Microsoft merges Sentinel and Defender into one console for AI-era security teams

The new Integrated Security Operations Center bets that human analysts and AI agents need to share the same tools, signals and controls, not bolt them together after the fact.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal editorial shot of a modern security operations center at night, rows of dark curved desks facing large wall-mounted dashboards
Share

Key points

  • Microsoft has announced ISOC in Microsoft Defender, an Integrated Security Operations Center that merges its SIEM (security information and event management, the tool that collects and searches security logs) and its threat protection products into one console.
  • The launch builds on Project Perception, the AI security effort Microsoft introduced in July 2026 to give defenders specialised agents that can reason over live attack data.
  • Microsoft is pitching ISOC as a fix for the "handoffs" between separate security tools that slow down both human analysts and AI agents.
  • The company frames the change as a response to attackers using AI agents to run intrusion campaigns with a single operator instead of a team.
  • No pricing, general availability date, or list of retiring product SKUs was disclosed.

Microsoft is trying to collapse the security operations center into a single product.

This week the company unveiled ISOC in Microsoft Defender, short for Integrated Security Operations Center. It pulls together Microsoft's SIEM (the log-searching layer sold as Sentinel) and its Defender threat protection suite so analysts and AI agents work from one set of signals, one context store, one set of controls. The pitch, laid out in a Microsoft corporate blog post and expanded on the Microsoft Security Response Center blog, is blunt: attackers now use AI agents to run intrusions that once needed a whole team. Defenders can't keep up if their own tools still require someone to copy findings from one product into another.

What is Microsoft actually shipping?

One console combining SIEM and Defender's endpoint, identity, cloud and email protection, with AI agents drawing from the same underlying data.

Microsoft describes ISOC as three layers working together: sensors that collect signals across a company's systems, a context layer that turns those signals into a picture of what's happening, and actuators that let the system take protective action, isolating a device or disabling an account. The company's existing Attack Disruption feature, which cuts off an intrusion mid-flight, is held up as the template for how that loop should work.

For a security analyst the practical change is fewer tabs. Investigations, threat hunting, incident management and automation sit in one place by default rather than spread across separate Defender and Sentinel portals.

Where do the AI agents fit in?

On top of that shared foundation, drawing from the same telemetry a human analyst sees.

Microsoft says ISOC is built for agentic security, meaning it's designed so AI agents can investigate alerts, correlate events, then recommend or execute responses without a separate agent platform bolted on. Those agents come from Project Perception, the July 2026 initiative Microsoft used to introduce security-specific AI models and the orchestration layer that lets them act on live data. We covered Project Perception when Microsoft first announced it on 28 July 2026.

Microsoft's argument is that agents fail when they have to reach across product boundaries the way humans do. Give them one context store and one control surface, they can operate continuously instead of running one-off tasks.

What Microsoft did not say

The announcement is light on the details buyers usually ask about first.

Detail What Microsoft disclosed
General availability date Not stated
Pricing or licensing changes Not stated
Impact on existing Sentinel SKUs Not stated
Supported non-Microsoft data sources Not stated
Independent efficacy data Not provided

There's no independent testing to point to yet. Microsoft's own "crash score" for the underlying model, referenced in an editor's note on the corporate post, isn't broken out in the public material.

Bear in mind our September scorecard story: Microsoft reported missing 221 high-severity emails per thousand users and still claimed its own benchmark. A unified console doesn't fix detection gaps; it just means the gaps live in one place now.

My read: the interesting part here isn't the AI agents, which every vendor now claims. It's Microsoft using the agent story as cover to finish merging Sentinel and Defender into a single product line. Customers who bought them as separate tools, and priced them that way, should be asking what the licensing looks like on the other side of this.

Should you worry about your existing Sentinel setup?

Yes, if you have custom data connectors or third-party integrations, because "one system" tends to be less friendly to outside tools than the launch materials suggest.

Ask your Microsoft account team for the ISOC availability timeline and the licensing model before it lands in your tenant. Map your current Sentinel connectors and Defender workflows against whatever Microsoft publishes. If you run agentic tooling from another vendor, get in writing how it will read from and write to the new shared context layer.

© 2026 Threat Vectr