AI-Powered, Human Controlled: The SOC Is Evolving

11 min read
Sep 25, 2026, 1:12:21 PM

Summary

Round-the-clock threat detection has traditionally required countless hours of billable engineering time or outsourced SOCs that are costly and slow to respond. inforcer TDR lets MSPs offer an alternative that leverages AI for detection, analysis and automatic containment of major threats, while humans train and validate the technology. MSPs can also push fixes to every tenant that needs them through inforcer’s 365 Manager and generate customer-facing reports, effectively creating a cost-effective alternative to SOCs.

Time to read

~9 minutes

What you'll learn

  • What a SOC does and how the model is evolving
  • Why round-the-clock detection is hard to deliver manually
  • Where automation-only tools and outsourced SOCs fall short
  • How MSPs use inforcer TDR to offer their customers an alternative to a traditional SOC

Next steps

  • Explore inforcer TDR
  • Offer your customers a cost-efficient alternative to traditional SOCs

Versioned Specifics:

  • Original publication date: 25th September 2026
  • Key problems addressed: the cost and response time of outsourced SOCs; alert noise from automation-only tools; the staffing needed to deliver 24/7 detection manually; third parties sitting between MSPs and their customers
  • Relevant inforcer solutions: inforcer TDR for detection, containment and customer reporting; 365 Manager for pushing fixes and configuration updates to every managed tenant

AI-Powered, Human Controlled: How The Modern SOC Is Evolving

Every business running on Microsoft 365 needs someone watching for attacks, including at 2am on a Sunday. For years, the standard way to get that coverage was a managed security operations centre (SOC): a third-party team of analysts monitoring alerts around the clock and acting on the threats they discovered.

But that model is changing. Pairing AI features with expert human oversight makes it possible to offer round-the-clock detection and response, without the cost and delays of a traditional SOC. We built inforcer TDR to create a version of this solution specifically for MSPs managing multiple tenants.

Below, we explain what a SOC does, why the traditional model struggles to keep pace with new Microsoft 365 threats across multiple tenant environments, and how MSPs are using inforcer TDR to offer their customers something most SOCs can't.

The role of AI in a traditional SOC

A security operations centre is the combination of people, tools and processes that watches an organization's systems for signs of attack, investigates what it finds and responds. For a business running on Microsoft 365, that means watching sign-in activity, mailbox changes, file access, app permissions and admin actions, and deciding which events point to a real threat.

A managed SOC delivers these capabilities as an outsourced service. The provider's analysts usually work in tiers: first-line analysts review incoming alerts and dismiss obvious false alarms, second-line analysts investigate anything suspicious, and senior responders take over confirmed incidents. Serious findings are passed back to the business or its IT provider to act on.

Businesses without their own security team, which describes most of the small and mid-sized businesses MSPs look after, have traditionally relied on this model for round-the-clock protection.

What's changing is how much of that work needs a person watching a screen. Automation and AI can now handle much of the monitoring, signal correlation and first response that analysts used to do by hand, and they can do it in seconds.

That shift is what makes it possible for MSPs to deliver SOC-level protection to their customers directly, as long as they use the right tools to do it.

Isn't automating security just another AI black box?

This is a fair question, and it is one that MSPs often hear from customers who associate more manual effort with better outcomes. These customers tend to picture a high-quality security solution as a room full of analysts, and are skeptical about the idea of an automated system making security decisions for them.

But a security solution that requires more manual effort usually isn’t the most effective option. And a security offering that includes automation doesn’t necessarily exclude oversight.

In an AI-powered, human controlled model, security experts train and maintain the system and decide what counts as a threat. Automation handles the volume and speed that people can't sustain at 2am, and the MSP can still show customers every threat they caught, along with every action they took to stop it. We'll look at how that works in practice further down.

For plain-English definitions of SOC, SIEM, MDR, XDR and the rest of the security alphabet, see our guide to Microsoft 365 security acronyms for MSPs.

Why round-the-clock threat detection is hard to do by hand

Attackers don't keep office hours. In an adversary-in-the-middle (AiTM) attack, a fake sign-in page captures a user's session token, the digital pass that keeps them signed in, so the attacker can get into the account without the user's password or MFA code.

If that happens at 2am, the attacker can have inbox rules hiding their activity and phishing emails going out to colleagues long before anyone arrives at work. We covered this attack in detail in MFA token theft: new risks and responses.

Stopping that means somebody, or something, has to be watching when it happens, and doing that manually takes a lot of people. There are 8,760 hours in a year, and a full-time engineer works roughly 1,700 to 1,900 of them once leave and training are accounted for.

Keeping a single seat staffed around the clock therefore takes about five people, which is the main reason round-the-clock protection has traditionally meant investing in a SOC. But this is expensive, and relying entirely on manual oversight leaves room for human error when people get burnt out or distracted.

MSPs already manage their customers' Microsoft 365 environments day to day, and they know those tenants better than any outside provider could. What they've lacked is a way to watch every tenant around the clock without building a night shift to do it.

Automation changes that. It runs all night, reads far more log data than any person could, and can act on a threat in seconds. But it's only effective when it's trained, maintained and supported by people with the security skills and experience to teach it what matters, keep it current as attack techniques change, and step in when a situation needs human judgement.

Where current approaches fall short

Until recently, most MSPs had two ways to give their customers round-the-clock protection: lean on automation-only security tools, or bring in an outsourced SOC. Both come with significant drawbacks.

Automation-only tools

These tools are inexpensive and always on, but without experts guiding them, they tend to create as much work as they save.

  • They're noisy. Without expert tuning, they flag almost anything unusual, from impossible travel that turns out to be a VPN to a legitimate admin change. A typical MSP can face 100 to 200 alerts a week at 15 to 30 minutes each, and real threats get lost in the pile. We've broken down the cost of alert fatigue for multi-tenant MSPs separately.
  • Some tools only look at events in isolation. A risky sign-in in Entra ID, a new inbox rule in Exchange and a burst of file downloads in SharePoint can be three stages of the same attack. Tools that alert on each event separately miss that connection. Conversely, inforcer TDR has been trained to correlate alert signals across different Microsoft 365 products and put threats in context, which can reveal attacks these other solutions often can’t.
  • They often alert without acting. A notification at 2am only helps if someone is awake to read it. Otherwise, nothing happens until an engineer opens the alert queue in the morning. Conversely, inforcer TDR uses AI to automatically contain major threats quickly when they occur.

Outsourced SOCs

  • Cost. Managed SOC services are usually priced per user or per endpoint, with a round-the-clock analyst team's wages built in. That's often hard to justify for SMB customers, leaving the MSP to absorb the cost or pass on a price rise its customers will resist.
  • Time to respond. An outsourced SOC can connect related signals and reach the right conclusion, but it takes longer to get there. An alert waits for an analyst, gets investigated, gets escalated and is finally passed to the MSP to act on, and every handoff gives an attacker more time. And since AI-powered attacks are moving faster than ever, this approach is even less effective than it once was.
  • Legacy platforms. The slow, handoff-heavy process is how these platforms were built. Many were designed years ago for large enterprises, and enough organizations still buy them that there's been little incentive to modernize.
  • Limited Microsoft 365 depth. Many SOC platforms were built around endpoint and network data and treat Microsoft 365 as one more log source, with less context on what's normal in a given tenant or how to tell a real attack from an unusual but legitimate change.
  • A third party between the MSP and its customer. The SOC's analysts, reports and escalations sit between the MSP and the business it serves, leaving the MSP to relay someone else's findings and making it harder to show customers the value of what they're paying for.

For most MSPs, that has meant asking customers to choose between a security solution that is cheap but noisy, and one that is thorough but slow and expensive. What MSPs need is a way to offer customers a cost-efficient security solution themselves.

How inforcer TDR fills the gap

Legacy SOC tools weren't going to modernize on their own, so we built inforcer TDR from scratch for MSPs managing Microsoft 365. It uses AI trained and monitored by human experts to deliver round-the-clock detection and response to every tenant an MSP manages so their customers don't have to rely on a traditional SOC.

By the time TDR became generally available in September 2026, more than 700 MSPs had used it during early access, 500,000 users had been onboarded in its first four weeks, and it had processed 20 billion Microsoft 365 logs.

What human-controlled means in practice

We haven't simply let AI decide what a threat looks like. Human expertise shapes inforcer TDR at every stage:

  • Experts train and maintain the platform. Our security specialists teach TDR what to look for, so the AI isn't left to do the heavy lifting on its own.
  • Its knowledge stays current. A dedicated team constantly updates what TDR knows, spots emerging trends and patterns in attacker behaviour, and shares new intelligence with partners.
  • Real people are on hand. Partners can talk to our specialist team whenever they want more triage or assistance. By the time they do, TDR has usually already dealt with the problem.
  • Automation covers the clock. TDR provides 24/7 coverage through AI alerting and automated containment, so threats are handled as they happen.

How inforcer TDR works: collect, detect, respond, prevent

TDR runs a continuous four-stage cycle for every tenant an MSP manages.

  • Collect. TDR monitors telemetry from across the whole Microsoft 365 estate of every managed tenant, from identity and email to files and collaboration, and can look back through up to six months of historical logs.
  • Detect. Rather than flagging every anomaly on its own, TDR correlates signals across Microsoft 365 within each tenant to separate likely attacks from isolated events, with our specialists validating detections where needed. Results for every tenant appear in a single view. As our Chief Product Officer, Matthé Smit, puts it, TDR “is quiet, so it earns a technician’s attention instead of draining it.”
  • Respond. For high-risk and critical threats, TDR contains the attack automatically by revoking sessions, locking or blocking accounts and retracting phishing emails, with an average containment time under 60 seconds. These actions follow rules of engagement agreed with the MSP, which can be defined per tenant, and a ticket is raised in the MSP's PSA for follow-up.
  • Prevent. When an incident occurs, TDR identifies the fix that would have prevented it, and the MSP can use 365 Manager to push that fix to every tenant that needs it, with no need to log in to each environment or remediate them one by one.

Built to work with 365 Manager

365 Manager, our multi-tenant management tool, is designed to work hand in hand with inforcer TDR. MSPs use it to set policies and update configurations for every tenant they manage at scale, which makes it easy to configure each tenant correctly from the same dashboard.

What MSPs can offer with inforcer TDR that most SOCs can't

Put together, this gives MSPs a managed security service their customers can't easily get from a traditional SOC:

  • Speed. High-risk threats are contained in seconds, before an attacker has time to set up inbox rules or move on to other accounts.
  • Microsoft 365 depth. inforcer TDR was built for Microsoft 365 from the ground up, so it understands how identity, email and file activity connect.
  • The fix as well as the alert. Detection, containment and hardening happen in one loop, so every incident leaves the MSP's tenants better protected.
  • Proof of value. Built-in, customer-ready reports show every threat detected and stopped, every action taken, and the updates made to harden each tenant as a result. In Smit's words, “the reporting matters as much as the detection.”
  • The MSP stays in front of the customer. Tickets land in the MSP's own PSA, and the MSP owns the conversation from detection through to remediation, with no third party in the middle.

inforcer TDR vs. traditional SOCs compared at a glance

 

Automation-only tools

Traditional outsourced SOC

MSP with inforcer TDR

Round-the-clock coverage

Yes, but alerts often wait for morning

Yes, through analyst shifts

Yes, through AI alerting and automated containment

Speed to contain

Often alerts without acting

Slowed by queues and handoffs

Seconds for high-risk threats (average under 60 seconds)

Alert noise

High: isolated anomalies flagged

Filtered by hand

Low: signals correlated within each tenant

Microsoft 365 depth

Often generic rules

One log source among many

Built for the Microsoft 365 estate

Human expertise

Little behind the tuning

Analysts review alerts manually

Experts train and maintain the platform; specialists on hand

Cost

Low

High: 24/7 analyst wages priced in

Leaner: automation carries the volume

Customer relationship

MSP, buried in alerts

SOC sits between MSP and customer

MSP stays in front, with customer-ready reports

Prevention

Rarely

Recommendations, then manual fixes tenant by tenant

Fix pushed to every tenant that needs it via 365 Manager

Give your customers a cost-effective alternative to the traditional SOC

Round-the-clock detection and response used to mean building a night shift or bringing in an outsourced SOC. An AI-powered, human controlled platform gives MSPs a third option: experts train and maintain the detection, automation contains threats in seconds, and the MSP stays in front of its customers with reports that show exactly what its service delivers.

inforcer TDR is built to help MSPs offer that service to every customer they manage.

 

FAQs

What is a managed SOC?

A managed SOC (security operations centre) is an outsourced service where a third-party team of analysts monitors a business's systems for signs of attack, investigates suspicious activity and escalates confirmed threats. Businesses without their own security team have traditionally used managed SOCs for round-the-clock protection, usually paying per user or per endpoint.

Can MSPs offer 24/7 threat detection and response without an outsourced SOC?

Yes. AI-powered, human controlled platforms such as inforcer TDR let MSPs monitor every Microsoft 365 tenant they manage around the clock. AI alerting sorts false positive alerts caused by routine activities from genuine threat signals as they happen, while inforcer’s security experts train and maintain the model so that MSPs don't need to staff a night shift or rely on an outsourced SOC.

What does AI-powered, human controlled security mean?

It means people with security expertise stay in charge of how the system works. Experts train and maintain the detection and keep the platform current as attack techniques change. Automation handles the alert volume to reduce the manual effort required by MSPs and prevent alert fatigue.

Why are outsourced SOCs slow to respond to Microsoft 365 threats?

Many outsourced SOCs run on legacy platforms built around queues and handoffs. An alert waits for an analyst, gets investigated, gets escalated and is then passed to the MSP to act on. Each step adds time, and an attacker holding a stolen session token can set up inbox rules and send internal phishing before the handoffs are complete.

How fast does inforcer TDR contain threats?

For high-risk and critical threats, inforcer TDR contains attacks automatically in seconds, with an average containment time of under 60 seconds. Actions such as revoking sessions, locking or blocking accounts and retracting phishing emails follow rules of engagement agreed with the MSP, and a ticket is raised in the MSP's PSA for follow-up.

How does inforcer TDR work with 365 Manager?

365 Manager is inforcer's multi-tenant management tool, designed to work hand in hand with inforcer TDR. When TDR identifies the fix that would have prevented an incident, MSPs can use 365 Manager to push it to every tenant that needs it from one dashboard, without logging in to each environment.

Live demo with Co-founder,
Will Connor

Want to see inforcer in action? Join a live platform demo with inforcer Co-founder and Chief Community Officer, Will Connor to explore how inforcer could benefit you.

Meet Inforcer
true