Microsoft folds Sentinel's SIEM into Defender — and Sentinel users wait

Share
Microsoft folds Sentinel's SIEM into Defender — and Sentinel users wait

Microsoft spent Wednesday collapsing two security products into one, and the fine print is doing as much work as the announcement. Also in this brief: a Chinese court says an AI-generated image isn't a protected work at all.

Microsoft opened a public preview of an Integrated Security Operations Center (ISOC) inside Defender, moving Sentinel's security information and event management features — case management, workbooks, and playbook generation written from plain-language instructions — into the Defender portal so teams can run security operations without standing up a separate SIEM first. Rob Lefferts, the corporate vice president for Microsoft Threat Protection, framed the shift around the adversary rather than the product: "What once required entire teams now requires a single operator and an agent framework." Inside ISOC, AI agents get the same signals, context and controls as a human analyst, which is the substance of the pitch — an agent investigating an incident is only useful if it can see what the analyst sees, and Microsoft's design keeps high-stakes actions behind human approval, a stance Lefferts summarises as "strategy stays human." The agentic layer itself isn't new; it's Project Perception, which Microsoft introduced in July with MAI-Cyber-1-Flash, its first in-house security model.

The eligibility rules are the part worth reading twice. During this preview ISOC is open to customers with Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 — and explicitly not to organisations that already run an active Sentinel workspace, with Microsoft's documentation telling them not to disconnect production Sentinel merely to qualify. That is an odd sentence for a vendor to publish on launch day, and it is the clearest signal yet that Sentinel, as a standalone product, is being absorbed rather than replaced. Pricing isn't disclosed, workspace-dependent features such as user and entity behaviour analytics, threat intelligence and anything beyond Defender data need an Azure subscription and may carry ingestion charges, and the preview includes thirty days of Defender data retention. More than 500 connectors exist for bringing in everything else, which is where the meter starts running.

Seen together with the week's other enterprise security news, the thesis is consistent: Oracle is arguing the complementary half from the other end — that agents cannot be trusted to enforce their own security, so authorisation belongs in the database, beneath the agent rather than inside it. Two vendors, one conclusion: the control plane is being rebuilt around agents, and the open question is no longer whether agents need governance but at which layer it gets enforced. Our read is that Microsoft's bet is the more comfortable one commercially and the riskier one architecturally — it asks the agent to police the same surface it operates on. We looked at the opposite instinct, enforcement that travels with the agent, in Talos ships a permission kernel for AI agents that demand shell access.


A basic-level court in Changsha dismissed a copyright claim over an AI-generated image, ruling the picture carried no originality and was therefore not a protected work — and became the first reported case to spell out a layered test for deciding when a generated image qualifies. The plaintiff had acquired the economic rights to a Dragon Boat Festival sachet image produced with Jimeng AI and then touched up in Photoshop; a kindergarten republished it on its WeChat account. The Kaifu District People's Court split the generation process into front-end conception, generation control and back-end processing, then assessed originality at each layer — asking of the middle layer whether the prompt pointed at expression rather than subject matter, whether prompt and output corresponded, and whether the user's choices dominated. Here the prompt reached only genre, colour and style, and the edit was a technical fix, so nothing cleared the bar. Both sides waived appeal, so the judgment is effective.

It points the opposite way to the Beijing Internet Court's 2023 finding that a Stable Diffusion image could be protected, and the caveats are proportionate: a district court binds nobody, China has no doctrine of precedent, and no source has published the judgment date. What it is, is a map of where one court is drawing the line — and a reminder that the AI copyright argument runs in both directions, as we argued in Training AI on books is fair use — piracy is the crime.

What to watch: whether Microsoft publishes the ISOC migration path and pricing for the Sentinel customers it just asked to wait, and whether other courts adopt Changsha's three-layer framework or ignore it.

If an agent can investigate an incident on its own, who is answerable when it acts on the wrong one — the operator, or the vendor? Tell us in the comments.

Sources: Microsoft Security Blog · Microsoft Learn — ISOC in Microsoft Defender (preview) · CRN · SiliconANGLE · SiliconANGLE — Oracle puts database security controls beneath AI agents · 华声在线 Hunan Online · 光明网 Guangming Online