Microsoft’s security leadership published its blueprint for the “agentic SOC” — a two-layer model where deterministic controls disrupt known attacks at machine speed while AI agents handle correlation and investigation, and analysts shift from triaging alerts to supervising outcomes. Microsoft reports its internal task agents now automate 75% of phishing and malware investigations. The framing matters because it moves the industry debate past whether agents belong in security operations to how roles change around them: detection engineers set confidence thresholds, hunters go hypothesis-driven, and leadership governs autonomy rather than queues. Whatever platform you run, the takeaway is the same — the scarce resource in the SOC is no longer alert handling, it’s investigative judgment. Teams that codify how their best analysts ask questions will get the most out of agents; teams that don’t will just automate their backlog.