Blog

Microsoft ISOC Signals a New Era for Security Operations

Microsoft ISOC creates a simpler path to integrated, AI-powered security operations. Ontinue helps organizations turn that foundation into around-the-clock detection, informed response, and stronger protection. Here’s what you need to know.

Microsoft recently announced the Integrated Security Operations Center, or ISOC, in Microsoft Defender. ISOC brings SIEM capabilities, XDR, threat intelligence, automation, and AI into one integrated experience, giving security teams and AI agents shared signals, context, and workflows.

ISOC is currently available in preview for eligible organizations without an active Microsoft Sentinel workspace. Its capabilities and availability may continue to evolve during the preview.

For existing ION MXDR customers, there is no action required. Your current agreement and service delivery remain unchanged.

A Simpler Starting Point for Security Operations

Building a security operations capability has traditionally required organizations to deploy a SIEM, connect data sources, integrate detection and response tools, and establish the processes needed to operate them. This can require significant investment and specialist expertise before meaningful security outcomes are realized.

Microsoft ISOC offers another path. Eligible organizations can begin with integrated security operations capabilities in Microsoft Defender and expand their visibility as their needs evolve. This can reduce complexity for organizations starting their security operations journey while creating a more unified foundation for human analysts and AI agents.

That foundation is important, but technology alone does not deliver security outcomes.

Technology Creates Potential. Operations Deliver Protection.

Bringing signals, tools, and workflows together can help teams work more efficiently. But integration alone does not determine whether an incident is a real threat, decide how to respond, or take responsibility for the outcome.

AI agents can accelerate analysis and execute repeatable tasks at scale. People remain essential for setting priorities, applying judgment, understanding organizational context, and making critical decisions. Microsoft’s vision for ISOC explicitly positions people and agents as working together on a common foundation.

Effective security operations therefore require more than access to integrated technology. They require the expertise to interpret evidence, the context to understand what matters, and clear accountability for investigation and response.

Ontinue brings these elements together by combining automation and Agentic AI with 24/7 security expertise and human oversight. The result is not simply more alerts or faster analysis, but consistent decisions and informed action when threats emerge.

Balance Cost with Investigative Value

Microsoft ISOC also gives organizations an opportunity to reassess which security data they collect and retain.

Cost is an important consideration. During the current preview phase, eligible customers receive 30 days of included retention for Defender data. Additional Microsoft and third-party data can be added through connectors, with ingestion charges applying depending on the data selected.

Cost, however, should inform telemetry decisions rather than drive them.

Reducing telemetry may create economic benefits, but it can also affect the evidence available when analysts and AI agents need to reconstruct an attack, validate a hypothesis, or determine the full scope of an incident.

The objective is not to collect every possible log. It is to identify the signals that matter most to the organization’s environment, threat model, regulatory requirements, and response processes. Analysts and AI agents need access to the right evidence to make informed decisions and take the right action.

Ready to Help Organizations Adopt ISOC

Organizations adopting ISOC can benefit from Ontinue’s early involvement with Microsoft. Our Product and Engineering teams worked directly with the Microsoft Product Group before the announcement and remain engaged as the platform evolves.

Ontinue’s Microsoft ISOC Deployment Package helps organizations move from platform activation to an operational security environment, with the right telemetry, access controls, automation, and workflows in place.

Extending ISOC with Managed Security Operations

Deployment is only the first step. Organizations still need to operate the technology around the clock, investigate threats, make informed decisions, and take accountable action.

Ontinue will introduce a managed service built on Microsoft ISOC. The service will extend Microsoft’s integrated technology foundation with Ontinue’s automation, Agentic AI, and 24/7 Cyber Defense Center.

It will make expert security operations accessible to organizations that need continuous protection across their core Microsoft Defender environment, with a more focused scope than a comprehensive MXDR service.

This future service will provide an accessible starting point for organizations that need 24/7 protection across core Microsoft Defender signals. ION MXDR will remain Ontinue’s comprehensive service for organizations requiring broader Microsoft and third-party visibility, deeper detection and investigation capabilities, and designated expert guidance.

What This Means for Existing ION MXDR Customers

Existing ION MXDR customers do not need to take action. Your agreement and service delivery remain unchanged, and ION MXDR will continue to provide the broad visibility, expert decision-making, and operational accountability needed to turn Microsoft and third-party security signals into informed action.

As Microsoft ISOC evolves, Ontinue will continue working closely with Microsoft and help customers evaluate new opportunities in the context of their security requirements. Any future decision should consider not only potential economic benefits, but also the visibility, evidence, expertise, and operational coverage required to manage risk effectively.

Turning an Integrated Platform into Stronger Protection

Microsoft ISOC is an important step toward simpler, more integrated security operations. Ontinue will help organizations turn that foundation into effective protection, from initial deployment to 24/7 managed operations.

Keep an eye on our blog for future updates.

Sharing
Keywords