Sentinel optimization, manage the data and not the headcount
Microsoft Sentinel charges for analysing data, per gigabyte ingested into the Log Analytics workspace it sits on, and there is no per analyst fee: a team of three can run a bill larger than a team of thirty if they ingest more data. Seats are the wrong mental model, and the meter rewards exactly one discipline, filtering what never feeds a detection before it ever bills.
Prepared by Redress Compliance · August 7, 2026 · Microsoft security advisory. Based on 25 to 35 Sentinel deployments benchmarked 2024 to 2025.
Executive summary
A fifth to two fifths of the bill analysed nothing. Across our deployments, 20 to 40 percent of ingested volume was verbose data that never fed a detection rule: debug logs, chatty network sources, and duplicated telemetry paying full analytics rates to sit unread.
Filtering noisy sources at the collector is the single biggest lever on the meter, because a gigabyte filtered costs nothing and a gigabyte ingested bills twice, once for Sentinel analysis and once for Log Analytics underneath.
The commitment tier was left unclaimed alongside the discount. Workspaces sat on pay as you go rates where a daily commitment tier would have cut 15 to 30 percent for volume that was already steady and predictable.
The trade is the standard consumption one: the pledged volume bills whether used or not, so the tier sizes to the measured floor after the filtering pass, never before it.
The E5 data grant was the free money nobody collected. Microsoft 365 E5 includes a data grant offsetting some Microsoft 365 connector ingestion, and teams ingesting those logs had mostly never applied it: an entitlement already paid for inside the suite, left off the bill by configuration.
The claim is administrative, not commercial, which is exactly why it kept being missed.
The tiering and retention lines complete the model. Auxiliary and basic logs cost far less than analytics logs for high volume, low value data, with limited query features as the trade, and retention beyond the included window is a separate and routinely overlooked charge.
The architecture decision, which sources land in which tier and how long anything stays, is the licensing decision, made in the collector configuration rather than the contract.
The two stacked charges, and the models on each
| Model | Best when | The risk |
|---|---|---|
| Pay as you go | Volume is small or erratic | The highest unit rate on every gigabyte |
| Commitment tier | Volume is steady and predictable | The pledged daily volume bills even if unused |
| Basic and auxiliary logs mixed in | High volume, low value sources exist | Limited query features on the cheap tiers |
Two charges stack on every gigabyte. The Sentinel analysis charge for processing the data sits on top of the Log Analytics ingestion and retention charge for storing it, which is why the filtering lever pays double and why the bill scales with data architecture rather than team size.
Manage the data, not the headcount: the meter has never once counted an analyst.
The filtering pass, run before any commercial decision
The optimization sequence is fixed because each step reprices the next. First, the detection audit: map every ingested source against the analytics rules that consume it, and the 20 to 40 percent feeding nothing surfaces immediately.
Second, the routing: verbose but occasionally useful sources move to basic and auxiliary log tiers at a fraction of the analytics rate, accepting the query limitations for data that is evidence rather than signal.
Third, the collector filtering: what neither detects nor evidences drops before ingestion, at the source, where it costs nothing. Only then does the commercial layer make sense, because a commitment tier sized before the filtering pledges volume the cleanup was about to remove.
The wider security stack rationalization this sits inside, what E5 already includes against what gets bought again, runs through the security licensing guide and the Defender P1 versus P2 analysis.
The Microsoft EA renewal playbook
The negotiation the security estate rides on: the E5 arithmetic, the suite entitlement map, and the consumption lines priced inside the agreement.
Get the white paper →The grant, the tier, and the retention line
- The E5 data grant: included with Microsoft 365 E5, offsetting a daily allowance of Microsoft 365 connector ingestion, claimed by configuration and missed by default in most deployments we benchmarked.
- The commitment tier: a pledged daily volume for a 15 to 30 percent lower effective rate, sized to the post filtering floor and reviewed as the estate changes.
- The retention charge: data kept beyond the included window bills separately, so retention policy per table, not one blanket setting, is a real cost line.
- The tier routing: analytics logs for detection, basic and auxiliary for high volume evidence, and nothing for what neither role justifies.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across Sentinel deployments, 2024 to 2025
Across roughly 25 to 35 Microsoft Sentinel deployments Morten Andersen benchmarked between 2024 and 2025, ingestion was the runaway line and most teams had never claimed the E5 data grant:
Verbose data billing analytics rates without a single detection rule consuming it.
On workspaces at pay as you go rates whose volume was already steady enough to commit.
The pattern is the security estate's version of every consumption meter: the bill grows with configuration decisions nobody owns commercially, the entitlements already paid for go unclaimed because claiming them is an admin task.
And the commercial constructs that reward predictability sit unused beside perfectly predictable volume.
The fix is ownership: one name on the ingestion line, the detection audit quarterly, the grant confirmed in configuration, and the tier reviewed against the measured floor at every renewal.
Your first five moves
- Audit every source against the detection rules that consume it, because the 20 to 40 percent feeding nothing is the biggest lever.
- Filter at the collector and route by tier: analytics for signal, basic and auxiliary for evidence, nothing for the rest.
- Claim the E5 data grant now, the offset already paid for inside the suite and missed by configuration default.
- Commit to the post filtering floor, where the 15 to 30 percent tier discount prices predictability you already have.
- Set retention per table and put one name on the ingestion line, reviewed quarterly. The Microsoft practice runs the optimization with you.
Frequently asked questions
How does Microsoft Sentinel licensing work?
Per gigabyte ingested, never per user: the Sentinel analysis charge sits on top of the Log Analytics ingestion and retention charge on the workspace beneath it, so every gigabyte bills twice.
There is no per analyst fee, which means the bill scales with data architecture rather than team size, and the data, not the headcount, is what gets managed.
What is the biggest Microsoft Sentinel cost saving?
Filtering: 20 to 40 percent of ingested volume across our deployments was verbose data that never fed a detection rule, billing full analytics rates to sit unread.
Auditing every source against the rules that consume it, filtering at the collector, and routing low value volume to basic and auxiliary tiers attacks the meter where it actually runs.
Are Sentinel commitment tiers worth it?
Where volume is steady, yes: the pledged daily volume buys a 15 to 30 percent lower effective rate, and workspaces sitting on pay as you go with predictable volume were leaving exactly that on the table.
Size the tier to the measured floor after the filtering pass, because committing before the cleanup pledges volume you were about to remove.
What is the Microsoft 365 E5 Sentinel data grant?
An included daily allowance offsetting Microsoft 365 connector ingestion for E5 licensed users, already paid for inside the suite and claimed through configuration.
Most teams ingesting Microsoft 365 logs in our benchmarks had never applied it, which made it the most reliable free saving in the estate: an admin task, not a negotiation.
What are Sentinel basic and auxiliary logs?
Cheaper ingestion tiers for high volume, low value data, priced far below analytics logs in exchange for limited query features.
They fit evidence grade data, verbose sources occasionally needed for investigation but never feeding detections, and the routing decision per source is where a large share of the optimization lives.
Does Sentinel charge for data retention?
Yes, beyond the included window, as a separate and routinely overlooked line: retention policy set per table against genuine investigation and compliance needs, rather than one blanket setting, keeps the archive from quietly becoming a second ingestion bill.
The retention review belongs in the same quarterly pass as the detection audit.