Microsoft integrates SOC capabilities with Defender for enterprises
Microsoft just bundled its SIEM into Defender for E5/E7 customers at no extra cost — collapsing what used to be a separate $2.40/GB license into one portal.

Why it matters
Microsoft is consolidating security operations into a single vendor stack (Defender + integrated SIEM/ISOC), lowering friction for enterprises already on Microsoft infrastructure but raising switching costs and dependency risk as AI agents enter the SOC.
The key facts
9 to knowISOC (Integrated Security Operations Center) launches in public preview Sept. 23, 2026
Free for Microsoft 365 E5/E7 customers; no separate Sentinel license needed
Third-party data ingestion metered at $2.40/GB on pay-as-you-go starting Oct. 1
30-day log retention in preview, 90 days starting Nov. 15
Covers Defender for Endpoint, Office 365, Identity, Cloud Apps, Entra ID Protection, Azure and Office 365 activity logs
500+ data connectors available in ISOC workspace (requires Azure subscription)
Existing Sentinel customers can migrate to ISOC from Nov. 15 onward
Microsoft positions ISOC as foundation for agentic SOC strategy (Project Perception, July 2026)
Not a new standalone product; capabilities like case management and natural-language playbook generation previously required separate Sentinel purchase
Go to the source
Computerworldcomputerworld.com
Publisher excerpt: Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with…