3 min Security

Microsoft brings Sentinel and Defender together for AI agents

Microsoft brings Sentinel and Defender together for AI agents

Microsoft is bringing various security features within Defender closer together so security teams and AI agents can work from the same environment. The new Integrated Security Operations Center (ISOC) combines, among other things, SIEM, threat protection, and threat intelligence.

Microsoft’s primary goal with this move is to address fragmented security information. Analysts currently often have to combine data and context from different tools before they can respond to an incident. According to the company, this problem becomes more acute when AI agents are also deployed, as they, too, must have access to various data sources and security features.

A key component of ISOC is further integrating Microsoft Sentinel with Defender. SIEM features from Sentinel are now directly available in the Defender portal. Features such as case management and workbooks function there without additional configuration. Users can also create automation playbooks using plain-language instructions.

Not everything is integrated immediately

Configuration remains necessary for other components. For example, organizations must configure User and Entity Behavior Analytics (UEBA) and data from Azure and external sources. Customers must also create a separate ISOC workspace linked to an Azure subscription.

More than 500 connectors are available for external data sources. Microsoft warns that fees may apply for processing incoming data, according to SiliconANGLE, citing Microsoft documentation.

ISOC is therefore not a completely standalone security product, but rather a new configuration of existing and new capabilities within Defender that does require a separate workspace.

More work for agents

This approach aligns with Microsoft’s strategy to give AI agents a greater role in security operations. In July, the company introduced Project Perception for this purpose, along with its proprietary security model, MAI-Cyber-1-Flash.

Within ISOC, agents have access to the same signals, context, and security measures as human analysts. For example, they can investigate incidents and help respond to them. For actions with significant consequences, human approval remains required under Project Perception.

Microsoft links this to what it calls an “integrated protection loop.” Defender uses telemetry, vulnerability data, and threat intelligence to provide protection. The existing Attack Disruption feature, which can automatically intervene during an ongoing attack, exemplifies this approach.

Preview with limitations

ISOC is now available as a public preview for customers with Microsoft Defender Suite, Microsoft 365 E5, or E7. Organizations that are already using an active Microsoft Sentinel workspace cannot participate at this time.

During the preview, Microsoft Defender retains data for 30 days at no additional cost. Microsoft has not yet announced final ISOC pricing.