{"id":25482,"date":"2019-02-21T19:00:17","date_gmt":"2019-02-21T19:00:17","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/"},"modified":"2019-02-21T19:00:17","modified_gmt":"2019-02-21T19:00:17","slug":"lessons-learned-from-the-microsoft-soc-part-1-organization","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/","title":{"rendered":"Lessons learned from the Microsoft SOC\u2014Part 1: Organization"},"content":{"rendered":"<p>We\u2019re frequently asked how we operate our Security Operations Center (SOC) at Microsoft (particularly as organizations are integrating cloud into their enterprise estate). This is the first in a three part blog series designed to share our approach and experience, so you can use what we learned to improve your SOC.<\/p>\n<p>In Part 1: Organization, we start with the critical organizational aspects (organizational purpose, culture, and metrics). In Part 2: People, we cover how we manage our most valuable resource\u2014human talent. And finally Part 3: Technology, covers the technology that enables these people to accomplish their mission.<\/p>\n<h3>Overall SOC model<\/h3>\n<p>Microsoft has multiple security operations teams that each have specialized knowledge to protect the different technical environments at Microsoft. We use a \u201cfusion center\u201d model with a shared operating floor, which we call our <a target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/msrc\/cdoc\" rel=\"noopener\">Cyber Defense Operations Center (CDOC)<\/a>, to increase collaboration and facilitate rapid communication among these teams. Each team manages to the specific needs of their environment.<\/p>\n<p>In this three part series, we focus on the operation of our corporate IT SOC team as they most closely reflect the challenges and approaches of our customers\u2014having many users and endpoints, email attack vectors, and a hybrid of on-premises and cloud assets. In addition, we include a few lessons learned from the other SOCs and our Detection and Response Team (DART) that helps our customers respond to major incidents.<\/p>\n<p>This SOC operates with three tiers of analysts plus automation as seen in Figure 1 below. (We\u2019ll provide more details in Part 2: People.)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-88636 size-full\" src=\"https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1.png\" alt=\"Figure 1. SOC analyst tiers plus automation.\" width=\"1640\" height=\"564\" srcset=\"https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1.png 1640w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1-300x103.png 300w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1-768x264.png 768w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1-1024x352.png 1024w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1-330x113.png 330w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1-800x275.png 800w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-1-400x138.png 400w\" sizes=\"auto, (max-width: 1640px) 100vw, 1640px\"\/><\/p>\n<p><em>Figure 1. SOC analyst tiers plus automation.<\/em><\/p>\n<p>The tooling in the SOC (Figure 2) is a mixture of centralized breadth capabilities and specialized tools to enable high quality alerts and an end-to-end investigation and remediation experience. (Part 3: Technology will provide more details.)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-88639 alignleft\" src=\"https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2.png\" alt=\"Figure 2. SOC tooling.\" width=\"1511\" height=\"859\" srcset=\"https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2.png 1511w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2-300x171.png 300w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2-768x437.png 768w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2-1024x582.png 1024w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2-330x188.png 330w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2-800x455.png 800w, https:\/\/cloudblogs.microsoft.com\/uploads\/prod\/sites\/13\/2019\/02\/Part-1-Lessons-learned-from-the-Microsoft-SOC-2-400x227.png 400w\" sizes=\"auto, (max-width: 1511px) 100vw, 1511px\"\/><\/p>\n<p><em>Figure 2. SOC tooling.<\/em><\/p>\n<p>Like all things in security, our SOC has evolved considerably over the years to its current state and will continue to evolve. We recently noticed that our SOC had sustained a 100+ percent growth in incidents handled over the past three years with a nearly flat staffing level. While we don\u2019t know if we can expect this astounding trend to continue in the future, it validates that we are on the right track and should share our learnings.<\/p>\n<h2>SOC organizational purpose<\/h2>\n<p>The first element we cover is the value of the SOC in the context of the overall mission and risk of the organization. Like the traditional incarnations of crime and espionage, we don\u2019t expect there will be a straightforward \u201csolution\u201d to cyberattacks. A SOC is often a crucial risk mitigation investment for an enterprise as it is core to limiting how much time and access attackers have in the organization. This ultimately increases the attacker\u2019s cost and decreases the benefit, which damages their return on investment (ROI) and motivation for attacking your organization. Everything in the SOC should be oriented toward limiting the time and access attackers can gain to the organization\u2019s assets in an attack to mitigate business risk.<\/p>\n<p>At Microsoft, our SOCs bear not just the responsibility of reducing risk to our employees and investors, but also the weight of the trust that millions of customers accessing our cloud services and products put in us.<\/p>\n<p>We\u2019ve learned that the SOC has four primary functional integration points with the business:<\/p>\n<ul>\n<li><strong>Business context (to the SOC)<\/strong>\u2014The SOC needs to understand what is most important to the organization so the team can apply that context to fluid real-time security situations. What would have the most negative impact on the business? Downtime of critical systems? A loss of reputation and customer trust? Disclosure of sensitive data? Tampering with critical data or systems? We\u2019ve learned it\u2019s critical that key leaders and staff in the SOC understand this context as they wade through the continuous flood of information and triage incidents and prioritize their time, attention, and effort.<\/li>\n<li><strong>Joint practice exercises (with the SOC)<\/strong>\u2014Business leaders should regularly join the SOC in practicing response to major incidents. This builds the muscle memory and relationships that are critical to fast and effective decision making in the high pressure of real incidents, reducing organizational risk. This practice also reduces risk by exposing gaps and assumptions in the process that can be fixed prior to a real incident.<\/li>\n<li><strong>Major incidents updates (from the SOC)<\/strong>\u2014The SOC should provide updates to business stakeholders for major incidents as they happen. This allows business leaders to understand their risk and take both proactive and reactive steps to manage that risk. For more learnings on major incidents by our DART team, see the <a target=\"_blank\" href=\"https:\/\/aka.ms\/irrg\" rel=\"noopener\">incident response reference guide<\/a>.<\/li>\n<li><strong>Business intelligence (from the SOC)<\/strong>\u2014Sometimes the SOC finds that adversaries are targeting a system or data set that isn\u2019t expected. As the SOC discovers the targets of attacks, they should share these with business leaders as these signals may trigger insight for business leaders (outside awareness of a secret business initiative, relative value of an overlooked data set, etc.).<\/li>\n<\/ul>\n<h2>SOC culture<\/h2>\n<p>If you take one thing away from this post, it\u2019s that the SOC culture is just as important as the individuals you hire and the tools you use. Culture guides countless decisions each day by establishing what the right answer looks and feels like in ambiguous situations, which are plentiful in a SOC.<\/p>\n<p>Our cultural elements are very much focused on people, teamwork, and continuous learning and include these learnings:<\/p>\n<ul>\n<li><strong>Use your human talent wisely<\/strong>\u2014Our people are the most valuable asset we have in the SOC and we can\u2019t afford to waste their time on repetitive thoughtless tasks that can be automated. To combat the human threats we face, we need knowledgeable and well-equipped humans that can apply expertise, judgement, and creative thinking. This human factor affects almost every aspect of SOC operations including the role of tools and automation to empower humans to do more (versus replacing them) and in <em>reducing toil<\/em> on our analysts. (More on this topic in Part 2: People.)<\/li>\n<li><strong>Teamwork<\/strong>\u2014We\u2019ve learned that we can\u2019t tolerate the \u201clone hero\u201d mindset in the SOC, nobody is as smart as all of us together. Teamwork makes a high-pressure working environment like the SOC much more fun, enjoyable, and productive when everyone knows they\u2019re on the same team and everyone has each other\u2019s back. We design our processes and tools to divide up tasks into specialties and to encourage people to share insights, coordinate and check each other\u2019s work, and constantly learn from each other.<\/li>\n<li><strong>Shift left mindset<\/strong>\u2014To get and stay ahead of cybercriminals and hackers who constantly evolve their techniques, we must continuously improve and shift our activities \u201cleft\u201d in the attack timeline. We focus on speed and efficiency to try and get \u201cfaster than the speed of attack\u201d by looking at ways we could have detected attacks earlier and responded more quickly. This principle is effectively an application of a continuous learning \u201cgrowth mindset\u201d that keeps the team laser focused on reducing risk for our organization and our customers.<\/li>\n<\/ul>\n<h2>SOC metrics<\/h2>\n<p>The final organizational element is how we measure success, a critical element to get right. Metrics translate culture into clear measurable objectives and have a powerful influence on shaping people\u2019s behavior. We\u2019ve learned that it\u2019s critical to consider both what you measure, as well as the way that you focus on and enforce those metrics. We measure several indicators of success in the SOC, but we always recognize that the SOC\u2019s job is to manage significant variables that are out of our direct control (attacks, attackers, etc.). We view deviations primarily as a learning opportunity for process or tool improvement rather than a failing on the part of the SOC to meet a goal.<\/p>\n<p>These are the metrics we track, trend, and report on:<\/p>\n<ul>\n<li><strong>Time to acknowledge (TTA)<\/strong>\u2014Responsiveness is one of the few elements the SOC has direct control over. We measure the time between an alert being raised (\u201clight starts to blink\u201d) and when an analyst acknowledges that alert and begins the investigation. Improving this responsiveness requires that analysts don\u2019t waste time investigating false positives while another true positive alert sits waiting. We achieve this with ruthless prioritization. Any alert that requires an analyst response must have a track record of 90 percent true positive. We\u2019ll talk more about the technology we use in Part 3: Technology and will describe our use of \u201ccold path\u201d activities like proactive hunting to supplement the \u201chot path\u201d of alerts in Part 2: People.<\/li>\n<li><strong>Time to remediate<\/strong> <strong>(TTR)<\/strong>\u2014Much like many SOCs, we track the time to remediate\u00a0an incident to ensure we\u2019re limiting the time attackers have access to our environment, which drive effectiveness and efficiencies in our SOC processes and tools.<\/li>\n<li><strong>Incidents remediated (manually\/with automation)<\/strong>\u2014We measure how many incidents are remediated manually and how many are resolved with automation. This ensures our staffing levels are appropriate and measures the effectiveness of our automation technology.<\/li>\n<li><strong>Escalations between each tier<\/strong>\u2014We track how many incidents escalated between tiers to ensure we accurately capture the workload for each tier. For example, we need to ensure that Tier 1 work on an escalated incident isn\u2019t fully attributed to Tier 2.<\/li>\n<\/ul>\n<h2>Get started<\/h2>\n<p>Our biggest recommendation for the SOC organization is to define the culture you want to inculcate. This will shape your team and attract the talent you want. In the coming weeks, we\u2019ll share our philosophy on managing people, career paths, skills, and readiness, and what tools we use to enable our people to accomplish their mission.\u00a0 In the meantime, head over to <a target=\"_blank\" href=\"https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/?content-type=ciso-series\" rel=\"noopener\">CISO series<\/a>\u00a0to learn more.<\/p>\n<p>READ MORE <a href=\"https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/2019\/02\/21\/lessons-learned-from-the-microsoft-soc-part-1-organization\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the first of our three part series, we provide tips on how to manage a security operations center (SOC) to be more responsive, effective, and collaborative.<br \/>\nThe post Lessons learned from the Microsoft SOC\u2014Part 1: Organization appeared first on Microsoft Secure. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":25483,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347],"class_list":["post-25482","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Lessons learned from the Microsoft SOC\u2014Part 1: Organization 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lessons learned from the Microsoft SOC\u2014Part 1: Organization 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-02-21T19:00:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/lessons-learned-from-the-microsoft-soc-part-1-organization.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1640\" \/>\n\t<meta property=\"og:image:height\" content=\"564\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Lessons learned from the Microsoft SOC\u2014Part 1: Organization\",\"datePublished\":\"2019-02-21T19:00:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/\"},\"wordCount\":1617,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/lessons-learned-from-the-microsoft-soc-part-1-organization.png\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/\",\"name\":\"Lessons learned from the Microsoft SOC\u2014Part 1: Organization 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/lessons-learned-from-the-microsoft-soc-part-1-organization.png\",\"datePublished\":\"2019-02-21T19:00:17+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/lessons-learned-from-the-microsoft-soc-part-1-organization.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/02\\\/lessons-learned-from-the-microsoft-soc-part-1-organization.png\",\"width\":1640,\"height\":564},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/lessons-learned-from-the-microsoft-soc-part-1-organization\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Lessons learned from the Microsoft SOC\u2014Part 1: Organization\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Lessons learned from the Microsoft SOC\u2014Part 1: Organization 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/","og_locale":"en_US","og_type":"article","og_title":"Lessons learned from the Microsoft SOC\u2014Part 1: Organization 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-02-21T19:00:17+00:00","og_image":[{"width":1640,"height":564,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/lessons-learned-from-the-microsoft-soc-part-1-organization.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Lessons learned from the Microsoft SOC\u2014Part 1: Organization","datePublished":"2019-02-21T19:00:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/"},"wordCount":1617,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/lessons-learned-from-the-microsoft-soc-part-1-organization.png","keywords":["Cybersecurity"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/","url":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/","name":"Lessons learned from the Microsoft SOC\u2014Part 1: Organization 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/lessons-learned-from-the-microsoft-soc-part-1-organization.png","datePublished":"2019-02-21T19:00:17+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/lessons-learned-from-the-microsoft-soc-part-1-organization.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/02\/lessons-learned-from-the-microsoft-soc-part-1-organization.png","width":1640,"height":564},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/lessons-learned-from-the-microsoft-soc-part-1-organization\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"Lessons learned from the Microsoft SOC\u2014Part 1: Organization"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/25482","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=25482"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/25482\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/25483"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=25482"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=25482"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=25482"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}