Microsoft unveils Integrated Security Operations Center in Defender for AI agents
Microsoft folds Sentinel into Defender, betting security operations are now an agent problem.

Why it matters
As attackers deploy AI agents, Microsoft is consolidating its security stack around agent-native detection and response. This signals a major product realignment: security ops are no longer just for humans monitoring dashboards.
The key facts
5 to knowMicrosoft Defender now includes Integrated Security Operations Center (ISOC)
SIEM features moved from Sentinel into Defender product
Product rebuild explicitly targets AI agent attack threats
Microsoft frames agent-driven attacks as accelerating security risk
Consolidation suggests agent autonomy is reshaping enterprise security posture
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Microsoft Corp. today unveiled Integrated Security Operations Center in Microsoft Defender as it rebuilds its security operations products around artificial intelligence agents. The service moves security information and event management features from Microsoft Sentinel directly into Defender. ISOC…