Ingestion tuning cut cost 25 to 45 percent without losing a single detection
That sentence is the whole article. If nearly half the bill can be removed without weakening detection, then nearly half the bill was buying no security, and no discount negotiated on the unit rate would have found it.
Prepared by Redress Compliance · August 11, 2026 · Microsoft advisory. Based on 20 to 30 Microsoft Sentinel cost reviews, 2024 and 2025.
Executive summary
Ingestion tuning cut cost 25 to 45 percent with no loss of detection coverage. Read that as a statement about what the spend was doing rather than about efficiency.
Volume that can be removed without weakening detection was never contributing to detection, so this is not an optimisation trade off, it is the removal of spend that had no security value in the first place.
Verbose firewall, proxy and endpoint logs running into the analytics tier at full volume drove most of the bill. Basic and auxiliary log tiers cost far less than analytics logs, so the same data routed correctly costs a fraction of the same data routed by default.
The cost driver is a routing decision, not a licensing one.
Free Defender ingestion paths were underused in roughly two of three estates. Microsoft Defender XDR alerts and incidents ingest at no charge, and Microsoft 365 E5 grants up to 5 MB of free ingestion per user per day.
Both are entitlements already owned, and both were being paid for again in the analytics tier.
Commitment tiers were sized to peak rather than to sustained volume. Tiers run from 100 GB per day to 50,000 GB per day, and a tier bought for the worst week is paid for every week, which compounds the routing problem rather than offsetting it.
How the meter actually reads
| Element | How it bills | Buyer note |
|---|---|---|
| Ingestion | Per gigabyte ingested and analysed | The only variable that moves the number materially |
| Analytics tier | Full rate | Where verbose sources drive most overruns |
| Basic and auxiliary tiers | Far less than analytics | Same data, a fraction of the cost |
| Defender XDR alerts | Free | Underused in two of three estates |
| Microsoft 365 E5 grant | Up to 5 MB per user per day free | An entitlement already paid for |
| Retention | First 90 days included | Long tail storage is a separate lever |
Nothing in this table is a licence you negotiate. There is no per seat charge, and feature choice, connector count and the number of analytics rules carry no licence fee at all. What you route into the workspace is the entire bill.
That is an unusual property in enterprise software and it has a direct organisational consequence: the person who controls the cost is whoever decides which sources land in which tier, and that person sits in security engineering rather than in procurement.
The simplified pricing tier collapses the Sentinel and Log Analytics charges onto one meter, which makes the bill easier to read but does not change what drives it.
Where the 25 to 45 percent comes from
- Move verbose firewall, proxy and endpoint sources out of the analytics tier, because basic and auxiliary tiers cost far less and these sources drove most of the bill at full analytics rates.
- Turn on the free Defender ingestion paths, since Defender XDR alerts and incidents ingest at no charge and were underused in roughly two of three estates.
- Claim the Microsoft 365 E5 grant, which allows up to 5 MB of free ingestion per user per day and is an entitlement the estate has usually already bought.
- Size the commitment tier to sustained volume, not to peak, because a tier bought for the worst week is paid for every week of the year.
- Treat retention beyond 90 days as a separate decision, as the first 90 days are included and long tail storage bills at standard Log Analytics rates on its own curve.
The Microsoft EA renewal playbook
Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the estate.
Get the playbook →The negotiation happens in the wrong building
Most cost problems in enterprise software are contract problems wearing a technical disguise. Sentinel is the reverse, and treating it the usual way is why the reviews keep finding the same thing.
Because the meter reads gigabytes ingested and analysed, and because feature choice, connector count and analytics rules carry no licence fee, there is almost nothing for a procurement team to win.
A good unit rate cannot rescue an estate that routes everything into the analytics tier, and the reciprocal is equally true: an estate with disciplined ingestion pays little even at an unremarkable rate.
The cost is set by an architecture decision about which sources land in which tier, and that decision is made by security engineering, usually while standing up connectors under time pressure and with no visibility of the price of each choice.
So the two functions that jointly determine the bill never meet. Procurement negotiates a rate against a volume it does not control, and security selects a volume without seeing what it costs. The 25 to 45 percent figure is the measurement of that gap.
What makes it decisive rather than merely large is the second half of the finding: the reduction came with no loss of detection coverage.
If removing nearly half the spend leaves detection unchanged, then that portion of the spend was not buying detection, which means this is not a trade between cost and security at all.
It is the removal of volume that was purchased by default rather than by decision, chiefly verbose firewall, proxy and endpoint logs sitting in the analytics tier when basic or auxiliary would have served.
And entitlements already owned but never switched on, with free Defender ingestion paths underused in two of three estates and the Microsoft 365 E5 grant of 5 MB per user per day left unclaimed.
Sizing commitment tiers to peak rather than sustained volume then locks the inflated number in for the year.
The practical move is organisational before it is technical: put the person who chooses the tier for each source in the same review as the person who sees the invoice, give them the per tier rates, and re examine the routing before renegotiating anything. Then size the commitment to what remains.
The wider Microsoft position sits in the Microsoft practice.
Watch the briefing · 7:05Microsoft EA Negotiation: Five ThingsThe five levers that move an Enterprise Agreement, including the baseline that a rising Unified Support bill is calculated from.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across Microsoft Sentinel engagements, 2024 and 2025
Across roughly 20 to 30 Microsoft Sentinel cost reviews advised in 2024 and 2025, the bill almost always traced back to undisciplined ingestion rather than to the rate:
Cost cut by ingestion tuning alone, which means that share of the spend was not contributing to detection in the first place.
Estates paying in the analytics tier for Defender data that ingests at no charge, an entitlement they already held.
Three patterns recurred: verbose network and endpoint logs in the analytics tier driving most of the bill, free Defender ingestion paths underused in roughly two of three estates, and commitment tiers sized to peak rather than sustained volume.
The buyer side move is to fix the routing before negotiating the rate. The wider library sits in the Microsoft practice.
Your first five moves
- Put security engineering and procurement in the same review, because the volume is chosen by one function and the price is negotiated by the other, and that gap is what the 25 to 45 percent measures.
- Re route verbose firewall, proxy and endpoint logs out of the analytics tier, where basic and auxiliary tiers carry the same data at a fraction of the cost.
- Switch on the free Defender ingestion paths and claim the E5 grant, since both are entitlements already owned and were being paid for a second time in two of three estates.
- Fix the routing before renegotiating the rate, as a good unit price cannot rescue an estate that ingests everything at full analytics rates.
- Size the commitment tier to sustained volume once the routing is fixed, not to peak. The Microsoft practice runs the ingestion review with you.
Frequently asked questions
How is Microsoft Sentinel priced in 2026?
On the volume of data ingested and analysed, billed per gigabyte, with no per seat licence. A Sentinel analysis charge sits on top of the underlying Log Analytics workspace ingestion cost, and the simplified pricing tier collapses both onto a single combined per gigabyte meter.
Can a better discount fix a Sentinel bill?
Rarely. Feature choice, connector count and analytics rules carry no licence fee, so there is little for procurement to win. A good unit rate cannot rescue an estate that routes everything into the analytics tier, which makes cost control an architecture problem rather than a discount problem.
How much can ingestion tuning actually save?
Between 25 and 45 percent, with no loss of detection coverage. That second clause is the important one: volume that can be removed without weakening detection was never contributing to detection, so this is not a trade off between cost and security.
What drives most of the overrun?
Verbose firewall, proxy and endpoint logs running into the analytics tier at full volume. Basic and auxiliary log tiers cost far less than analytics logs, so the same data routed correctly costs a fraction of what it costs routed by default.
What ingests for free?
Microsoft Defender XDR alerts and incidents ingest at no charge, and Microsoft 365 E5 grants up to 5 MB of free ingestion per user per day. Both are entitlements the estate already holds, and both were underused in roughly two of three estates we reviewed.
How should the commitment tier be sized?
To sustained volume rather than to peak, and only after the ingestion routing has been fixed. Tiers run from 100 GB per day to 50,000 GB per day, and a tier bought for the worst week is paid for every week of the year.
Does retention affect the bill separately?
Yes. The first 90 days of retention on ingested data carry no charge, and retention past 90 days bills at standard Log Analytics rates. That makes long tail storage a distinct lever from ingestion, worth reviewing on its own rather than inside the ingestion discussion.
Microsoft EA: Where the Leverage Really Is, and the Mistakes That Give It Away
Leverage lives in Microsoft's calendar and targets, and in credible movement at the edges of the estate. The three mistakes that hand it back: the copy-paste renewal, everyone-gets-everything licensing, and price-only negotiation under their clock.