Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost.
Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal.
“Security cannot operate at AI speed when protection and operations are built as separate systems,” Rob Lefferts, corporate vice president of Microsoft Threat Protection, wrote in a blog post announcing ISOC. He said attackers now use AI agents to automate attacks at scale, and that every handoff between separate tools slows defenders down.
Until now, E5 and E7 included Defender XDR but not SIEM, which Microsoft sells separately as Microsoft Sentinel.
Under ISOC, logs from Microsoft’s own security products are available without ingestion charges. From Oct. 1, data ingested from third-party security tools and other outside sources will be metered at $2.40 per GB on a pay-as-you-go basis, Microsoft said in a technical blog post.
The company opened ISOC as a public preview, meaning it is not fully production-ready, on Sept. 23 and has not said when the preview phase will end. It is available to organizations with an active Microsoft Defender Suite and Microsoft 365 E5 or E7 license that do not already run Microsoft Sentinel, and has no minimum seat requirement.
For organizations whose security stack already runs largely on Microsoft, the trade is attractive, said Yih Khai Wong, senior research manager for security services research at IDC Asia/Pacific. “Most telemetry already resides in Defender, Entra, and M365, so bundling Sentinel’s SIEM into E5/E7 effectively makes ingestion free, with no separate license needed to move and re-analyze data your own vendor already holds,” Wong said.
“ISOC is not a new standalone product,” Microsoft said in an FAQ accompanying the technical post. Its ISOC product page said capabilities such as workbooks and natural-language-to-SOAR automation “previously required a separate Sentinel purchase.”
According to the technical post, Microsoft began rolling out case management, workbooks and natural-language playbook generation to eligible customers’ Defender portals on Sept. 23, with no additional configuration required.
The included data covers Defender for Endpoint, Office 365, Identity, Cloud Apps and Cloud, plus Microsoft Entra ID Protection logs and Azure and Office 365 activity logs. Retention is 30 days during the preview, rising to 90 days on Nov. 15, the post added.
Anything beyond that requires an ISOC workspace, which needs an Azure subscription, according to Microsoft’s product documentation. The workspace unlocks more than 500 data connectors, user and entity behavior analytics (UEBA), CI/CD repositories and threat intelligence.
Wong said mixed environments face a different calculation. “For multicloud shops or organizations with significant non-Microsoft telemetry, this requires a real total cost-of-ownership comparison against current SIEM spend.”
The current preview excludes organizations with an active Sentinel workspace. Microsoft said nothing changes for existing Sentinel customers, and those meeting the licensing criteria can choose to move to ISOC from Nov. 15.
Consolidating identity, endpoint, productivity and security operations under one vendor can simplify investigations, Wong said, but it also “creates greater dependency on that vendor’s roadmap, pricing model, availability, and security resilience.”
CISOs running a separate SIEM face a genuine evaluation, not a quick swap, weighing migration effort, retraining of detection content, exit costs and contractual complexity, he added.
Sanchit Vir Gogia, chief analyst at Greyhound Research, advised enterprises interested in ISOC to “reproduce the organisation’s highest-value cross-vendor detections before replacing a mature SIEM,” warning that “Microsoft’s claim of more than 500 connectors establishes reach, not equal treatment of every source.”
Microsoft’s Lefferts positioned ISOC as the foundation for the agent strategy Microsoft introduced alongside Project Perception in July.
Gogia questioned the premise that this requires a single vendor. “Microsoft has established a useful integration path. It has not established that one supplier is technically necessary for an agentic SOC,” he said. He noted that Project Perception remains invitation-only in limited public preview.
Microsoft has not published details on how agent actions within ISOC are logged, audited or reversed. Gogia said the critical threshold comes when agents gain authority to make changes, since changes to identity, endpoint or cloud policy “create a blast radius.” He recommended distinct agent identities, narrow tool permissions and independent approval for consequential changes.
The agents themselves add attack surface, Wong warned. “Adversaries may attempt to manipulate the telemetry an agent relies on, poison contextual data, or use prompt injection techniques to influence agent behavior and decision-making,” Wong said.
“Microsoft has made integration easier to buy. The enduring test is whether customers retain the means to challenge and reverse it,” Gogia said.
Microsoft did not immediately respond to a request for comment.