Microsoft has unveiled its Integrated Security Operations Center (ISOC) within Microsoft Defender, a move that centralizes security information and event management features from Microsoft Sentinel and rebuilds its security operations products around artificial intelligence agents, according to a recent report by Silicon Angle.The new ISOC aims to address the growing complexity of cyber threats, where attackers are increasingly leveraging AI agents. Microsoft argues that by consolidating security operations and protection into a unified system within Defender, analysts can operate more efficiently. Features like case management, workbooks, and automation playbook creation from natural language instructions are now integrated directly into the Defender portal.While some advanced capabilities, such as user and entity behavior analytics and third-party data integration, require additional setup and an ISOC workspace linked to an Azure subscription, Microsoft offers over 500 connectors for external data sources, though ingestion charges may apply. The integrated protection loop allows telemetry, exposure data, and threat intelligence to directly inform Defender's controls, enabling features like real-time attack disruption. AI agents within ISOC receive the same context and controls as human analysts, streamlining incident investigation and response, though human oversight remains crucial for strategic decisions and high-stakes actions.Source: Silicon Angle