ThreatDefender | Microsoft ISOC Readiness Assessment
Is your organization ready for Microsoft ISOC?
A free, automated, read-only review of your Microsoft 365 tenant. See whether you qualify for Microsoft's Integrated SOC in Defender, what it means for your Microsoft Sentinel costs, and which Defender gaps to close first.
- Read-only
- No content accessed
- Report in minutes
- No standing access
What your report covers
A clear answer, backed by your own data
Your branded PDF report is built from a live read of your tenant, not a questionnaire. It gives eGroup's recommendation and the evidence behind it.
Eligibility verdict
Whether your licensing qualifies for ISOC today, after November 15, or not yet, and what to do in each case.
Readiness score
Scores across licensing, Defender deployment, security configuration, data, detections and operations.
Gaps to close
Defender coverage and configuration gaps, Secure Score opportunities and exposure, ranked by impact.
Sentinel cost view
If you run Microsoft Sentinel, today's ingestion cost compared with ISOC, from your real volumes.
How it works
Three steps, a few minutes
There is nothing to install and no questionnaire to fill in.
Sign in and approve
Sign in with your Microsoft work account and approve read-only access.
We read, you watch
We read licensing, Defender and Sentinel configuration: counts and settings only. Progress shows live.
Get your report
Download your branded PDF straight away, and receive a copy by email.
Your data, your control
Read-only by design
- Delegated accessThe assessment uses your own account's permissions and cannot change anything in your environment.
- No standing accessAccess is used only while your assessment runs and is not retained afterwards.
- No contentWe read counts and configuration, never email, file or log content.
- Remove any timeYou can remove the app at any time: Microsoft Entra admin center > Enterprise applications > "ThreatDefender ISOC Readiness Assessment" > Properties > Delete.
Start your assessment
Ready when you are
A Global Administrator can approve and run it in one step. Otherwise, send the approval page to your administrator first, then run it with Global Reader or Security Reader, plus Azure Reader to include Microsoft Sentinel.