Microsoft introduces a new approach to security operations built for AI agents
Microsoft unveils an integrated security operations center (ISOC) in Microsoft Defender to unify AI-driven defense, eliminating fragmented workflows and enabling real-time threat disruption.
Cyberattackers increasingly deploy AI agents to automate attacks at scale, forcing defenders to rethink fragmented security systems. Microsoft argues that traditional, siloed approaches—where protection and operations operate separately—cannot match the speed of agentic threats. The company introduces the integrated security operations center (ISOC) in Microsoft Defender to consolidate security information and event management (SIEM) and threat protection into a single system. This foundation aims to provide defenders and AI agents with a shared view of the environment, reducing operational complexity and enabling faster, coordinated responses.
Microsoft’s ISOC integrates signals, context, and controls into a continuous protection loop, allowing defenders to detect, predict, and disrupt attacks in real time. The system leverages rich telemetry and exposure insights to strengthen defenses dynamically, focusing on threats with the highest impact. By eliminating the need to manually assemble and maintain separate tools, ISOC shifts practitioners’ focus from tool management to strategic defense. The result is a more responsive security posture that adapts to evolving threats without requiring constant manual intervention.
The ISOC model removes traditional boundaries between tools and teams, enabling practitioners to organize work around security outcomes rather than tool boundaries. As AI autonomy grows, the integrated loop can handle more detection and response tasks, while agents assist with investigation and action using consistent context. Microsoft emphasizes that the system is designed to scale with organizational needs, allowing defenders to multiply their expertise rather than spending time operating disjointed security stacks.
Microsoft positions ISOC as a foundational shift in security operations, where people and AI agents collaborate as a unified system. The company highlights that the next generation of security operations centers will be defined by seamless collaboration between humans and machines, not just the number of AI features. ISOC in Microsoft Defender is available in preview, offering defenders a new operating model for continuous defense against AI-powered threats.