Microsoft Rebuilds the SOC with AI Agents, SIEM Integration and Machine-Speed Defense

Microsoft Rebuilds the SOC with AI Agents, SIEM Integration and Machine-Speed Defense

By Tushar Subhra Dutta
Publication Date: 2026-09-24 11:12:00

Cyberattacks can move faster than a security team can investigate them. Attackers increasingly use AI agents to automate steps that once needed several people, while defenders still work across separate monitoring and protection tools.

Microsoft says this mismatch is driving a rethink of how security operations centers, or SOCs, should work. This is not a newly discovered malware strain or a documented intrusion. Attacks can scale while defenders lose time moving between systems.

Reporting on AI-driven attacks and fraud shows how automation can accelerate intrusions and other abuses, although Microsoft identifies no specific campaign.

Microsoft security leaders described an integrated security operations center, called ISOC, in a September 23 announcement. The company says the model brings security information and event management, or SIEM, together with threat protection inside Microsoft Defender.

It is available in preview, leaving organizations to assess how well…