Site icon VMVirtualMachine.com

Microsoft unveils Integrated Security Operations Center in Defender for AI agents – SiliconANGLE

Microsoft unveils Integrated Security Operations Center in Defender for AI agents – SiliconANGLE

By Duncan Riley
Publication Date: 2026-09-23 22:10:00

Microsoft Corp. today unveiled Integrated Security Operations Center in Microsoft Defender as it rebuilds its security operations products around artificial intelligence agents.

The service moves security information and event management features from Microsoft Sentinel directly into Defender. ISOC is aimed at a problem Microsoft says is getting worse as attackers put agents to work.

“What once required entire teams now requires a single operator and an agent framework,” Rob Lefferts, corporate vice president of Microsoft Threat Protection, wrote in a blog post. Defenders fall behind, he argued, when protection and day-to-day operations run as separate systems and analysts have to piece incidents together by hand across several tools.

Several of the features ISOC brings over from Sentinel, including case management and workbooks, work in the Defender portal without any setup, according to Microsoft’s documentation. So does a feature that writes automation playbooks from…

Exit mobile version