Editorial photograph of a security operations team running a SIEM consolidation review
Article · Microsoft · Sentinel

Sentinel licensing. 2026.

Microsoft Sentinel is priced on ingestion. Defender XDR overlaps the use case. E5 changes the math. Read the buyer side reference for SIEM consolidation under the 2026 catalog.

Read the Framework Microsoft Hub
20 to 55%Typical Sentinel cost movement
a leading industry analyst firmRecognized
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Microsoft Sentinel is the Azure native SIEM priced primarily on data ingestion. The 2026 catalog adds Defender XDR overlap, archive tier math, and an E5 license offset that resets the buyer side picture. Most estates run 20 to 55 percent off the first Sentinel quote after a clean ingestion review and a commitment tier match.

Pair this article with the Microsoft security licensing guide, the Azure FinOps framework, and the EA renewal playbook before the next Sentinel scoping call.

Key Takeaways

What a CISO needs to know in 90 seconds

  • Sentinel is ingestion priced. GB per day drives the bill.
  • Archive math matters. Long retention shifts to a cheaper tier.
  • Defender XDR overlaps. Endpoint, identity, email logs already in XDR.
  • E5 includes an offset. Up to 100 MB per user per day on certain logs.
  • Commitment tiers cut the rate. 100 GB to 5 TB per day bands.
  • Basic logs and Auxiliary logs are cheaper. Match log type to tier.
  • Year three is the cliff. Volume grows, the bill grows faster.

Why ingestion pricing matters

Sentinel pricing is consumption based. The customer pays per GB ingested into the workspace. Volume drives the bill. Volume grows with log enrichment, new data sources, and broader detection coverage.

The three volume drivers

  • New data sources. Network, application, cloud logs added over time.
  • Enrichment. Threat intelligence and behavioral signals add bytes per event.
  • Coverage expansion. Workloads, subsidiaries, and regions extending the scope.

Ingestion tier math

Sentinel is sold on a pay as you go rate with commitment tiers that step down the rate. The commitment is a daily GB floor. Volume above the commitment is billed at the same rate.

Commitment tier examples

Daily commitmentIndicative rateBuyer side note
Pay as you go$4.30 per GBBaseline, no commitment
100 GB per day$2.96 per GB~31% off PAYG
500 GB per day$2.50 per GB~42% off PAYG
1 TB per day$2.30 per GB~46% off PAYG
5 TB per day$2.00 per GB~53% off PAYG

Archive and basic logs

Not all logs need the analytics tier. Sentinel offers Basic Logs and Auxiliary Logs at lower rates with query and retention constraints. Matching log type to tier is the highest leverage saving on most estates.

The log tier match test

Run the log tier match test before signing a Sentinel commitment. Sort each data source by query frequency and retention need. Daily queries belong in Analytics. Weekly or monthly queries belong in Basic Logs. Compliance only logs go to Auxiliary or Archive. The reshuffle typically saves 20 to 35 percent without losing detection.

Log type taxonomy

  • Analytics Logs. Full query, real time alerts, full retention.
  • Basic Logs. Limited query, eight day retention default, lower rate.
  • Auxiliary Logs. Long term, limited query, cheaper still.
  • Archive. Up to seven years, query on demand, lowest rate.

Defender XDR overlap

Defender XDR carries endpoint, identity, email, and cloud app logs. Many of these logs also feed Sentinel. The overlap is the most common over spend on the security stack.

Overlap examples

Log sourceIn Defender XDRIn SentinelBuyer side response
Endpoint detectionsYesOptionalPull only summary, not raw
Identity sign inYesOften duplicatedUse connector with filters
Email threatsYesSometimes duplicatedDetect in XDR, alert in Sentinel
Cloud app logsYesOptionalFilter at source, not in Sentinel

E5 license offset

Microsoft 365 E5 and certain Microsoft Defender bundles include a Sentinel data benefit. The benefit covers up to 100 MB per user per day on specific log types. The offset is meaningful on large E5 estates.

E5 offset rules

  1. Eligible users. E5, Microsoft Defender for Office 365, and certain other bundles.
  2. Eligible log types. Office, Endpoint, Identity, and Cloud App connectors.
  3. Daily cap. Up to 100 MB per eligible user per day.
  4. Workspace scope. The benefit applies per workspace.

Commitment levers

The commitment tier is the primary buyer side lever. Pick the tier that matches the forecast volume after the log tier match and the Defender XDR overlap fix.

Sentinel is the single line in the Microsoft security stack where the buyer side can make the biggest dollar saving in the shortest time. The log tier match and the XDR overlap fix together typically deliver thirty percent without losing detection coverage.

Commitment levers

  • Right size the tier. Match commitment to the post fix forecast.
  • Lock the per GB rate. Multi year commitment for rate stability.
  • Workspace consolidation. Fewer workspaces, higher commitment leverage.
  • Negotiated overage. Cap the rate for volume above commitment.

What to do next

The seven step checklist below moves a Sentinel deployment from open consumption to a defended commercial picture.

  1. Inventory the data sources. Every connector, every workspace.
  2. Run the log tier match. Analytics, Basic, Auxiliary, Archive.
  3. Map the Defender XDR overlap. Pull only what adds value.
  4. Apply the E5 offset. Eligible users and connectors.
  5. Forecast the post fix volume. Twelve months out.
  6. Pick the commitment tier. Match the forecast plus buffer.
  7. Lock the multi year rate. Cap escalators and overage.

Frequently asked questions

How is Microsoft Sentinel actually priced?

Sentinel is priced on data ingested into Log Analytics. The per GB rate steps down at commitment tiers from 100 GB per day up to 5 TB per day. Volume above the commitment is billed at the commitment rate. Different log types attract different rates. The full picture includes ingestion, retention, and archive restore operations.

What is the difference between Analytics, Basic, and Auxiliary logs?

Analytics Logs support real time query and alerting with standard retention. Basic Logs support limited query against an eight day window at a lower rate, useful for audit logs. Auxiliary Logs sit lower again with tight query constraints, for long retention with minimal active query. Archive is the lowest cost tier with on demand restore.

Does Defender XDR replace Sentinel?

Defender XDR overlaps in capability for Microsoft sourced logs but does not replace Sentinel for the wider SIEM use case. Defender XDR is strong on endpoint, identity, email, and cloud app detection. Sentinel is the place where third party logs, network telemetry, and custom detections come together. Most estates run both, with careful connector tuning to avoid duplicate ingestion.

How big is the E5 Sentinel benefit?

The benefit covers up to 100 MB per eligible user per day on specific connectors. On a 20,000 user E5 estate the daily benefit is up to 2 TB per day, a material offset against the post fix forecast. The benefit applies per workspace and only on the eligible connectors, so the inventory work matters as much as the headcount.

Should we consolidate to one workspace or many?

The right number depends on regulatory boundaries, data residency, and operational ownership. Fewer workspaces concentrate the commitment tier leverage and simplify the commercial picture. More workspaces help where data residency or tenant boundaries demand it. Most estates land on a small number of workspaces with cross workspace query for the operations team.

What happens when our ingestion grows faster than the commitment?

Volume above the commitment is billed at the commitment per GB rate. There is no penalty rate for overage. Growth that consistently exceeds the commitment is the signal to step up to the next tier. The buyer side response forecasts volume quarterly and adjusts the commitment at the contract anniversary rather than waiting for renewal surprises.

How Redress engages on Sentinel and Microsoft security

Redress runs Sentinel as part of the broader Microsoft security stack engagement. The work covers data source inventory, log tier match, Defender XDR overlap, E5 offset, and the commitment tier decision. Engagements close in eight to twelve weeks.

Read the related Vendor Shield, Renewal Program, Benchmark Program, Software Spend Assessment, Benchmarking, about us, management team, locations, and contact pages.

Score your Microsoft security readiness against the buyer side benchmark in under five minutes.
Open the Microsoft Readiness Check →
White Paper · Microsoft

Download the Microsoft EA Renewal Playbook.

A buyer side playbook for Microsoft EA and MCA renewals that includes the Sentinel commitment tier framework, the Defender XDR overlap map, the E5 offset rules, and the broader Microsoft security stack anchor table used across hundreds of EA engagements.

Independent. Buyer side. Built for CISOs, security operations leads, and procurement teams carrying Sentinel, Defender, and Microsoft 365 E5 contracts. No vendor influence. No sales kickback.

Microsoft EA Renewal Playbook

Open the white paper in your browser. Corporate email only.

Open the Paper →
20 to 55%
Sentinel cost movement
100 MB
E5 daily benefit
4
Log tier options
500+
Enterprise clients
100%
Buyer side

The log tier match plus the Defender XDR overlap fix cut our Sentinel bill by thirty four percent in three months. Detection coverage did not move. The commitment tier moved down a step at the next anniversary.

Group CISO
North American healthcare group
More Reading

More from this practice.

Microsoft Hub →
Microsoft Security Guide
Microsoft · Guide
Microsoft Security Guide
The security stack reference.
24 min read
Azure FinOps Framework
Microsoft · Article
Azure FinOps Framework
The Azure cost framework.
18 min read
EA Renewal Playbook
Microsoft · Pillar
EA Renewal Playbook
Multi product renewal anchor.
26 min read
Azure Cost Management
Microsoft · Article
Azure Cost Management
The six layer framework.
18 min read
M365 Copilot Licensing
Microsoft · Article
M365 Copilot Licensing
The Copilot enterprise reference.
16 min read
Editorial photograph of enterprise contract negotiation strategy

Sentinel cost is a fixable problem.

We have run 500+ enterprise clients across 11 publishers. Every engagement starts with one conversation.

Microsoft security intelligence, monthly.

Sentinel per GB pricing movement, Defender XDR coverage changes, E5 benefit examples, Log Analytics commitment patterns, and the wider Microsoft security stack commercial leverage signals across every engagement.