SOC Optimization, Full Content Hub solutions, built-in data lake functionality, and 90-day retention benefits.

January 15, 2027

General Availability (GA)

ISOC reaches general availability for both Phase 1 and Phase 2 audiences.

ISOC in Microsoft Defender release schedule by customer type

Customer Type

September 23

November 15

January 15

E5/E7 without Sentinel

Phase 1 Public Preview begins.

Additional capabilities and retention benefits become available.

General Availability.

E5/E7 with Sentinel

Continue using Sentinel; not eligible for ISOC in Phase 1.

Can opt into ISOC during Phase 2 Public Preview.

General Availability.

Standalone Defender / Mini Suites

Case Management only.

No major ISOC benefit changes announced.

No change annou

 

How do we implement ISOC features in Defender?

Implementing ISOC in Microsoft Defender should start with confirming whether the organization’s requirements for security operations fit ISOC or still require Sentinel. ISOC is best suited for Microsoft-centric environments that need extended retention, case management, basic workbook visibility, and selected automation capabilities. Organizations with significant third-party data, custom sources, or advanced automation requirements should continue planning around Sentinel.

ISOC in Defender implementation process

  1. Confirm eligibility by verifying that your organization has Microsoft 365 E5 or E7 licensing and is eligible for the current phase of the rollout. Existing Sentinel customers remain on their current deployment until Phase 2 eligibility becomes available.
  2. Access Microsoft Defender and begin using the built-in ISOC capabilities that do not require a workspace, including Case Management, Workbooks, and the Natural Language Playbook Generator.
  3. Create an ISOC workspace if you want to use workspace-dependent features or bring in a limited amount of non-Microsoft security data. Workspace onboarding occurs through the Defender experience. 
  4. Evaluate external data source requirements carefully before connecting non-Microsoft data. ISOC can support limited third-party ingestion, but organizations with broad connector requirements, custom logs, or complex ingestion needs should use Sentinel.
  5. Enable case-centric investigations by using Cases as the primary location for incident management, evidence tracking, ownership, SLA management, and response workflows.
  6. Configure automation and orchestration through natural language playbook generation and SOAR capabilities to streamline repetitive investigation and response activities.
  7. Use Workbooks and SOC optimization features to monitor security operations, track performance metrics, visualize trends, and improve analyst efficiency.
  8. Leverage Threat Intelligence and UEBA to identify high-risk threats, suspicious user behavior, insider threats, and compromised accounts with additional context and prioritization.
  9. Take advantage of extended retention and data lake capabilities as they become available through the phased rollout, enabling longer-term investigations, hunting, and analytics.
  10. Adopt agentic security workflows by using the shared signals, context, controls, and automation provided by ISOC to enable security teams and AI-powered agents to investigate and respond within a common operating model.

The takeaway: Choose the right approach to SIEM functionality for your business

While it’s not a replacement for Sentinel, the ISOC feature set in Microsoft Defender offers an easy on-ramp for E5 and E7 customers who need basic SIEM capabilities with limited ingestion of non-Microsoft data and more than 30 days’ data retention. For companies with more robust SIEM requirements, Sentinel remains the gold standard. If you need help choosing the right approach to SIEM—or managing your path throughout the ISOC rollout—get in touch with us. We’ve helped 1,000+ customers on their technology journey. Let’s take the next step in securing your environment.

Related posts

As Vice President of Security Operations, Clayton Mach brings 15+ years of experience, a strong leadership perspective, and deep technical expertise to the everyday security operations of Corsica’s clients. His wide range of expertise—from ERP systems to network support, infrastructure deployment, and process auditing—equips him to apply a practical perspective to rapidly evolving threat landscape faced by Corsica clients. He holds the professional development and success of his team members as his most satisfying accomplishments.

Ready to take your next step?

Contact us today to get the outside perspective you need for the next step on your journey.

Contact Us Now →

Moving forward with AI- Corsica Technologies

Table of Contents

💡 Which solution is right for you? 

Get in touch with us to decide on ISOC vs. Sentinel.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.