Editorial photograph of a security operations centre with multiple monitoring screens
Guide · Microsoft · Sentinel

Microsoft Sentinel licensing in 2026. The bill is the data, not the seats.

Microsoft Sentinel charges on the volume of data you ingest and retain, not on user seats. This guide maps the commitment tiers, the E5 data grant, and the moves that cut the bill.

Read the Guide Microsoft Practice
GBThe billing unit
500+Enterprise clients
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Microsoft Sentinel is priced on the volume of data ingested and retained, measured in gigabytes, which makes data engineering the real cost lever, not the licence.

Teams that treat Sentinel as a seat licence overspend within a quarter. The meter runs on every log you send it.

This guide shows the tiers, the data grant most enterprises forget to claim, and four moves that cut the bill.

Key takeaways

What drives a Sentinel bill

  • Microsoft Sentinel bills primarily on data ingested into the Log Analytics workspace, charged per gigabyte.
  • Commitment tiers cut the per gigabyte rate in exchange for a daily volume pledge.
  • Microsoft 365 E5 includes a data grant that offsets some Microsoft 365 connector ingestion.
  • Auxiliary and basic logs cost far less than analytics logs for high volume low value data.
  • Retention beyond the included window is a separate and often overlooked charge.
  • Filtering noisy sources at the collector is the single biggest lever on the meter.

How does Microsoft Sentinel billing actually work?

Microsoft Sentinel charges for analysing data, and that charge sits on top of the Log Analytics workspace that stores it. The unit is the gigabyte ingested, not the user.

The authoritative breakdown is in the Microsoft Sentinel billing documentation, and the current rates are on the Sentinel pricing page.

The two charges that stack

  • Sentinel analysis: the per gigabyte Sentinel charge for processing data.
  • Log Analytics: the underlying data ingestion and retention charge.

Why seats are the wrong mental model

There is no per analyst Sentinel fee. A team of three can run a bill larger than a team of thirty if they ingest more data. Manage the data, not the headcount.

What are Microsoft Sentinel commitment tiers?

Commitment tiers let you pledge a daily ingestion volume in exchange for a lower effective rate. The trade is predictability and discount against flexibility.

Pay as you go versus commitment tier logic

Model Best when Risk
Pay as you goVolume is small or erraticHighest unit rate
Commitment tierVolume is steady and predictablePay for pledged volume even if unused
Mixed with basic logsHigh volume low value sources existLimited query features on basic logs

How to size a tier

Measure a stable thirty day baseline before you commit. Pledge slightly below your steady median, because overage above a tier still bills at the tier rate, not the higher pay as you go rate.

What is the Microsoft 365 E5 data grant?

Customers with Microsoft 365 E5 receive a per user daily data grant that offsets ingestion of certain Microsoft 365 security logs into Sentinel. Many teams never claim it.

The scope of the grant and the eligible data types are documented in the Sentinel billing reference, and the wider security entitlements sit on the Microsoft 365 E5 Security page.

Beyond the grant. The data engineering levers

  • Filter at the collector: drop verbose fields before they hit the workspace.
  • Route to basic logs: send high volume low value sources to the cheaper tier.
  • Tune retention: archive cold data rather than keep it in hot analytics retention.

Where the common advice on Microsoft Sentinel cost is wrong

The common advice is to ingest everything because storage is cheap and you might need the data later. We disagree. In roughly 18 of the 25 Sentinel deployments we benchmarked, a quarter or more of ingested volume never touched a detection rule yet billed at the full analytics rate. The buyer side move is to classify every source by detection value first, route low value high volume sources to basic or auxiliary logs, and archive cold data outside hot retention. Ingest everything is a slogan that suits the meter, not the budget, and disciplined data engineering cuts the bill without losing a single detection.

Editorial photograph of a data engineer reviewing log ingestion volumes on a dashboard
Classifying every log source by detection value, before it reaches the workspace, is the lever that controls a Sentinel bill.

What to do next

  1. Measure a stable thirty day ingestion baseline by source.
  2. Classify each source by whether it feeds an active detection rule.
  3. Claim the Microsoft 365 E5 data grant if you hold E5 seats.
  4. Route high volume low value sources to basic or auxiliary logs.
  5. Size a commitment tier just below your steady median ingestion.
  6. Move cold data to archive rather than hot analytics retention.
  7. Review ingestion monthly, because new connectors quietly raise the meter.

Frequently asked questions

How is Microsoft Sentinel priced?

Sentinel is priced on data ingested and retained, measured per gigabyte, plus the underlying Log Analytics charge. There is no per user or per seat Sentinel fee.

What is a Sentinel commitment tier?

A commitment tier is a pledged daily ingestion volume that lowers the effective per gigabyte rate. It suits steady predictable volume and bills for the pledge even if you ingest less.

Does Microsoft 365 E5 reduce Sentinel cost?

Yes. E5 includes a per user daily data grant that offsets ingestion of certain Microsoft 365 security logs. Many teams never claim it, so check your entitlement.

What are basic logs in Sentinel?

Basic logs are a lower cost ingestion tier for high volume low value data, with reduced query and retention features. They suit verbose sources that do not drive detections.

How do I cut a Sentinel bill without losing coverage?

Filter verbose data at the collector, route low value sources to basic logs, claim the E5 grant, size a commitment tier, and archive cold data. Coverage is set by detection rules, not by raw volume.

Should I ingest every available log into Sentinel?

No. Ingesting data that never feeds a detection rule bills at the full rate for no security value. Classify sources by detection value before you connect them.

Is retention charged separately in Sentinel?

Yes. Data kept beyond the included window incurs a separate retention charge. Archive tiers are cheaper than hot analytics retention for data you rarely query.

How often should I review Sentinel ingestion?

Monthly. New connectors and noisy sources raise the meter quietly, so a recurring review keeps ingestion aligned with detection value.

Benchmark your Microsoft security spend in under five minutes.
Open the 365 Optimizer →
White Paper · Microsoft

Download the Microsoft EA Renewal Playbook.

A buyer side reference for the next Microsoft renewal. Mix shift, Copilot ramp, Defender stacking, true up timing, and the seven clause renewal levers that move the bill.

Independent. Buyer side. Written for CIOs, CFOs, and procurement leaders carrying Microsoft Enterprise Agreements. No Microsoft kickback. No conflict on the table.

Microsoft EA Renewal Playbook

Open the white paper in your browser. Corporate email only.

Open the Paper →
30
Sentinel deployments benchmarked
28%
Median verbose ingestion removed
22%
Saving from tier plus filtering

Source: Redress Compliance advisory engagement file, 2024 to 2025.

Ingest everything is a slogan that suits the meter, not the budget.

Morten Andersen
Co Founder, Redress Compliance
Editorial photograph of enterprise contract negotiation strategy

Cut the Sentinel bill, keep the coverage. Independent advisors, end to end.

We have run 500+ enterprise clients across 11 publishers. Every engagement starts with one conversation.

Microsoft intelligence, monthly.

Microsoft EA benchmarks, renewal cadence intelligence, Copilot ramp patterns, and Azure commitment math from every Microsoft engagement we run on the buyer side.