Microsoft’s September 23, 2026 announcement of the public preview of Integrated Security Operations Center (ISOC) in Microsoft Defender is more than a portal change. For eligible Microsoft Defender Suite, Microsoft 365 E5, and Microsoft 365 E7 customers, it changes how security operations capabilities, data retention, connector ingestion, and Sentinel transition decisions fit together.
Two dates deserve a place on the security and licensing calendar: October 1, 2026, when Microsoft says eligible customers can use a $2.40 per GB pay-as-you-go meter for non-Microsoft data through more than 500 connectors; and November 15, 2026, when included Microsoft Defender data retention is planned to extend from 30 to 90 days and eligible Sentinel customers can choose to move to ISOC.
What Microsoft is changing
| Microsoft’s announcement | What it means for administrators | Decision to prepare |
|---|---|---|
| ISOC is a benefit for eligible Defender Suite, Microsoft 365 E5, and Microsoft 365 E7 customers, not a standalone product. | Security operations capabilities from Sentinel appear in the Defender experience for qualifying tenants. | Verify the actual tenant SKUs and service plans before promising the benefit to every security operator. |
| Included Microsoft Defender data retention is 30 days in preview and planned to become 90 days on November 15. | Retention assumptions, investigations, and compliance evidence may change across Defender, Azure Activity, and Office 365 Activity data. | Reconcile the new window with policy, legal hold, export, and longer-term archive requirements. |
| More than 500 connectors can use a $2.40/GB pay-as-you-go ingestion meter starting October 1; regional pricing and terms may vary. | Non-Microsoft telemetry can expand quickly, and the bill is tied to data volume rather than simply enabling a connector. | Inventory sources, estimate daily volume, and assign an owner for budget and data-quality review. |
| An Azure subscription is required to create an ISOC workspace for broader ingestion and workspace-dependent capabilities. | The licensing conversation now touches Azure subscription ownership, region, permissions, and cost controls. | Confirm the subscription, resource ownership, and least-privilege access path before creating a workspace. |
ISOC is not an immediate Sentinel replacement
Microsoft explicitly says the current Microsoft Sentinel offering continues unchanged for existing Sentinel customers. ISOC gives eligible organizations another path to bring XDR, SIEM, threat intelligence, automation, and AI into Microsoft Defender; it does not turn every existing workspace into a free, automatically migrated service.
The distinction matters because the public preview has two layers. Eligible customers without an active Sentinel workspace begin receiving out-of-the-box capabilities in the Defender portal, including Cases, Workbooks, and playbook generation in natural language. Broader data ingestion and workspace-dependent capabilities such as UEBA, Content Hub connectors, repositories, and threat intelligence require an ISOC workspace. That workspace requires an Azure subscription.
Keep the architecture decision explicit: first assess whether the integrated experience improves investigation and response for your team, then compare ingestion, retention, data residency, operational ownership, and existing Sentinel commitments. Do not treat a new navigation item as a migration plan.
Before October 1: model the ingestion meter
The most immediate operational risk is enabling connectors before anyone has quantified their data. The $2.40/GB figure is a useful planning input, but Microsoft notes that regional pricing and other terms may vary. The right first step is a bounded estimate, not a broad connector rollout.
- Inventory: list the non-Microsoft sources your SOC actually needs, including identity, endpoint, network, SaaS, and cloud telemetry.
- Estimate: capture representative daily volume for each source, including retries, verbose categories, and seasonal peaks where they materially affect the result.
- Prioritize: separate must-have detections from useful context. Start with the sources that close a documented investigation or response gap.
- Budget: create a simple volume-and-cost envelope with an owner, alert threshold, and review date. Keep ingestion approval separate from connector enablement.
- Validate: confirm the connector’s data types, regional availability, retention behavior, and access model before moving from a test source to production.
For a growing business, this is also a data-minimization exercise. More signals are not automatically better if analysts cannot explain their value, the data lacks an owner, or the source creates cost without improving a decision.
Before November 15: reconcile retention and compliance
Microsoft says eligible customers will move from 30 to 90 days of included Microsoft Defender data retention on November 15. The announcement names Microsoft Defender data, Azure Activity, and Office 365 Activity logs in that benefit. That is useful for investigations, but it should not be confused with a complete records-retention or long-term archive strategy.
| Review | Questions for the owner |
|---|---|
| Current state | Which Defender and Sentinel sources are currently retained, for how long, and under which cost or compliance assumption? |
| Evidence needs | Do incident response, legal, regulatory, or audit requirements need more than 90 days or an immutable export? |
| Data boundaries | Which sources are Microsoft-native, which are non-Microsoft, and which will use the pay-as-you-go meter? |
| Operating runbook | Who owns retrieval, export, case closure, and escalation when an investigation crosses the retention window? |
Use the new retention window to improve investigation speed, not to delete a separate archive or evidence policy. Preserve the records your organization is required to preserve, and document the source of truth for every high-impact investigation.
Set guardrails around the new built-in capabilities
Cases, Workbooks, and natural-language playbook generation can reduce analyst friction, but they introduce familiar governance questions. Before broad adoption, define who can create or assign cases, who can publish a workbook, which automations may run without approval, and how the team reviews AI-generated workflow logic.
- Cases: establish ownership, severity language, required evidence, handoff rules, and closure criteria.
- Workbooks: classify dashboards by audience, document the underlying data, and review access before exposing executive or sensitive operational views.
- Playbooks: start with read-only or notification actions, require an approval boundary for containment or write operations, and log every production execution.
- Workspace: use a dedicated subscription and least-privilege roles where practical, with budget alerts and a named service owner.
These controls keep the preview from becoming a parallel, undocumented SOC. They also make a later move from existing Sentinel patterns easier to explain to security leadership and auditors.
A safe 30-day ISOC readiness plan
| Phase | Scope | Evidence to retain |
|---|---|---|
| Confirm | Check eligible licensing, tenant roles, Azure subscription ownership, and regional requirements. | SKU and service-plan snapshot, access matrix, subscription owner, and decision log. |
| Model | Estimate connector volume, retention needs, and the October meter exposure for one priority use case. | Source inventory, daily-volume assumptions, budget envelope, and data-minimization rationale. |
| Pilot | Use the Defender-native Cases, Workbooks, and playbook capabilities with a small analyst group. | RBAC decision, sample cases, workbook review, automation test results, and rollback path. |
| Compare | Assess ISOC against the current Sentinel operating model before changing production ownership or routing. | Capability map, cost comparison, retention comparison, migration risks, and recommendation. |
| Decide | Approve expansion, hold, or a controlled transition with security, IT, finance, and compliance owners. | Signed decision, implementation backlog, communications plan, and review date. |
Frequently asked questions
What is Microsoft Defender ISOC? Microsoft describes Integrated Security Operations Center as a benefit that brings security operations capabilities from Sentinel into Microsoft Defender for eligible Defender Suite, Microsoft 365 E5, and Microsoft 365 E7 customers. It is not a standalone product.
Who can use the preview? Microsoft says an active eligible license is required and there is no minimum seat threshold. An Azure subscription is required to create an ISOC workspace and use workspace-dependent capabilities.
What should happen on October 1? Eligible customers can use a $2.40 per GB pay-as-you-go meter for non-Microsoft data through more than 500 connectors. Confirm the pricing and terms for your region before enabling production ingestion.
What should happen on November 15? Review the planned 90-day included retention window and decide whether an eligible Sentinel environment should remain in place or be evaluated for a controlled move to ISOC. Microsoft says existing Sentinel customers are not changed automatically.
Need an ISOC readiness review?
Accred Consulting can map Defender and Sentinel data flows, model connector cost, design retention guardrails, and turn the preview into an approval-ready operating plan.
Plan a Security Operations Review