BlueVoyant Launches Microsoft ISOC Deployment Service

BlueVoyant launches a Microsoft ISOC deployment service as enterprises prepare SOC environments for AI agents and new managed security demands.

Written By
Luis Millares
Luis Millares
Oct 2, 2026
5 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

BlueVoyant has launched a Microsoft Defender XDR ISOC Deployment Service to help organizations prepare their security operations environments for Microsoft’s push toward more integrated, agent-driven security.

The service is designed for Microsoft 365 E5 and E7 customers and Microsoft Defender Suite users, with a focus on assessing existing deployments, configuring underlying security technologies, and operationalizing detections, workflows, and automation before organizations expand the role of AI agents in the SOC. 

For MSPs and MSSPs, that transition could create new opportunities in Microsoft security optimization, ISOC deployment, and ongoing managed operations as customers determine how to integrate Microsoft tooling with existing third-party security investments.

Operational debt could slow agentic security adoption

Microsoft’s ISOC brings security information and event management (SIEM) and extended detection and response (XDR) together in the Defender portal, creating a shared foundation of signals, context, and controls for security teams and AI agents.

According to BlueVoyant, its new service was designed to help customers assess whether their existing Microsoft security environments are ready for that transition, configure the underlying technologies, and operationalize detections, workflows, and automation.

Speaking with Channel Insider, Micah Heaton, executive director of Microsoft Product and Innovation Strategy at BlueVoyant, said the bigger obstacle to agentic security may not be access to AI itself.

“I think the biggest barrier isn’t the lack of AI; I think it’s operational debt,” Heaton said. 

“Customers already own tremendous security capability, especially Microsoft customers that have already made an investment in one of those enterprise licenses, but the data that they have can be fragmented, detections aren’t always tuned, workflows aren’t consistent, and automation that’s available may never have been operationalized.”

Heaton argued that adding AI agents on top of that environment does not remove underlying problems and can make them more consequential.

“Agentic security turns yesterday’s technical debt into tomorrow’s decision debt,” Heaton said.

Advertisement

Balancing agentic security with human expertise

That issue sits at the center of BlueVoyant’s approach to the ISOC rollout. Microsoft is framing the architecture as a foundation for agentic security operations, but Heaton argued that giving agents more responsibility also increases the importance of the environment underneath them.

He further cautioned against looking at the shift primarily as a replacement for security analysts.

“I don’t see the destination or the foundation as humans versus agents,” he said. “I think humans are still responsible for strategy, risk and accountability. Agents give them scale.”

“The interesting question is not whether an agent can perform a task; I think it’s which decisions we’re comfortably delegating under what conditions and how we verify the outcome,” Heaton continued. “AI can inherit execution foundationally, but humans still own the consequence.”

That becomes especially important as organizations consider giving AI agents wider access to security data and response capabilities.

BlueVoyant builds readiness assessment around Microsoft ISOC

BlueVoyant’s deployment service is designed to help customers put those foundations in place before expanding agents’ roles within the SOC.

Customers and prospects can begin with the company’s no-cost ISOC Readiness Assessment, which evaluates what is already deployed, where capabilities remain fragmented, and what a customer would need for a scoped ISOC deployment.

The deployment support includes:

  • Defender deployment and configuration across Endpoint, Identity, Office 365, Cloud Apps, and Entra ID Identity Protection
  • Walkthroughs of ISOC custom detections, workbooks, automation, and user and entity behavior analytics (UEBA)
  • Use-case engineering to develop and refine detection rules, workbooks and automations

Heaton said the readiness process also examines license levels and how responsibilities are divided among security operations, infrastructure, networking, cloud operations, and other teams.

Advertisement

“If you’re somewhere along your Microsoft adoption journey, the answer is going to be yes,” he said. “I’ve got some Legos, right? Tell me what I can do with the Legos I have and tell me what these ISOC advancements actually mean for us.”

BlueVoyant does not require direct access to a customer’s environment during the assessment, according to Heaton. Instead, customers can export data and snapshots that the company uses to help identify potential engineering use cases.

“The only way, in my opinion, to get to real use cases and produce genuine outcomes, real security outcomes for the humans in the trenches, is for it to be a data-driven exercise in science,” Heaton said.

For Heaton, that is also the difference between simply turning on a capability and actually embedding it into security operations.

“Activation is a technical event, adoption is an operational outcome, and the no-cost readiness assessment is the exercise that lets us prove that out, start to finish,” Heaton said.

Integrated security does not mean Microsoft-only

While ISOC is built around Microsoft’s security stack, Heaton said customers should not view integration as requiring an exclusively Microsoft environment.

“I don’t think that integrated has to mean exclusively Microsoft,” Heaton said. “I think the question is whether you can bring the relevant signals and context together and create a coherent investigation and response, regardless of the tools that you have.”

“Customers should start with what they already own and expand where additional context materially improves an outcome.”

That framing also carries into the partner opportunity, particularly for MSPs and MSSPs helping customers balance Microsoft investments with existing third-party tools.

Advertisement

Microsoft ISOC creates new roles for MSPs and MSSPs

When asked what new service opportunities ISOC could create for MSPs and MSSPs managing Microsoft environments, Heaton pointed to a broader role across deployment and ongoing managed security operations.

He also noted that customer environments still vary widely across licenses, configurations, integrations, and third-party tools.

“There is the deployment opportunity: how do I maximize and optimize my Microsoft investment around integrated SOC or ISOC, but also what does it look like for us to manage these tools 24-7, 365 days a year?” Heaton said.

Heaton emphasized BlueVoyant’s experience on both sides of that equation, from deploying Microsoft security environments to operating them for customers with different licenses, configurations, and third-party tools. 

He said that perspective helps the company advise customers on how much of the Microsoft stack to use and where incumbent non-Microsoft tools should remain part of the security strategy.

“When we’re designing a detection or automation, we’re not just asking, can we deploy it? Can we turn it on for you?” Heaton said. “We’re asking what happens at 2 a.m. when there’s fires? Who owns it? And what should happen next?”

Heaton said Microsoft’s effort to remove platform friction could push partners toward more outcome-focused services.

“A partner’s value shouldn’t depend on a customer’s environment staying complicated,” he said. “The opportunity moves from maintaining complexity to creating capability.”

“If Microsoft makes the technology easier to use, good partners don’t become less relevant; they become more accountable for outcomes.”

The XDR ISOC Deployment Service is now available, with implementation tied to customer eligibility, agreed-upon scope, and Microsoft’s phased rollout.

Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.