BlueVoyant's Defender XDR ISOC Deployment Service Follows Microsoft's Preview Launch
BlueVoyant calls the offering one of the first deployment solutions on the market built to help enterprises adopt the newly announced ISOC in Microsoft Defender. The announcement came the same day Microsoft revealed ISOC on its Security Blog. SecurityBrief Australia covered it the following day. Most other coverage so far is the PR Newswire release syndicated on finance sites, so the service details come from BlueVoyant itself. Microsoft's own documentation supplies the product facts.
BlueVoyant ties its launch timing closely to Microsoft's. The company says the service is available now, with implementation aligned to customer eligibility, agreed scope and Microsoft's phased rollout. In practice, the partner can start talking to you today. What it can actually deploy depends on whether Microsoft's preview is open to your tenant.
SecurityBrief framed the launch around a familiar complaint. The service is aimed at a common problem for large organisations that already hold broad Microsoft security licences but have not fully deployed the tools included in those subscriptions. The publication added that many enterprises in Australia and New Zealand, as well as other markets, are only using part of what they already pay for. That claim comes from SecurityBrief's framing, not from published usage data.
What ISOC in Microsoft Defender Changes for SIEM and XDR Teams
ISOC brings together two tool categories that many security teams still run separately. SIEM (security information and event management) collects and correlates logs from across an environment. XDR (extended detection and response) handles detection and response across endpoints, identities, email and cloud apps. In BlueVoyant's words, ISOC in Microsoft Defender brings SIEM and XDR together in the Defender portal, providing a shared foundation of signals, context and controls for security teams and AI agents.
Rob Lefferts, Microsoft's corporate vice president for threat protection, announced ISOC as a foundation for what Microsoft calls agentic security. In this model, AI agents and human analysts work from the same telemetry, context and response controls. Microsoft says the tools practitioners need to investigate, hunt, automate, manage incidents and respond are available by default. It also says people still set priorities and apply judgment while agents provide speed and scale. The announcement links ISOC to Project Perception, which Microsoft introduced in July 2026. Microsoft Learn describes security teams and "Perception agents" working from a common set of signals and workflows.
Microsoft's product documentation carries the key qualifier: ISOC is in preview, and capabilities and availability may change during the preview period. That affects any partner engagement. A deployment designed around this month's feature set may need adjusting before general availability.
Microsoft Learn also says ISOC delivers SIEM capabilities "out of the box" in Defender, with no traditional SIEM deployment needed as a starting point. That is the pitch to E5 customers who never bought or built a separate SIEM. They get SIEM-style case management and workbooks inside a portal they already have.
The Microsoft Sentinel Workspace Rule That Decides ISOC Eligibility
Having the right licence does not make you eligible. Microsoft Learn states that in this phase of the preview, ISOC is available to eligible customers with Microsoft Defender Suite, Microsoft 365 E5 or Microsoft 365 E7 that don't have an active Microsoft Sentinel workspace.
Microsoft also says what Sentinel customers should do. Organisations with an active Sentinel workspace should keep using their existing Sentinel experience during this phase. Microsoft explicitly warns against disconnecting a production Sentinel workspace just to qualify for the ISOC preview.
This limits who BlueVoyant's service can help right now. The company's marketing points to its history with Sentinel, and its existing deployment services page promises to deploy and optimize Microsoft Sentinel with expert guidance tailored to your complex needs. Under Microsoft's current rules, though, an established Sentinel customer is exactly the kind of organisation that cannot join the ISOC preview yet. For those tenants, an "ISOC readiness" conversation today is about planning, not deployment.
The preview seems aimed at E5-licensed organisations that never set up Sentinel. Those tenants have Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud Apps data but no SIEM layer. BlueVoyant's deployment scope, which starts with configuring those Defender workloads, fits that profile.
Where UEBA, Threat Intelligence and Third-Party Data Need an ISOC Workspace
Microsoft Learn splits ISOC into two tiers. Some capabilities work straight away inside Defender. Others need an ISOC workspace, which requires an Azure subscription with the right permissions. The table below lists the workspace requirement for each capability during the preview.
| Capability | ISOC workspace required |
|---|---|
| Case management | No |
| Natural-language playbook generation | No |
| Enhanced automation rules | No |
| Workbooks | No |
| User and Entity Behavior Analytics (UEBA) | Yes |
| Content hub | Yes |
| CI/CD (content as code from a repository) | Yes |
| Threat intelligence | Yes |
| Azure and third-party security data | Yes |
Microsoft notes that the table only shows workspace requirements within this preview. It does not describe licensing or availability of the same features in other Microsoft security products.
The split matters when you read BlueVoyant's scope. The press release promises walkthroughs of ISOC custom detections, workbooks, automation and UEBA. Workbooks and automation rules work without a workspace. UEBA does not. A customer who wants the behaviour analytics part of the engagement needs to provision the Azure side first, with a subscription and permissions in place.
Data costs are the other workspace consideration. Microsoft says eligible customers get 30 days of included retention for Defender data during this phase of the preview. Beyond that, organisations can add Microsoft and non-Microsoft data through more than 500 connectors. Microsoft warns that additional ingestion charges may apply depending on what is ingested. Nothing in BlueVoyant's announcement says the service covers or reduces those charges.
Heaton's comment that cost pressure should not decide which evidence an analyst gets to see fits here. The 30-day included retention removes part of the cost problem for Defender data. For anything outside Defender, including firewall logs, other cloud providers and third-party SaaS, the usual SIEM trade-off between coverage and ingestion cost still applies.
What BlueVoyant's ISOC Readiness Assessment Covers, and What It Leaves Unpriced
The engagement has two stages. Current customers and prospects can request the no-cost ISOC Readiness Assessment Security Diagnostic. BlueVoyant describes this as a starting point to discuss the organisation's environment and prepare for scoped deployment support. The scoped deployment then covers three areas, according to the press release:
- BlueVoyant deploys and configures Defender across Endpoint, Identity, Office 365, Cloud Apps and Entra ID Identity Protection.
- BlueVoyant walks customers through ISOC custom detections, workbooks, automation and UEBA.
- BlueVoyant does use-case engineering to develop and refine detection rules, workbooks and automations.
SecurityBrief describes the offer as focused on that implementation gap, with a defined assessment phase before scoped deployment begins. The announcement gives no prices for the deployment stage. It also gives no engagement length, contract terms or a standard list of deliverables. Only the assessment is described as free. Deployment and the managed services BlueVoyant mentions should be treated as commercial work until a quote says otherwise.
BlueVoyant says it supports more than 2,500 customer deployments in Microsoft-native environments worldwide. That figure is self-reported and covers its Microsoft work in general, not ISOC installations, which could not have existed at scale before this week. The company already runs related services. In 2025, MSSP Alert reported a BlueVoyant optimisation service for Microsoft security tools in which each customer is assigned a dedicated Microsoft Security Architect who acts as a Technical Account Manager. The ISOC service builds on that existing Microsoft practice.
Microsoft's backing is on the record. The press release quotes Naseem Tuffaha, corporate vice president of customer value creation at Microsoft, saying partners like BlueVoyant play a critical role in helping customers bring these capabilities together, operationalize them in their environments. One trade outlet, IT Digest, attributed that quote to Rob Lefferts. BlueVoyant's own release and SecurityBrief both name Tuffaha. The quote is standard partner endorsement and does not describe a formal certification programme for ISOC deployment.
Deciding Whether an ISOC Partner Engagement Fits Your Tenant
The first step does not involve BlueVoyant. Check whether your tenant is eligible for the ISOC preview. The answer depends on your licence and on whether you run an active Sentinel workspace. If you do run Sentinel, Microsoft's instruction is to stay on it, and a deployment engagement can wait until Microsoft widens eligibility.
For eligible E5, E7 or Defender Suite tenants without Sentinel, the free assessment costs nothing but time. It is most useful if you arrive with your own answers to the questions ISOC leaves open. Which non-Defender data sources do you actually need? How long must you keep them? Do you have an Azure subscription ready for workspace features? Which response actions are you willing to automate? SecurityBrief made the same point: a unified portal is also configuring products, linking telemetry sources and deciding how detections and automated actions should run in practice.
Microsoft's model keeps humans in charge of priorities and judgment. Neither Microsoft nor BlueVoyant publishes a checklist for approving or limiting agent-driven actions. Setting those authorisation boundaries is your job, whoever runs the deployment.
- Confirm eligibility against Microsoft's current ISOC preview rules before booking any engagement, because licensing alone does not qualify a tenant that has an active Sentinel workspace.
- Do not disconnect a production Microsoft Sentinel workspace to get into the ISOC preview, which Microsoft explicitly warns against.
- Budget for an Azure subscription and the right permissions if you want UEBA, threat intelligence, Content hub, CI/CD or third-party data, since all of these need an ISOC workspace.
- Model ingestion costs for any data beyond Defender telemetry, because the included 30-day retention covers Defender data only and extra ingestion may be billed.
- Treat BlueVoyant's assessment as free and the deployment and managed services as scoped commercial work, because no pricing has been published.
- Expect preview features and eligibility rules to change, and ask any partner how their deployment will adapt when Microsoft updates ISOC.
BlueVoyant's launch shows that partners see Microsoft's SIEM-in-Defender strategy as a services opportunity, and it offers a sensible path for E5 tenants that have never deployed a SIEM. The service is only as broad as the ISOC preview, which currently excludes Sentinel customers. The dates to watch are Microsoft's announcements on when active Sentinel workspaces can move into ISOC and when the preview reaches general availability. Those decide how many organisations can actually use partner deployment services like this one. BlueVoyant's September 29 webinar on preparing for ISOC is the next public event on its calendar.