Microsoft Combines Sentinel and Defender Products for Agentic Security Operations

Microsoft is combining its security information and event management and threat protection capabilities within Microsoft Defender, creating what the company calls an Integrated Security Operations Center built for an era of AI-driven attacks.

The new ISOC experience brings Microsoft Sentinel capabilities, including case management, threat intelligence, workbooks, and automation, into Defender. The goal is to give security analysts and AI agents a common set of signals, context, and controls without requiring teams to move between separate security systems.

"Fundamentally, the physics of cyber have changed," Hayete Gallot, executive vice president of security at Microsoft, said during the company's announcement.

Gallot said attackers have moved beyond using AI to assist with individual parts of their campaigns. Microsoft is now seeing AI-executed operations in which automated systems handle most of an attack while people provide limited direction. Some purpose-built systems can also adjust their tactics as an operation unfolds.

That speed creates a problem for traditional security operations centers, which still depend heavily on people investigating alerts and coordinating responses across multiple tools.

Microsoft's answer is to bring Sentinel's SIEM functionality and Defender's extended detection and response capabilities into a shared operational environment. The company said ISOC supports more than 500 connectors, allowing organizations to bring third-party security data into Defender alongside Microsoft telemetry.

In a product demo, Microsoft connected Amazon Web Services CloudTrail data to Defender through a Sentinel connector. An analyst then examined an active incident spanning a compromised endpoint, stolen credentials and an AWS account.

Defender's automated attack disruption had already intervened, but the analyst still had to determine the scope of the breach and verify that the attacker had been removed. The demonstration showed the analyst reviewing the attack graph, investigating the potential blast radius, and hunting across 90 days of active data.

Microsoft is positioning that unified data foundation as a prerequisite for using AI agents effectively. Those agents need access to the same telemetry, threat intelligence, and security controls used by analysts if they are expected to investigate incidents and take defensive action.

The company also demonstrated a connection between ISOC and Project Perception, its multiagent security system introduced in July. Specialized agents performed tasks such as threat investigation, reconnaissance, attack emulation and posture assessment. The system then recommended configuration changes, vulnerability fixes and additional Defender detections. 

[Click on image for larger view.]   Figure 1. Microsoft's reorganized Cyber Stack.

The analyst remained involved throughout the process, reviewing the agents' activity and steering their work. Microsoft said people will continue to set priorities, exercise judgment, and define outcomes, while agents provide the speed and scale to perform continuous security work.

Allie Mellen, a principal analyst at Forrester, said during the video presentation that organizations will need more than AI models to make agentic security work.

"AI agents need context," Mellen said. That means organizations must first build a reliable security data foundation and give agents enough information about the business to make sound decisions.

Mellen cautioned that AI may not resolve incidents as quickly as security teams hope, at least at first. Its more immediate value could be helping analysts investigate incidents more thoroughly. Threat-hunting agents may be particularly useful for smaller organizations that do not have dedicated threat hunters.

Microsoft also wants ISOC to reduce the time analysts spend pulling together data from disconnected tools. Martin Joy, a longtime technology and security leader with the Government of Nunavut, said that is a familiar problem for his small team because many of its systems do not work well together.

Joy said ISOC could help analysts spend less time sorting through data and dealing with workarounds, leaving them more time to focus on active threats.

Microsoft described ISOC as an "integrated protection loop" connecting detection, investigation, disruption, containment, and remediation. The system is designed to use what defenders learn from an incident to strengthen protections before the next attack, rather than treating every alert as an isolated event.

ISOC is now available in public preview in Microsoft Defender. Microsoft said customers can begin with Defender data and add external telemetry over time, avoiding a large upfront migration project.

For more information, visit the Microsoft site.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured