← Back to feed
AI SecurityEmerging1 sourceSep 24, 2026 · 15:55via CSO Online

Microsoft integrates SOC capabilities with Defender for enterprises

Brief

Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost.

Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal.

“Security cannot operate at AI speed when protection and operations are built as separate systems,” Rob Lefferts, corporate vice president of Microsoft Threat Protection, wrote in a blog post announcing ISOC. He said attackers now use AI agents to automate attacks at scale, and that every handoff between separate tools slows defenders down.

Until now, E5 and E7 included Defender XDR but not SIEM, which Microsoft sells separately as Microsoft Sentinel.

Read more on CSO Online→