IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
BlueVoyant launches Microsoft Defender XDR ISOC service

BlueVoyant launches Microsoft Defender XDR ISOC service

Thu, 24th Sep 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

BlueVoyant has launched a Microsoft Defender XDR ISOC Deployment Service for organisations adopting Microsoft's Integrated Security Operations Centre in Defender. The offer targets customers using Microsoft 365 E5, E7 and the Microsoft Defender Suite.

The service begins with a no-cost ISOC readiness assessment, followed by deployment across endpoint, identity, Office 365, cloud apps and Entra ID identity protection. It also covers detection engineering, automation, walkthroughs for custom detections and workbooks, and support for user and entity behaviour analytics.

The launch comes as Microsoft brings security information and event management together with extended detection and response in the Defender portal. The shift gives security teams a single environment for signals, context and controls, and reflects Microsoft's push to support AI agents in security operations.

It is aimed at a common problem for large organisations that already hold broad Microsoft security licences but have not fully deployed the tools included in those subscriptions. Many enterprises in Australia and New Zealand, as well as other markets, are only using part of what they already pay for.

Micah Heaton, Executive Director of Microsoft Product and Innovation Strategy at BlueVoyant, said customers often struggle to turn licensed software into day-to-day operational use.

"The pattern we see most often is a gap between the security technology customers own and what they can actually put to work," Heaton said. "ISOC helps close that gap by bringing security data, context and response workflows together in Microsoft Defender. The economics matter too. Cost pressure should not decide which evidence an analyst gets to see. Our role is to help customers assess readiness, activate the capabilities that matter and put them to work through deployment and managed services. That gives customers a practical foundation for adopting agents with the right context and controls."

Broader shift

The product reflects a wider shift in security operations as suppliers and service providers adapt tools for AI systems to work alongside human analysts. In Microsoft's model, ISOC is designed to create a shared operational base for analysts and software agents working from the same security data and response processes.

For customers, that means the challenge is no longer just buying software. It is also configuring products, linking telemetry sources and deciding how detections and automated actions should run in practice. BlueVoyant's service is positioned around that implementation gap, with a defined assessment phase before scoped deployment begins.

The service builds on BlueVoyant's work as a Microsoft security partner and extends its coverage across the main parts of Microsoft's security portfolio, including Sentinel, Defender, Entra and Purview. The company also supports more than 2,500 customer deployments in Microsoft-native environments worldwide.

Microsoft said partners will play an important role as customers try to operationalise the new model in their own environments.

"ISOC in Microsoft Defender represents an important evolution in how organizations defend against modern threats," said Naseem Tuffaha, Corporate Vice President of Customer Value Creation at Microsoft. "Our security partners like BlueVoyant play a critical role in helping customers bring these capabilities together, operationalize them in their environments, and turn Microsoft's security innovation into meaningful outcomes. ISOC is built for agentic security, and the combination of technology and operational experience will be essential to helping customers realize its full value."

Deployment focus

BlueVoyant's offer centres on practical setup and operational design rather than software resale. The deployment scope includes Defender configuration for endpoints and identities, Office 365 integration, cloud app coverage and identity protection in Entra ID, along with detection rules, workbooks and automations tied to customer use cases.

That work has become more important as security teams try to consolidate tools and cut duplication in monitoring and response. Bringing SIEM and XDR together in a single Microsoft interface may reduce some operational friction, but organisations still need to decide how incidents are triaged, what data is retained and which actions can be automated safely.

BlueVoyant Chief Executive Officer John Hernandez said customers need support that extends beyond initial deployment.

"We're proud to be one of the first Microsoft partners to help customers deploy Microsoft's new integrated security operations center," Hernandez said. "ISOC gives customers an opportunity to improve how they run security operations and prepare for teams and AI agents to work from shared data and context. Customers need a practical path from deployment to day-to-day operations, which is exactly where BlueVoyant's expertise comes in - we don't just help stand it up, we help run it."