Microsoft integrates SOC capabilities with Defender for enterprises

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4226195/microsoft-integrates-soc-capabilities-with-defender-for-enterprises.html

https://www.csoonline.com/article/4226195/microsoft-integrates-soc-capabilities-with-defender-for-enterprises.html

ONE SENTENCE SUMMARY:

Microsoft’s ISOC brings bundled SIEM into Defender for E5/E7, reducing Microsoft-log costs while raising third-party metering and vendor-dependency concerns.

MAIN POINTS:

  1. E5/E7 customers can now use SIEM in Microsoft Defender without extra license cost.
  2. ISOC unifies SIEM with XDR, threat intelligence, automation, and AI in one portal.
  3. Previously, SIEM required a separate Microsoft Sentinel purchase despite Defender XDR inclusion.
  4. Microsoft-source security logs incur no ingestion charges under ISOC.
  5. Third-party and external data ingestion becomes pay-as-you-go at $2.40 per GB from Oct. 1.
  6. Public preview began Sept. 23; production readiness and end date remain unspecified.
  7. Eligibility requires Defender Suite plus E5/E7, no Sentinel workspace, and no minimum seats.
  8. Case management, workbooks, and natural-language SOAR playbooks roll out automatically to eligible tenants.
  9. Included telemetry spans Defender products, Entra ID Protection, and Azure/O365 activity logs.
  10. Retention is 30 days in preview, increasing to 90 days on Nov. 15.

TAKEAWAYS:

  1. Microsoft-heavy stacks may gain major savings by avoiding re-ingestion of vendor-held telemetry.
  2. Mixed and multicloud environments should compare total SIEM ownership costs versus current tools.
  3. Migrating from established SIEMs demands scrutiny of retraining, content portability, and exit costs.
  4. Workspace-based features (connectors, UEBA, CI/CD, TI) require Azure subscription and added complexity.
  5. SOC agents increase risk via telemetry poisoning and prompt injection, needing strict identities and approvals.