ISOC in Microsoft Defender: Not a New Product, a New E5 and E7 Benefit

Today (September 23, 2026) Microsoft announced the public preview of the Integrated Security Operations Center (ISOC) in Microsoft Defender. The announcement leans heavily on the agentic SOC vision, so this post is the practical version: what it is, who gets it, what it costs, and who should wait.

ISOC is a benefit, not a product

ISOC is not a new Microsoft security product. It is a new benefit for Microsoft 365 E5 and E7 customers, and Microsoft's own FAQ on Tech Community says the same thing. It does two main things:

  1. Extends included Defender log retention from 30 days to 90 days.
  2. Turns on SIEM features in the Defender portal for customers who chose Microsoft as their XDR but never deployed Sentinel as their SIEM.

The 90-day retention starts November 15, 2026. Until then, preview customers get 30 days. It covers Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender for Cloud, Entra ID Protection logs, and Azure Activity and Office 365 Activity logs (via connector).

What you get without creating anything

If you have E5 or E7 and no active Sentinel workspace, these show up in the Defender portal with no configuration:

  • Case management
  • Workbooks (custom reporting and dashboards)
  • Playbook generation in natural language. Describe the automation you want and it builds the playbook. This is the SOAR piece (security orchestration, automation, and response).
  • Enhanced automation rules

There is no minimum seat count. A tenant with any number of E5 or E7 licenses is eligible.

When you need an ISOC workspace

You only need an ISOC workspace if you want to ingest third-party security logs, or if you need one of the workspace-dependent features:

Capability ISOC workspace required?
Case management, workbooks, natural-language playbooks, automation rules No
Third-party and additional Microsoft/Azure data ingestion Yes
User and Entity Behavior Analytics (UEBA) Yes
Content hub connectors Yes
Repositories (CI/CD) Yes
Threat intelligence Yes

Some of these light up in phases during the preview, so don't be surprised if a feature isn't in your tenant on day one.

When a customer without Sentinel goes to connect third-party data, Defender prompts them to create an ISOC workspace. Think of it like a Log Analytics workspace. It gets created from Setup & configuration > Settings > Microsoft Sentinel > SIEM workspaces in the Defender portal and lives in your Azure subscription.

To create one, you need Security Administrator in Entra ID, plus either an unconditional Owner or User Access Administrator + Microsoft Sentinel Contributor on the Azure subscription.

The pricing is the real story

For customers without Sentinel, this is where the value is. Starting October 1, 2026, third-party data ingested into an ISOC workspace through any of the 500+ connectors is billed at $2.40 per GB on a new pay-as-you-go meter. Compare that to Sentinel's pay-as-you-go price for the analytics tier (the fastest tier, where detections and hunting run) of $4.30 per GB (East US list). That's a 44% discount.

Meter (East US list price; regional pricing varies) Price per GB
Sentinel analytics tier, pay-as-you-go $4.30
ISOC third-party ingestion meter $2.40
Sentinel data lake ingestion $0.05 (plus $0.10 data processing; storage and query metered separately)

One caveat: if you already run Sentinel on a commitment tier, your effective rate is below $4.30 (Microsoft advertises up to 52% off pay-as-you-go). Compare your actual per-GB cost, not list price.

The other thing this greatly simplifies: ISOC workspace data will be mirrored to the Microsoft Sentinel data lake at no additional cost. Presumably customers will then be able to choose which tables to move to the lake tier to take advantage of the much lower data lake ingestion price. I'm hoping that assumption gets validated at Microsoft Ignite (November 17–20), where Microsoft is expected to share more on migration path options for existing data lake customers.

Most of the data lake feature set will be available in ISOC, and interactive KQL against lake data runs in Advanced Hunting. A small handful of advanced features require Microsoft Fabric: jobs, notebooks, and graphs. Fabric compute is billed separately.

Who qualifies

Microsoft 365 E5 or E7. Microsoft's public documentation also lists Microsoft Defender Suite as eligible for the preview, but the benefit details in Microsoft's own FAQ are written for E5 and E7. If you're on Defender Suite rather than full E5 or E7, don't assume you get the 90-day retention or the $2.40 meter until your Microsoft account team confirms it.

Sentinel is not going away

Microsoft Sentinel remains available as a standalone purchase. ISOC does not replace it.

Existing Sentinel customers can opt into ISOC starting November 15, 2026. If you do, you give up the E5/E7 Sentinel benefit: up to 5 MB per user per day of free ingestion for eligible Microsoft data. If you stay on Sentinel as-is, that benefit stays in place. Weigh it carefully. For a 5,000-seat E5 tenant, that grant is up to 25 GB per day of eligible Microsoft data at no charge.

And don't disconnect a production Sentinel workspace just to qualify for the ISOC preview. Microsoft says the same thing in its documentation.

My take: existing Sentinel customers should sit tight

In my opinion, existing Sentinel customers should sit tight. Unless Microsoft announces more at Ignite, the next date you actually have to act on is March 31, 2027. After that date Sentinel is no longer supported in the Azure portal and is available only in the Defender portal (security.microsoft.com).

You don't have to wait until March to use the unified portal. Moving early has been available for quite some time. I wrote my first impressions of the unified Sentinel and Defender XDR portal back in April 2024.

If you use an MSSP, wait for their guidance

If an MSSP runs your SOC, wait for guidance from them before you change any configuration. Your MSSP should lead this change before March 31, 2027, because Microsoft is changing how an MSSP reaches your data in the unified portal.

Most MSSPs manage customer Sentinel workspaces through Azure Lighthouse today. In the Defender portal, multitenant access runs through Unified RBAC with GDAP or Microsoft Entra B2B instead. Per Microsoft's current documentation, GDAP covers Defender data only; Sentinel data in the Defender portal requires B2B, and some cross-tenant Sentinel scenarios (such as cross-workspace queries) still use Lighthouse. That access model has to be rebuilt deliberately, and it's the MSSP's job to sequence it.

If you're an E5 or E7 customer trying to decide whether an ISOC workspace makes sense, or a Sentinel customer weighing the opt-in, reach out at [email protected].

Sources

Also referenced:

Note: The author created this article with assistance from AI. Learn more