Microsoft Defender ISOC merges Sentinel SIEM for AI agents
Microsoft has introduced the Integrated Security Operations Center, or ISOC, as a public preview inside the Microsoft Defender portal. It brings selected Microsoft Sentinel functions directly into Defender so analysts and AI agents share the same signals and workflows. The goal is to reduce tool switching and give automation a common data foundation. This preview is limited by licensing, workspace rules, and incomplete integration. The Defender home page introduces these ISOC capabilities alongside cases, workbooks, and automation.
Source
👉@sysadminoff
https://4sysops.com/archives/microsoft-defender-isoc-merges-sentinel-siem-for-ai-agents/
Post #20513
15
