Editorial photograph of a security operations center monitoring data ingestion dashboards
Microsoft / Security

Microsoft Sentinel licensing. The 2026 pricing read.

Microsoft Sentinel is priced on the data you ingest, not on seats. Commitment tiers, free Defender data, and cheaper log tiers decide the bill. Ingestion discipline is the whole game.

Contact Us Microsoft Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Microsoft Sentinel is priced by data ingestion, not by seats. Commitment tiers, free Microsoft Defender data, and cheaper log tiers decide the bill. Ingestion discipline, not feature choice, is what controls Sentinel cost.

Key takeaways

  • Sentinel is billed per gigabyte of data ingested and analyzed.
  • Pricing combines a Sentinel charge and the underlying Log Analytics cost.
  • Commitment tiers discount a reserved daily ingestion volume.
  • Microsoft Defender XDR security data largely ingests free.
  • Basic and auxiliary log tiers cost far less than analytics logs.
  • Verbose sources in the analytics tier drive most cost overruns.
  • Ingestion tuning cuts cost 25 to 45 percent without losing coverage.

How is Microsoft Sentinel priced in 2026?

Sentinel is priced on the volume of data you ingest and analyze, billed per gigabyte. There is no per seat license.

The charge combines a Sentinel analysis fee and the underlying Log Analytics workspace cost. Microsoft sets the rates on its Sentinel pricing page. Volume is the variable that matters.

Pay as you go versus commitment

Pay as you go bills each gigabyte at the standard rate. Commitment tiers reserve a daily volume at a discount. Microsoft documents the mechanics in its billing guide.

What are the Sentinel commitment tiers?

Commitment tiers reserve a fixed daily ingestion volume in exchange for a lower per gigabyte rate. The higher the commitment, the deeper the discount.

Sentinel pricing options at a glance

OptionHow it billsBest forWatch out for
Pay as you goPer gigabyte ingestedLow or variable volumeHighest unit rate
Commitment tierReserved daily volumeSteady predictable volumeOver committing to peak
Basic and auxiliary logsReduced per gigabyteHigh volume low value logsLimited query features
Data lakeLow cost retentionLong term storageSeparate query model

How to size a commitment

Size the commitment to steady state ingestion, not to peak. A commitment set to peak pays for headroom you rarely use. Measure a full month before committing.

What data is free or discounted in Sentinel?

Two paths cut cost: free Microsoft Defender data and the cheaper log tiers.

Free Defender data

Microsoft Defender XDR alert and security data largely ingests at no charge. Routing security signal through that path avoids paying twice for the same telemetry.

Cheaper log tiers

Basic and auxiliary logs ingest high volume, low value data at a fraction of the analytics rate. Microsoft explains the table plans in its table tiers documentation. Route verbose sources there.

Where the common advice on Sentinel pricing is wrong

The common advice is to ingest everything into Sentinel so nothing is missed, then optimize later. We disagree. More data does not mean more security, it means a larger bill, and the verbose sources that inflate cost rarely change a detection outcome. In our reviews the cheapest and most effective Sentinel deployments fed only the logs that earned their place, routed high volume noise to cheaper tiers, and leaned on the free Defender path. The buyer side move is to design ingestion before turning the taps on, not to ingest broadly and tune under budget pressure later. Detection value comes from the right logs, not all logs.

Editorial photograph of a data engineering team mapping log ingestion pipelines on a whiteboard
Routing verbose firewall and proxy logs to basic tiers, and security signal through the free Defender path, is where most Sentinel savings are found.
25
Sentinel reviews 2024 to 2025
25 to 45%
Ingestion cost cut by tuning
2 of 3
Estates underusing free Defender data

Source: Redress Compliance advisory engagement file, 2024 to 2025.

Sentinel does not bill for security. It bills for data. The cheapest Sentinel is the one fed only the logs that earn their place.

What drives Sentinel cost overruns?

Verbose sources in the analytics tier drive almost every overrun.

  • Firewall and proxy logs: high volume, low detection value at full analytics rate.
  • Endpoint noise: raw endpoint logs that duplicate Defender signal.
  • Peak sized commitments: reserved volume set above steady state use.

How to control them

Filter at the source, route noise to cheaper tiers, and resize commitments to steady state. Microsoft offers concrete guidance in its cost reduction documentation.

What buyer side moves cut Sentinel cost?

Three moves control the bill without weakening detection.

Design ingestion first

Decide which sources earn analytics ingestion before onboarding them. Design beats retrofitting under budget pressure.

Route by value

Send high value logs to analytics, noise to basic tiers, and security signal through the free Defender path.

Size commitments to steady state

Measure a month, then commit to steady state volume, leaving peaks on pay as you go.

Suggested reading

What should a buyer do next?

  1. Inventory every Sentinel log source and its monthly ingestion volume.
  2. Identify verbose sources in the analytics tier with low detection value.
  3. Route high volume low value logs to basic and auxiliary tiers.
  4. Move security signal onto the free Microsoft Defender path.
  5. Measure steady state ingestion for a full month.
  6. Size the commitment tier to steady state, not peak.
  7. Recheck ingestion design after every new source onboards.
  8. Engage independent advisory before a multi year commitment.

Frequently asked questions

How is Microsoft Sentinel priced?

Microsoft Sentinel is priced by the volume of data ingested and analyzed, billed per gigabyte. Pricing combines a Sentinel analysis charge and the underlying Log Analytics cost, so ingestion volume is the main driver.

What are Sentinel commitment tiers?

Commitment tiers let you reserve a daily ingestion volume at a discount against pay as you go. The more you commit per day, the lower the effective per gigabyte rate, provided the commitment matches real volume.

Is Microsoft Defender data free in Sentinel?

Much Microsoft Defender XDR alert and security data flows into Sentinel at no ingestion charge. Routing security signal through the free Defender path instead of paid ingestion is a major cost lever.

What are basic and auxiliary logs?

Basic and auxiliary log tiers ingest high volume, low value data at a much lower per gigabyte rate than analytics logs. Verbose sources can be routed to these cheaper tiers when full analytics is not needed.

What is the Sentinel data lake?

The Sentinel data lake provides lower cost long term storage and querying for large volumes of security data. It separates cheap retention from the higher cost analytics tier.

What drives Sentinel cost overruns?

Verbose log sources ingested into the analytics tier without filtering. Firewall, proxy, and endpoint logs at full volume are the usual culprits, and they inflate the bill without adding detection value.

How much can ingestion tuning save?

In our reviews, filtering verbose sources and routing to cheaper tiers typically cut Sentinel ingestion cost by 25 to 45 percent without losing detection coverage. The range depends on how unfiltered the original feed was.

What is the biggest Sentinel cost mistake?

Ingesting everything into the analytics tier on the assumption that more data means more security. It means more cost. Detection value comes from the right logs, not all logs.

Microsoft EA Renewal Playbook

The full Microsoft EA renewal playbook framework from the Microsoft Practice.

Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

No spam. We will only email you about this download. Privacy.
Run the Microsoft 365 license optimizer against your estate in under five minutes.
Open the Tool →