On 23 September Microsoft opened a preview of something it calls the Integrated , or ISOC, inside the Microsoft Defender portal. The capabilities that used to live in , a separate product with its own workspace and its own bill, now sit in the same console as , Identity, and Cloud Apps. Case management, workbooks, automation rules and playbooks you describe in plain English are there from day one. Microsoft says eligible tenants get 30 days of Defender data retention included during this phase of the preview, moving to 90 days on 15 November.
ISOC is for tenants with Microsoft 365 E5, Microsoft 365 E7 or the Microsoft Defender Suite that do not already have a Sentinel workspace running. Business Premium is not on the list. Neither are the education and frontline SKUs, nor the smaller standalone security bundles. Existing Sentinel customers are told, in Microsoft's own words, not to disconnect a production workspace to qualify, and they will get the option to move from 15 November.
What is in the box, and what is not
The out-of-the-box list is short and useful. Case management. Workbooks. Automation rules. Playbook generation in natural language, which means describing what you want to happen when an alert fires and having the platform draft the logic. All of that works on Defender's own data without any further setup.
The second tier needs an ISOC workspace, which in turn needs an Azure subscription. That is where user and entity behaviour analytics live, along with , the Content hub with its 500-odd connectors for third-party data, and detection content deployed from a repository. Microsoft's docs say additional ingestion charges may apply, and its announcement put a figure on it: from 1 October, non-Microsoft data comes in at US$2.40 a gigabyte. Firewall and VPN logs, and anything else from outside the Microsoft estate, will cost by volume the way they always have.
Rob Lefferts, the corporate vice president who runs Microsoft Threat Protection, wrote that "what once required entire teams now requires a single operator and an agent framework". The agents are the Perception agents Microsoft introduced in July, working from the same signals and context as the human analyst, with high-stakes actions held for a person to approve. Microsoft's phrase for that is "strategy stays human". There is a Tech Community AMA on 6 October and Ignite runs from 17 November, so expect the preview to move quickly.
Our opinion
The console is the least interesting part of this announcement.
The announcement is about where the tooling lives. For an E5 tenant the SIEM is no longer a product you buy alongside your licence. It is a feature of the licence, in the portal your team already opens. That is the same direction the endpoint story took when Defender for Endpoint became a fixture of the Microsoft 365 bundle, and it is the direction we bet on when we built Fortify.
Fortify is Microsoft-first on purpose. We do not layer third-party agents on top of the Microsoft stack. We configure , Defender, and to standards and lift the month on month, because the platform most Australian SMEs already run has most of the controls they need, switched off or half configured. Every time Microsoft folds another capability into the portal, that bet looks better and the case for a separate SIEM and a separate looks worse for a business of 20 to 500 people.
Back to Lefferts's sentence. A single operator and an agent framework. The operator did not go away. The tooling gap between a large enterprise SOC and a fifty-person accounting firm has been closing for years and ISOC closes it further. The gap that remains is the person who reads the console at 2am, decides whether the alert is a scanner or a foothold, and picks up the phone. Microsoft has never sold that, and ISOC does not change it. Monitoring is a job, not a licence tier.
If you are on Business Premium
Nothing here applies to you today, and that is fine. Defender for Business, which Business Premium includes, is the endpoint detection product. What it does and does not do is written up here. You do not need a SIEM to get the basics right, and the basics are still where most Australian SMEs are exposed. on every account and that actually blocks. That is the Microsoft 365 hardening work that closes the doors affiliates walk through, and no console launch changes the order of operations.
Do not upgrade to E5 to get ISOC. At the licence prices involved, the money is better spent making sure what you already pay for is configured and watched.
If you are on E5 or E7 with no Sentinel
Turn it on. It is included, the retention is 30 days now and 90 in November, and case management alone is worth having if incidents are currently tracked in a Teams channel. Then give someone the job of looking at it every day, because 30 days is not long. The Mathspace breach sat on a public flaw for 23 days. The Auto-IT compromise was listing dealerships on a leak site for a month before the vendor confirmed it. If your retention is shorter than your time to notice, the console will be empty when you finally look.
Two cautions from the preview itself. Everything beyond Defender's own data needs an Azure subscription and a workspace, and third-party ingestion is metered, so the bill moves rather than disappearing. And it is a preview. Microsoft says capabilities and availability may change, which in practice means the thing you build a runbook around in October may look different by Ignite.
Does ISOC replace Microsoft Sentinel?
Not yet. Sentinel continues as it is for existing customers. From 15 November eligible Sentinel customers can choose to move to ISOC. Microsoft has said there is no change for current Sentinel tenants and has told them not to disconnect a production workspace to qualify for the preview.
Do we need an Azure subscription?
Only for the second tier. Case management, workbooks, automation rules and playbook generation run on Defender data with no workspace. Behaviour analytics, third-party connectors, threat intelligence and content repositories need an ISOC workspace, and that needs an Azure subscription.
Is Fortify affected by this?
Fortify already runs on the Defender portal, so a better portal helps us and costs you nothing extra. Where a client is E5 eligible we will use ISOC's case management and playbooks. Where a client is on Business Premium, which is most of them, the work is the same as it was last month: configure the tenancy properly and watch it.



