Source: CSO Online
Author: unknown
URL: https://www.csoonline.com/article/4226195/microsoft-integrates-soc-capabilities-with-defender-for-enterprises.html
ONE SENTENCE SUMMARY:
Microsoft’s ISOC brings bundled SIEM into Defender for E5/E7, reducing Microsoft-log costs while raising third-party metering and vendor-dependency concerns.
MAIN POINTS:
- E5/E7 customers can now use SIEM in Microsoft Defender without extra license cost.
- ISOC unifies SIEM with XDR, threat intelligence, automation, and AI in one portal.
- Previously, SIEM required a separate Microsoft Sentinel purchase despite Defender XDR inclusion.
- Microsoft-source security logs incur no ingestion charges under ISOC.
- Third-party and external data ingestion becomes pay-as-you-go at $2.40 per GB from Oct. 1.
- Public preview began Sept. 23; production readiness and end date remain unspecified.
- Eligibility requires Defender Suite plus E5/E7, no Sentinel workspace, and no minimum seats.
- Case management, workbooks, and natural-language SOAR playbooks roll out automatically to eligible tenants.
- Included telemetry spans Defender products, Entra ID Protection, and Azure/O365 activity logs.
- Retention is 30 days in preview, increasing to 90 days on Nov. 15.
TAKEAWAYS:
- Microsoft-heavy stacks may gain major savings by avoiding re-ingestion of vendor-held telemetry.
- Mixed and multicloud environments should compare total SIEM ownership costs versus current tools.
- Migrating from established SIEMs demands scrutiny of retraining, content portability, and exit costs.
- Workspace-based features (connectors, UEBA, CI/CD, TI) require Azure subscription and added complexity.
- SOC agents increase risk via telemetry poisoning and prompt injection, needing strict identities and approvals.