AI Affairs, home

Thursday 24 September 2026

Technology

Microsoft introduces ISOC in Defender for agentic security era

The company says attackers now use agents to automate execution at unprecedented scale, exposing the limits of separate protection and operations systems.

Rows of white server racks in a data center aisle
Photo: PiDatacenters, CC BY-SA 4.0, via Wikimedia Commons (cropped)

Microsoft announced ISOC in Microsoft Defender on 23 September 2026, describing it as a foundation built for agentic security that brings security information and event management and threat protection together in one system.

Key points

  • Microsoft says cyberattackers are using agents to automate execution at unprecedented scale, exposing the limitation of protection and operations built as separate systems.
  • ISOC provides signals and sensors for awareness, context for understanding, and actuators for protective action, enabling an integrated protection loop.
  • The integrated protection loop includes attack disruption capabilities that spot, forecast and adjust to an attacker while the attack is still in progress.
  • ISOC in Microsoft Defender is available in preview from 23 September 2026, alongside a whitepaper titled “Agentic SOC: The new operating model for continuous defense”.

The agentic threat surface

Microsoft says cyberattackers are now using agents to automate execution at unprecedented scale, and that what once demanded whole teams now demands one person and an agent framework. The company argues this change has revealed a difficult reality: security cannot move at AI speed when protection and operations are constructed as distinct systems, because every transfer, integration and border slows defenders down, and agents absorb that complexity.

Integrated protection loop

ISOC is designed to furnish signals and sensors that give the system awareness, context that converts those signals into understanding, and actuators that turn insights into protective action. With these layers functioning together, Microsoft says the outcome is an integrated protection loop that keeps turning what defenders learn into stronger pre-breach protection, breaking the pattern of linear security workflows.

Attack disruption in Microsoft Defender demonstrates what this makes possible. Detailed telemetry and controls allow the system to spot, forecast and adjust to an attacker while the attack is still in progress, interrupting threats underway and predicting where attackers might head next. The loop applies exposure insights to reinforce protection in near real time with threat intelligence directing it toward the threats that matter most, and ISOC assembles the capabilities required to render this loop native, removing the work of putting it together, adjusting and keeping it up by hand.

From July stack to ISOC

The announcement builds on Microsoft’s July 2026 introduction of an end-to-end cyber stack alongside Project Perception, focused on delivering models, a harness and specialised agents to help defenders perceive, reason and act at machine speed. The company says intelligence and orchestration alone are not enough, because agents depend on the rest of the stack working as one, and ISOC represents the next layer addressing the integration of security operations and native protection rather than adding isolated AI features.

For practitioners, the capabilities required to probe, search, automate, handle incidents, grasp threats and respond are gathered and ready from the start. Rather than arranging their work around the borders between tools, teams can arrange around the security outcome they aim for, and the foundation grows more capable as autonomy increases, with the integrated protection loop assuming more of the ongoing labour of spotting and countering threats.

Preview and whitepaper

ISOC in Microsoft Defender is available in preview from 23 September 2026, alongside a whitepaper titled “Agentic SOC: The new operating model for continuous defense”.

Topics: Agents, Enterprise adoption, Safety