ISOC Is a Licence Change in an Agentic Costume (And That's Actually Good News)

ISOC Is a Licence Change in an Agentic Costume (And That's Actually Good News)

All right class.

You've got E5. You've got Defender filling the incident queue before your first coffee. You haven't got Sentinel, because the last time somebody priced it the finance director went quiet in a way that felt personal.

Then on 23 September Microsoft announced ISOC, with a keynote and a blog post that opens "The physics of cybersecurity are changing".

So is this the SIEM you never bought, or just hype?

It's a licence change wearing an agentic costume. Take the costume off and what's underneath is actually good: E5 and E7 tenants get SIEM features they used to buy Sentinel for, and they get their Defender data without paying to ingest it. The agents are a trailer for a game that's still in invite-only beta.

Read the patch notes, not the cinematic. Then notice how much the patch notes leave out.

What it actually does

ISOC isn't a new product. Microsoft's own FAQ says so. It's a benefit for Microsoft 365 E5, E7 and Microsoft Defender Suite, in public preview since 23 September 2026. There's no minimum seat count, but for now you only qualify if you don't already run a Microsoft Sentinel workspace.

It comes in two halves.

Half one, no workspace needed. Microsoft says these are available out of the box in the Defender portal:

  • Cases. Incident cases and generic cases, with tasks, templates and SLA policies.
  • Workbooks. Dashboards that query advanced hunting directly.
  • Enhanced automation rules. Rules that fire on new alerts and on new or updated cases.
  • Playbook Generator. You describe a workflow in plain English, it writes a Python playbook, and you review and test it before switching it on.

Half two, workspace needed. Third-party logs through 500-plus connectors, UEBA, Content hub, CI/CD repositories and threat intelligence all need an ISOC workspace. You create it in Defender under Setup & configuration > Settings > Microsoft Sentinel > SIEM workspaces, and it lives in your Azure subscription.

The data is where the money is. Defender for Endpoint, Office 365, Identity, Cloud Apps and Cloud, plus Entra ID Protection, stay where they already live, so none of it gets ingested twice. Azure and Office 365 activity logs come in through connectors. Retention is 30 days now, with 90 days planned from 15 November.

Non-Microsoft data costs $2.40/GB, pay-as-you-go, from 1 October, and Microsoft says regional pricing may vary. What the rest of your Microsoft data costs, Microsoft doesn't say.

The buff hiding under the agent talk

Until 23 September, E5 gave you Defender XDR but not a SIEM. Workbooks and SOAR-style automation meant buying Sentinel, and Microsoft's FAQ now says exactly that about the features ISOC includes.

That's buff number one. An E5 tenant that never justified Sentinel now gets a case queue with SLAs and dashboards over data it already owns. No workspace. No ingestion invoice.

Buff number two is the meter. On Microsoft's own retail price list, Sentinel pay-as-you-go in East US is $4.30/GB, so ISOC's $2.40/GB for non-Microsoft data is 44% less. If you're on a commitment tier you already pay less than $4.30, because Microsoft discounts those tiers by up to 52%, so compare against your invoice, not the price list.

Buff number three is retention. Advanced hunting gives you 30 days of Defender data. From 15 November, ISOC tenants get 90 without ingesting a byte.

I do wonder what an ISOC workspace actually is, given it's created under Microsoft Sentinel settings, wants the Microsoft Sentinel Contributor role and turns up on a page called SIEM workspaces.

The costume is Project Perception, which Microsoft announced on 27 July: red, blue and green agents, plus a multi-model setup that includes Microsoft's new MAI-Cyber-1-Flash model. Microsoft's docs call it a limited public preview for a small, invitation-only set of customers, and it's billed separately, on consumption. ISOC is the floor those agents will stand on. Unless you're on the invite list, the new AI you'll actually touch in ISOC is the Playbook Generator.

The blog calls it the Integrated Security Operations Center. The small print calls it a benefit. Trust the small print.

Limitations

Every patch has a known issues list, and this one's long.

Sentinel customers wait until 15 November. Microsoft's advice is to keep using Sentinel and not to disconnect a production workspace just to qualify. So, in its generosity, Microsoft has handed E5 customers SIEM features and politely asked everyone who already bought Sentinel to wait in the car.

Your identity logs aren't on the list. Today the E5 grant gives you up to 5 MB per user per day of free Sentinel ingestion, and it covers SigninLogs and AuditLogs. Microsoft values it at up to $2,200 a month for a typical 3,500-seat tenant. ISOC's included list names Entra ID Protection, not sign-in or audit logs. Defender does have its own sign-in table, EntraIdSignInEvents, but it has different columns, so your SigninLogs rules won't run on it unchanged.

Content hub installs connectors and nothing else. In the preview, a solution that ships analytics rules, hunting queries and workbooks gives you the data connector only. The logs flow in, and writing the detections is your problem. Greyhound Research's Sanchit Vir Gogia told CSO Online that the 500-connector claim "establishes reach, not equal treatment of every source".

The Playbook Generator is on a short lead.

  • Python only, with no external libraries and no playbooks calling other playbooks.
  • 100 playbooks per tenant, and each run stops at 10 minutes.
  • Enhanced automation rules run one action each, with no priority ordering.
  • Run results go to the activity log, not SentinelHealth, so your existing automation monitoring won't see them.

Microsoft says a human has to review the generated code, so read every line. Also, clicking Save in the chat approves a step without saving the playbook, which is exactly the sort of thing I'd find out at 1am.

UEBA isn't in the box. It's listed as an ISOC capability, but Microsoft's UEBA doc calls it an optional paid Sentinel capability that isn't included with E5. The good news is that it reads Defender's own tables without you ingesting them first. Log Analytics charges apply to what it writes out.

MSSPs get a preview built for one tenant. Microsoft's product page says the workspace sets up in "just two clicks". The docs have eight steps and want Security Administrator in Entra plus Owner, or User Access Administrator and Microsoft Sentinel Contributor, on the customer's subscription, which no sensible MSSP holds. Defender's multitenant portal still needs Entra B2B rather than GDAP for Sentinel data, still needs Lighthouse for cross-tenant queries, and still stops at 100 tenants. Workspace manager still isn't in the Defender portal.

Agents have an audit trail, not the full story. Microsoft's Perception docs say session records can't be altered after the fact, and agents can be set to pause for approval before high-impact actions. Each agent gets its own Entra Agent ID, and device groups have to be assigned to it by hand. What I haven't found in those docs is how you undo an action once an agent has taken it.

What the patch notes don't say

This is the part that bothers me. For all the diagrams, Microsoft hasn't answered the questions you need answered before you move anything. Right now it's a muddle.

  • What the rest of your Microsoft data costs. Microsoft's announcement puts the 500-plus connectors on a $2.40/GB meter. The FAQ in the same post says that meter is for non-Microsoft data. Neither says what SigninLogs, AuditLogs, Azure diagnostics or Windows security events cost, and the Learn docs only say ingestion charges might apply.
  • What happens to the E5 grant. Microsoft's ISOC docs on Learn don't mention it.
  • What an ISOC workspace actually is. The onboarding doc covers the subscription, resource group, workspace name and region, and doesn't say what kind of resource you end up with.
  • What happens to your data on 15 November. Microsoft says existing Sentinel customers get a choice to move. It hasn't said what happens to their history, retention settings or content when they do.
  • Who actually gets what. Microsoft lists Defender Suite as eligible, then its own FAQ describes the benefit for E5 and E7 customers only. The Defender Suite add-on for Business Premium, which Microsoft says delivers the same product capabilities as Defender Suite, isn't mentioned at all.
  • How ISOC works across tenants. The only multitenant mention I found is a link to managing cases across tenants. Nothing covers ISOC workspaces, the benefit or generated playbooks in multitenant management.

Until those answers land, nobody can do the maths properly, Microsoft's partners included. Ignite (17 to 20 November) is the obvious place to fix that.

The real decision

E5 or E7 with no SIEM. Yes. Turn on the free features this week. It costs nothing extra in licensing, an afternoon to set up cases and a first workbook, and a day to build and properly review one generated playbook. Only create a workspace when a specific third-party source earns it, and price that source first:

Third-party logs ISOC ($2.40/GB) Sentinel pay-as-you-go ($4.30/GB)
10 GB a day about $720 a month about $1,290 a month
100 GB a day about $7,200 a month about $12,900 a month

At 100 GB a day you'd be on a Sentinel commitment tier: $296 a day on Microsoft's East US price list, roughly $8,880 a month, so the gap narrows and ISOC still wins. These are East US list prices for ingestion only, on a 30-day month. Your region, extra retention and VAT all move the numbers.

Existing Sentinel on E5. Not yet. Nothing changes before 15 November, and after that moving is a choice, not a deadline. The date that actually matters is 31 March 2027, when Sentinel leaves the Azure portal. You can't price both sides properly yet, because Microsoft hasn't priced the Entra logs, Azure diagnostics and security events sitting in your workspace today. Run the query below now so you're ready when it does.

MSSPs. Pilot, don't promise. Test with one greenfield E5 customer that has no Sentinel, leave everyone else alone until the multitenant story is written down, and wait for Ignite before redesigning a service. Start planning for the shift, though. When SIEM features and Defender data come with the licence, "we run your SIEM" gets harder to sell than "we write and tune your detections".

Defender Suite without full E5. Yes, once it's in writing. Microsoft lists it as eligible, but its FAQ describes the benefit for E5 and E7, so get the 90-day retention and the $2.40 meter confirmed before you plan around them.

Business Premium. No, not today. It isn't on the eligible list, and Microsoft excludes security mini suites, standalone security suites, Education and Frontline SKUs. The Defender Suite add-on for Business Premium isn't named either way, and a similar name isn't an entitlement. Get it in writing before anyone sells ISOC to a 300-seat customer.

Next steps

  1. Check eligibility (10 minutes). Look up the SKU in the Microsoft 365 admin center, not on the reseller quote. If you already have an active Sentinel workspace, you're waiting for 15 November.
  2. Set up cases first (1 hour). Build a case template and an SLA policy before anyone opens a case.
  3. Generate one harmless playbook (half a day). Something read-only, like enriching the URLs in an alert, is the right size. Leave Auto-approve off, test it on a real alert ID, read every line, then switch it on.
  4. Price your data before you create a workspace (1 hour). If you run Sentinel today, this splits the last 30 days of billable data into what ISOC covers, what the E5 grant covers and what nobody has priced yet:
// Billable volume for the last 30 days, grouped by how ISOC treats it
let DefenderNative = dynamic(["CloudAppEvents", "EmailEvents", "EmailAttachmentInfo", "EmailPostDeliveryEvents", "EmailUrlInfo", "UrlClickEvents", "IdentityLogonEvents", "IdentityQueryEvents", "IdentityDirectoryEvents", "AlertInfo", "AlertEvidence"]);
let IdentityProtection = dynamic(["AADRiskyUsers", "AADUserRiskEvents", "AADRiskyServicePrincipals", "AADServicePrincipalRiskEvents"]);
let EntraLogs = dynamic(["SigninLogs", "AADNonInteractiveUserSignInLogs", "AADServicePrincipalSignInLogs", "AADManagedIdentitySignInLogs", "AuditLogs", "AADProvisioningLogs", "ADFSSignInLogs"]);
Usage
| where TimeGenerated > ago(30d)
| where IsBillable == true
| extend Bucket = case(
    DataType startswith "Device" or DataType in (DefenderNative), "Defender tables (native in ISOC)",
    DataType in (IdentityProtection), "Identity Protection (on ISOC's list)",
    DataType in (EntraLogs), "Entra logs (E5 grant today, no ISOC price)",
    "Everything else (third-party $2.40/GB, Microsoft unpriced)")
| summarize BillableGB = round(sum(Quantity) / 1024, 2) by Bucket
| sort by BillableGB desc
  1. Take the muddle list to the AMA (1 hour). Microsoft is running an Ask Microsoft Anything with the ISOC engineers on Tech Community on 6 October. Every question in the section above is fair game.

Patch verdict: a proper buff for E5 tenants without a SIEM, homework for anyone already running Sentinel, and a very loud trailer for agents most of you can't play yet. Hype or dog's dinner? Neither. It's a good patch with an overproduced trailer and a lot of missing small print.

Class dismissed.

Consent Preferences