Microsoft Customers E5 and E7 will receive ISOC economic assessment results based on their respective tenant circumstances. In addition, they will also obtain 7 MXDR365 agents and operation manuals to support their round-the-clock operations.
Irvine, California, September 30, 2026 / PRNewswire / -- Patriot Consulting, which holds the qualification to be a Microsoft Security Solutions Partner and possesses Microsoft-certified hosting for XDR solutions, today announced the launch of a free ISOC cost assessment service for Microsoft organizations that have adopted Microsoft Defender's recently released Integrated Security Operations Center ( ISOC ) within their E5 and E7 environments. ISOC will integrate these capabilities into the Microsoft Defender portal as part of the benefits offered with Microsoft 365 E5 and E7. This includes providing 90 days of Defender data retention starting from November 15, 2026, as well as charging $2.40 per GB for non-Microsoft data starting from October 1, 2026.
This is a right, not a product: Why cost estimation is so important
In his analysis article "Microsoft Defender's ISOC: Not a new product, but a new E5 and E7 entitlement," Patriot explains that whether ISOC can reduce costs depends on the specific tenants. The new billing standard is 44% lower than the previous pay-as-you-go rate of $4.30 per GB. Existing Sentinel customers can choose to join from November 15, 2026, but by doing so, they will give up the current entitlement of up to 5 MB free data ingestion per user per day; however, organizations that have already implemented high-capacity log tiered storage in Sentinel data lakes may already have achieved optimization.
ISOC Cost assessment will compare the license status, log volume of each organization, as well as the relationship between the current tiering strategy and the pricing for retention and ingestion in ISOC. Subsequently, recommendations based on the actual circumstances of each tenant will be provided.
President Rick Cox stated: "We are very pleased to announce the launch of a free ISOC assessment. We will conduct cost estimations and provide expert guidance on the fastest deployment path. We guarantee to provide a quote within 24 hours, and we can usually utilize Microsoft's financial support and discounts to offset our consulting fees."
Agentic MXDR365 operation running on ISOC
The MXDR365 24x7 managed detection and response service of Patriot operates on top of Microsoft Defender XDR and Microsoft Sentinel. It includes proprietary proxies and automated operation manuals, and is designed to utilize the signals and context shared by ISOC.
- MXDR365 Vanguard: Threat intelligence agent that collects public threat intelligence data streams from dozens of sources.
- MXDR365 Overwatch: Threat hunting agent, undertaking the output of Vanguard and constructing targeted threat hunting tasks.
- MXDR365 Hindsight: The log ingestion delay detection proxy will rerun the detection rules within the time gap caused by the ingestion delay.
- MXDR365 Sentry: In-depth analysis agents, before determining the authenticity of an event, will conduct multi-hub investigations, historical reviews, and adversarial verifications of their own conclusions. This approach covers a wider range and reduces noise.
- MXDR365 Automated Identity Triage: A deterministic automated operation manual that can extract third-party open-source intelligence related to relevant compromise indicators, compare it with historical data, and complete automated identity restoration in about one minute.
- MXDR365 Phishing Triage Agent: Check if there are signs of user interaction in the phishing emails reported by users, and then perform automated repairs.
- MXDR365 Minuteman: Local AI proxy, designed to prevent front-line models from refusing to respond. For more information, see "You have the right to a local LLM for self-defense."
Patriot Consulting, the vice president in charge of MXDR365's business, stated: "ISOC allows analysts and agents to work at the same location based on the same signals and context, and that's precisely where our agents can be most effective. Vanguard and Overwatch transform the latest intelligence into targeted hunting actions, Hindsight fill in the gaps in information collection, while Sentry will challenge their own conclusions before escalating any situation."
In Microsoft's announcement on September 23, Rob Lefferts, Vice President of Threat Protection for Enterprises at Microsoft, wrote: "Security operations and native protection must work together as a system."
Beyond SOC
Patriot indicates that it will pair MXDR365 with three other services to enhance the value of ISOC.
- SecureShield365: The proactive security configuration reinforcement service of Patriot transforms the lessons learned from the SOC investigation into a more robust Microsoft Defender XDR configuration.
- AIShield365 : The latest solution from Patriot aims to reduce risks through AI.
- Patriot Academy Premium: Provides real-time instructor-led training on the latest best practices for Microsoft Defender XDR and Sentinel.
Service Availability
The ISOC cost assessment for Patriot is now available and is freely accessible to Microsoft, E5, and E7 organizations (including any organization that wishes to understand whether upgrading to E5 or E7 will result in cost-effectiveness due to the benefits of ISOC). As mentioned in the original text, you can click on the link to apply for the ISOC cost assessment.
About Patriot Consulting
Patriot Consulting Technology Group indicates that it is one of Microsoft's top security partners in the United States. The company claims to assist an average of 4 million users in deploying Microsoft security technologies each year. Focusing on the secure deployment of Microsoft cloud technologies, the company emphasizes knowledge transfer, which enables its customers to have more confidence in their own security and their investments on the Microsoft platform.









