A cybersecurity analyst monitors threat alerts and cloud security dashboards in a dimly lit operations center.
BlueVoyant's Microsoft Defender XDR ISOC Deployment Service is a partner offering for Microsoft's new Integrated Security Operations Center in Defender. Before you call anyone, check Microsoft's preview eligibility rules. They matter more than the sales pitch.

What BlueVoyant launched, and when​

Channel Insider's October 2 interview coverage is not the first appearance of this launch. BlueVoyant's own announcement was dated September 23, 2026. It described the service as one of the first deployment solutions built to help enterprises adopt the newly announced ISOC in Microsoft Defender.

Channel Insider's contribution is an interview with Micah Heaton, BlueVoyant's executive director of Microsoft Product and Innovation Strategy. Heaton explains the thinking behind the service.

The service targets Microsoft 365 E5, Microsoft 365 E7 and Microsoft Defender Suite customers. Its stated aim is to assess existing deployments, configure the underlying security technologies, and operationalize detections, workflows and automation. BlueVoyant wants that done before organizations give AI agents a bigger role in the SOC.

BlueVoyant says the service is available now, with implementation aligned to customer eligibility, agreed scope and Microsoft's phased rollout. In plain terms, the vendor can start a conversation today, but what it can deploy depends on Microsoft's preview.

What the service includes​

According to the Channel Insider report, customers can start with a no-cost ISOC Readiness Assessment. It looks at what is already deployed, where capabilities are fragmented, and what a scoped deployment would need. Heaton said it also looks at license levels. It examines how responsibilities are divided among security operations, infrastructure, networking, cloud operations and other teams.

The deployment support covers three areas:

  • Defender deployment and configuration across Endpoint, Identity, Office 365, Cloud Apps and Entra ID Identity Protection.
  • Walkthroughs of ISOC custom detections, workbooks, automation and user and entity behavior analytics (UEBA).
  • Use-case engineering to develop and refine detection rules, workbooks and automations.

Heaton said BlueVoyant doesn't need direct access to a customer's environment for the assessment. Customers export data and snapshots instead, and BlueVoyant uses them to identify engineering use cases. The report doesn't say which data fields are involved, what format they take, or how the data is transferred and handled. Ask about all of that before you hand anything over.

A BlueVoyant blog post adds scoping detail. It says the service includes up to 20 hours of use-case engineering. It also says the engagement is scoped to one tenant. The same post describes the no-cost readiness diagnostic, the scoped deployment engagement and ongoing managed detection and response (MDR) as distinct services. The vendor itself is therefore separating the free assessment from paid implementation and from 24/7 operations. The Channel Insider piece doesn't give a price for implementation.

Heaton's argument: operational debt​

Heaton's central claim is that the main barrier to agentic security isn't a lack of AI. He called it "operational debt." Customers already own a lot of capability, he said, but their data is fragmented, detections are untuned, workflows are inconsistent, and available automation was never put into operation.

His line is that agentic security "turns yesterday's technical debt into tomorrow's decision debt." That is a vendor's opinion, not a measured finding. It is still a reasonable thing to worry about. An agent working from noisy or incomplete signals will reach conclusions faster, but they won't be any better.

He also rejected the framing of humans versus agents. In his view people keep responsibility for strategy, risk and accountability, and agents provide scale. He said the useful question is which decisions you are comfortable delegating, under what conditions, and how you verify the outcome.

Other points from the interview:

  • Not Microsoft-only: Heaton said integrated doesn't have to mean exclusively Microsoft. Customers should start with what they own and expand where extra context clearly improves an outcome.
  • Partner role: He sees a deployment opportunity and a 24/7 managed-operations opportunity for MSPs and MSSPs.
  • Operational ownership: He said BlueVoyant designs detections by asking what happens at 2 a.m. during an incident, who owns it, and what should happen next.

Microsoft's eligibility rules​

Microsoft Learn is the authority on what ISOC is and who can use it. It describes ISOC as bringing SIEM and XDR together in the Defender portal. The Microsoft Learn overview page labels it a preview and warns that capabilities and availability might change.

The eligibility rules matter most:

  • License and Sentinel limits: During this phase of the preview, ISOC is available to eligible customers with Defender Suite, Microsoft 365 E5 or Microsoft 365 E7. Those customers must not have an active Microsoft Sentinel workspace. Microsoft's page says that if you have an active Sentinel workspace, you should keep using your existing Sentinel experience. It also says not to disconnect a production Sentinel workspace just to qualify for the preview.
  • Azure subscription: To create an ISOC workspace and use workspace-dependent capabilities, you also need an Azure subscription with the required permissions.
  • Data and cost: Microsoft's page says eligible customers get 30 days of included Defender data retention during this phase. You can bring in more Microsoft and non-Microsoft data through more than 500 connectors, and additional ingestion charges might apply.

This means "E5, E7 and Defender Suite customers" is not the whole story. An E5 shop with a live Sentinel workspace, which is common among mature Microsoft security teams, is excluded from the preview as Microsoft currently describes it.

What needs a workspace​

Microsoft's table of capabilities separates what works without an ISOC workspace from what doesn't.

CapabilityISOC workspace required
Case managementNo
Natural-language playbook generationNo
Enhanced automation rulesNo
WorkbooksNo
UEBAYes
Content hubYes
CI/CD repositoriesYes
Threat intelligenceYes
Azure and third-party security dataYes

Microsoft notes that the table shows workspace requirements in this preview. It doesn't describe licensing or availability in other Microsoft security experiences.

This affects BlueVoyant's scope. Its walkthrough covers UEBA, which needs a workspace. Using that capability means an Azure subscription and potential ingestion costs.

Retention and pricing figures conflict across sources​

BlueVoyant's CISO blog post says Microsoft's datasheet highlights 90 days of included Defender retention and $2.40 per GB for non-Microsoft ingestion. The same post says Defender retention stays at 30 days in Phase 1, with 90 days planned for Phase 2. It also says the $2.40 figure is a U.S. headline rate tied to the ISOC offering, not a universal price for every Sentinel workspace.

I haven't confirmed those datasheet numbers against Microsoft's own materials, so treat them as BlueVoyant's reading. Microsoft Learn currently says 30 days. If your business case assumes 90 days, check which phase you're in.

What to do before engaging a partner​

  1. Check Sentinel status. Confirm whether your tenant has an active Sentinel workspace. If it does, Microsoft says to stay put for now.
  2. Confirm your license. Verify that you hold Defender Suite, E5 or E7 and that the entitlement is active.
  3. Decide which capabilities you need. Cases, workbooks, automation rules and playbook generation don't need a workspace. UEBA, connectors and threat intelligence do.
  4. Estimate ingestion costs. Work out what non-Microsoft data you would bring in and ask Microsoft what it would cost.
  5. Define ownership. For each detection or automation, name an owner, the approved response and the after-hours escalation path. This is Heaton's 2 a.m. question made practical.
  6. Ask about data handling. If you do the export-based assessment, ask what is exported, how it is transferred and how long it is kept.
  7. Clarify the commercial boundaries. Ask what the free assessment covers, what the one-tenant engineering allowance covers, and where paid managed services start.

Assessment​

This is a vendor launch, and the sources behind it are largely BlueVoyant's own. The service description, the quotes and the market claims come from the company. Another WindowsForum report on this launch made the same point, noting that most coverage is the syndicated press release, so the service details come from BlueVoyant itself.

The coverage also contains no customer outcomes, performance figures, service-level commitments or implementation prices. Nothing here shows the service works better than an in-house team or another Microsoft partner.

Heaton's underlying point is still sound. Turning on a Defender feature is a technical event, and running it reliably at 2 a.m. is an operational one. Whether you hire BlueVoyant or do the work yourself, ISOC's convergence of SIEM and XDR won't fix fragmented data, untuned detections or unclear ownership. It will make those problems more visible, and with agents in the loop, more consequential. Settle eligibility and ownership first, then decide whether you need a partner.

 

References

  1. BlueVoyant Launches Microsoft ISOC Deployment Service - channelinsider.com channelinsider.com 2026-10-02T09:12:19+00:00
  2. BlueVoyant Launches Microsoft Defender ISOC Deployment Service bluevoyant.com
  3. Integrated Security Operations Center (ISOC) in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn learn.microsoft.com