What happened
On Sept 23 Microsoft announced ISOC in Microsoft Defender, converging SIEM (Sentinel capabilities) and XDR into a single SOC foundation with case management, workbooks, playbooks, and AI-assisted investigation; Defender XDR retention rises to 90 days and third-party ingestion via 500+ connectors at new lower rates.
Why it matters
Lowers the barrier to a modern SOC for the agentic era by eliminating separate Sentinel deployment for many E5/E7 shops, making AI-assisted detection/response the default operating model and shifting SIEM consumption economics.
Applicability
Microsoft 365 E5/E7 security teams evaluating SIEM consolidation; review ingestion architecture in preview before migrating production workspaces.