Microsoft integrates SOC capabilities with Defender for enterprises
Summary
Microsoft has integrated Security Information and Event Management (SIEM) capabilities into its Microsoft Defender platform for E5 and E7 customers at no additional license cost. This new Integrated Security Operations Center (ISOC) combines SIEM with Defender's existing Extended Detection and Response (XDR), threat intelligence, automation, and AI tools into a single portal. The move aims to enable security operations to function at AI speed by eliminating the need for separate security systems.
IFF Assessment
This integration enhances defenders' capabilities by providing a unified platform for security operations, combining SIEM with advanced detection and response tools, which is beneficial for defense.
Defender Context
This development streamlines security operations for organizations heavily invested in the Microsoft ecosystem, offering a more integrated approach to threat detection and response. Defenders should be aware of how this bundling impacts their SIEM strategy and consider the cost-effectiveness of ingesting third-party data within the new Defender ISOC framework.