ISOC shift in Microsoft Defender unifies XDR SIEM and Sentinel pre March migration, enhancing analytics and retention
Key insights
ISOC is Microsoft’s new integrated security-operations layer inside Defender that lets teams see, investigate, and act from one shared workspace. It combines traditional operations and agentic workflows so analysts and AI can work together in the same environment.
Core capabilities include SIEM, XDR, Threat intelligence, Automation, and AI all available through the Defender portal. These layers provide collection, detection, enrichment, orchestration, and analyst assistance without switching tools.
Preview access requires active Defender Suite or Microsoft 365 E5/E7 licenses and an Azure subscription to create an ISOC workspace. Microsoft offers built-in retention expansion to 90 days starting November 15, 2026, and sets a migration deadline of March 31, 2027 for affected customers.
The main technical shift moves SIEM-style operations into Defender rather than requiring separate Sentinel-only setups. ISOC is presented as an added benefit within Defender investments, not a standalone product.
Practical advantages include fewer tool handoffs, a single Defender-based workflow, shared security signals and context, and faster detection and response by human and AI agents working together. Customers gain easier access to integrated analytics and retention capabilities already tied to their Microsoft licenses.
Recommended immediate steps: confirm license eligibility and Azure subscription, inventory any existing Sentinel workspaces, test ISOC features in preview, and plan data/retention and automation changes ahead of the March 31, 2027 deadline. Validate analytics and playbooks early so teams avoid operational gaps during migration.
Keywords
What is ISOC, ISOC explained, Internet Society overview, ISOC 5 minute guide, ISOC quick summary, Internet Society mission, ISOC membership benefits, ISOC history