Urgent.News

What's breaking now, across thousands of outlets.

AI

Microsoft unveils Integrated Security Operations Center in Defender for AI agents

Microsoft Corp. today unveiled Integrated Security Operations Center in Microsoft Defender as it rebuilds its security operations products around artificial intelligence agents. The service moves security information and event management features from Microsoft Sentinel directly into Defender. ISOC is aimed at a problem Microsoft says is getting worse as attackers put agents to work. “What […]…

Microsoft unveils Integrated Security Operations Center in Defender for AI agents

Microsoft has unveiled a new Integrated Security Operations Center (ISOC) within its Defender product as part of a broader shift to AI-driven security operations. The service consolidates security information and event management features from Microsoft Sentinel directly into Defender, allowing for streamlined security management by a single operator.

Rob Lefferts, corporate vice president of Microsoft Threat Protection, highlighted that protection and day-to-day operations often run as separate systems, causing analysts to piece together incidents manually across multiple tools. ISOC aims to address this issue by providing a unified platform.

Key features from Microsoft Sentinel, such as case management and workbooks, function seamlessly within the Defender portal without any setup. Additionally, ISOC includes a feature that generates automation playbooks from plain-language instructions. However, certain components like user and entity behavior analytics and the ability to ingest data from Azure and third-party sources require additional setup, including the creation of a dedicated ISOC workspace linked to an Azure subscription. Microsoft warns that ingestion charges may apply for these external data sources.

A central component of ISOC is the integrated protection loop, which integrates telemetry, exposure data, and threat intelligence directly into Defender's controls. This loop is exemplified by Defender's existing attack disruption feature, which can respond to intrusions in real-time. The agents within ISOC receive the same signals, context, and controls as human analysts, ensuring that core security workflows are seamlessly integrated.

This integration allows agents to investigate incidents and act upon them without the need for a separate operating model.

ISOC builds upon Microsoft's Project Perception, introduced in July alongside MAI-Cyber-1-Flash, its first in-house security model. While Project Perception agents require human approval for high-stakes actions, priorities are still set by people, maintaining a strategic human oversight. During the public preview, which opens today to customers with Microsoft Defender Suite, Microsoft 365 E5, or Microsoft 365 E7 licenses, Defender data is retained for 30 days at no additional cost.

Microsoft has not disclosed the pricing for ISOC. A Tech Community Ask Me Anything session on the service is scheduled for October 6.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

More from Wednesday 23 September →