Updated
Updated · Computerworld · Sep 24
Microsoft Adds SIEM to Defender for E5 and E7 Users, Charging $2.40 per GB for Outside Data
Updated
Updated · Computerworld · Sep 24

Microsoft Adds SIEM to Defender for E5 and E7 Users, Charging $2.40 per GB for Outside Data

3 articles · Updated · Computerworld · Sep 24

Summary

  • Sept. 23 marked the public preview of Microsoft’s Integrated Security Operations Center, letting Microsoft 365 E5 and E7 customers run SIEM inside Defender with no separate Sentinel license.
  • The offer is aimed at customers already centered on Microsoft’s stack: telemetry from Defender, Entra, Azure and Office 365 comes without ingestion charges, while third-party and other external data will cost $2.40 per GB from Oct. 1.
  • Microsoft is bundling case management, workbooks and natural-language playbook generation into the Defender portal, with 30-day retention in preview rising to 90 days on Nov. 15.
  • The preview excludes organizations with an active Sentinel workspace, though eligible customers can choose to move to ISOC from Nov. 15; anything beyond the included features requires an Azure-backed ISOC workspace.
  • Analysts said the bundle could lower costs and simplify investigations for Microsoft-heavy environments, but mixed estates still need a full SIEM cost comparison and tighter controls as Microsoft pushes agent-driven security operations.

Insights

Will Microsoft's free SIEM integration trap enterprises in a costly ecosystem, or is it the ultimate weapon against AI-driven cyberattacks?
As Microsoft forces Sentinel into Defender, could relying on a single vendor for your entire security stack create a catastrophic point of failure?
Can AI-generated playbooks truly streamline security workflows, or are analysts about to face a nightmare of untested automated responses?