Microsoft opens Defender security operations preview built around agents
Microsoft folded Sentinel's SIEM features into Defender and rebuilt security operations around agents; the preview is open but pricing is undisclosed and active Sentinel customers are excluded.
Original event 2026-09-23
Microsoft opened the public preview of Integrated Security Operations Center (ISOC) on September 23, moving SIEM features from Sentinel directly into Defender.
The preview is available to customers with Microsoft Defender Suite, Microsoft 365 E5 or E7 licenses; organizations already running an active Sentinel workspace are excluded for now. Case management and workbooks work without setup, while user and entity behavior analytics and third-party data ingestion require extra configuration, and ingestion charges may apply.
The design gives security agents the same signals and controls as a human analyst, letting them investigate and act on incidents, with humans still approving high-stakes actions. Microsoft has not disclosed pricing, and Defender data is kept for 30 days at no charge during the preview. The claim that attackers are putting agents to work comes from Microsoft's own executives, not independent verification.