Contents
Key takeawaysHow Sentinel is pricedWhy discounts do not fix itWhere the saving comes fromA worked exampleWhat we have seenCheck your own ingestionWhat Microsoft will sayWhat to do nextFAQSentinel bills per gigabyte ingested, with no seat license, so the invoice follows your routing choices. In our reviews, ingestion tuning removed close to half the cost in some workspaces without losing a detection, which no unit rate discount would have found.
- Priced on volume. Sentinel charges per GB ingested and analyzed, and features, connectors and analytics rules carry no license fee.
- Tuning beats discounts. Moving and filtering ingestion removed up to 45 percent of cost with no loss of detection coverage, so that spend was buying no security.
- Verbose logs drive the bill. Firewall, proxy and endpoint logs at full analytics rates made up most of the overruns we saw, and cheaper tiers hold the same data.
- Free data goes unused. Defender XDR alerts and incidents are free and Microsoft 365 E5 grants a daily data allowance, yet two of three workspaces paid for that data anyway.
- Size tiers to sustained volume. Commitment tiers run from 100 GB to 50,000 GB per day, and a tier bought for the worst week is paid for every week.
- Retention is a separate decision. The first 90 days are included, and longer retention bills on its own curve at Log Analytics or data lake rates.
How is Microsoft Sentinel priced in 2026?
Microsoft Sentinel is billed per gigabyte of data you ingest and analyze. There is no per seat or per user license, and feature choice, connector count and the number of analytics rules carry no license fee at all.
Workspaces created since July 2023 default to the simplified pricing tier, which puts the Log Analytics ingestion charge and the Sentinel analysis charge on one meter. Older workspaces may still show both charges under the classic tiers. The combined meter is easier to read but does not change what drives the total.
| Element | How it bills | What to watch |
|---|---|---|
| Analytics tier, pay as you go | $4.30 per GB ingested and analyzed | The only variable that changes the total materially |
| Analytics tier, commitment tiers | Fixed daily price, from 100 GB per day ($296 a day) to 50,000 GB per day | Up to 52 percent below pay as you go at the top tier; raise any time, lower only every 31 days |
| Basic and auxiliary logs, Sentinel data lake tier | Far less than the analytics tier; data lake ingestion lists at $0.05 per GB | Where verbose sources belong when no detection rule needs them |
| Defender XDR alerts and incidents | Free | Covers alerts and incidents only; raw Defender and Entra ID logs are paid |
| Microsoft 365 E5 data grant | Up to 5 MB per user per day free | Covers named Microsoft data types only |
| Retention | First 90 days included; standard Log Analytics rates after that | A separate cost line from ingestion |
What carries no license fee?
Nothing in that table is a license you negotiate. Enabling UEBA, adding a fortieth connector or writing another hundred rules costs nothing extra. The invoice is set by which sources land in which tier, a choice security engineering usually makes far from the people who read the bill.
Which data ingests for free?
Microsoft publishes a short list of sources that never touch the paid meter, plus a grant for E5 customers. Both are entitlements you already hold:
- Always free. Azure Activity logs, Office 365 audit logs (SharePoint, Exchange admin and Teams), Sentinel health data, and alerts and incidents from Defender XDR, Defender for Endpoint, Identity, Office 365, Cloud Apps and Cloud.
- Covered by the E5 grant. Entra ID sign in and audit logs, Defender for Cloud Apps discovery logs, Purview Information Protection logs and Microsoft 365 advanced hunting data. Microsoft 365 E7, A5, F5 and G5 qualify on the same terms.
- Not covered by anything. Firewall, proxy, DNS, third party EDR and server logs, which are usually the largest tables in the workspace.
Microsoft applies the E5 grant automatically, but only to the listed data types. Entra or Defender data forwarded through a third party collector into a custom table does not count, and advanced hunting data above the allowance bills at the normal rate.
Microsoft EA: Where the Leverage Really Is, and the Mistakes That Give It Away
Why can a better discount not fix a Sentinel bill?
A lower unit rate cannot rescue a workspace that routes everything into the analytics tier. In most enterprise software, a cost problem turns out to be a contract problem. Sentinel runs the other way, because the rates are published and the volume you send decides the invoice.
So the two functions that set the bill rarely meet. Procurement negotiates a rate against a volume it does not control. Security engineering picks the volume without seeing what each choice costs, often while standing up connectors under time pressure.
If nearly half the bill can be removed without weakening detection, then nearly half the bill was buying no security, and no discount on the unit rate would have found it.
The saving we measured from ingestion tuning is the size of that gap. Detection coverage did not drop, which is what makes the finding decisive. Volume you can remove without losing a detection was never contributing to one.
Why a bigger commitment tier is the wrong first step
The usual advice, often from the account team, is to step up a commitment tier to cut the per GB rate. We disagree when it comes first. A tier bought on today's volume locks in data that arrived by default, and it stays locked for at least a month. Fix the routing, let volume settle, then buy the tier.
How Sentinel spend sits next to your Azure commitment and E5 decisions is covered across our Microsoft practice library.
Microsoft EA Renewal Guide
The renewal preparation guide from our Microsoft practice, covering E5, Copilot, Azure commitments and contract terms.
Get the white paper →Where does the ingestion tuning saving come from?
It comes from five routing and sizing changes, none of which touches a detection rule. The first usually matters most, because verbose sources drove most of the bill:
- Move verbose firewall, proxy and endpoint sources out of the analytics tier. The lower cost tiers hold the same data for a fraction of the price.
- Turn on the free Defender ingestion paths. Defender XDR alerts and incidents ingest at no charge through the native connector.
- Collect the Microsoft 365 E5 grant. Route Entra ID and Defender data through native connectors so the allowance applies.
- Size the commitment tier to sustained volume. A tier bought for the worst week is paid for every week of the year.
- Decide long term retention separately. Long tail storage bills at standard Log Analytics rates on its own curve.
Which logs belong outside the analytics tier?
Microsoft's own guidance names firewall, proxy, NetFlow, cloud storage access, TLS certificate and IoT logs as secondary data suited to the lower tier. Apply one test. If no analytics rule reads a table and analysts query it only during investigations, it does not need analytics pricing.
Keep the slice that feeds detections, such as firewall deny events and threat intelligence matches, in the analytics tier. Send the full allowed traffic record to the lower tier, and use KQL jobs or summary rules to lift aggregates back when a rule needs them.
How do the free paths go unused?
They usually go unused because of how the data arrives. The free and granted treatment applies only to data that lands in Microsoft's own tables, such as SecurityAlert or SigninLogs. Data sent through syslog or a third party forwarder lands in a custom table and bills in full.
How much does sizing to peak cost?
You pay the tier price every day whether you reach it or not. Overage bills at the tier's discounted rate, so a tier at or just below sustained volume usually beats one bought for the peak.
Smaller workspaces have a new option. Microsoft put a 50 GB per day tier into public preview on October 1, 2025, and buyers who sign up by December 31, 2026 keep its promotional price until March 31, 2027.
When does retention become its own problem?
Once the included period ends, analytics tier data bills at Log Analytics retention rates, $0.10 per GB per month in East US, for up to two years. The data lake tier holds data for up to 12 years at $0.026 per GB per month on compressed data. Give retention its own owner and review.
What does ingestion tuning save in a real bill?
Take a hypothetical company with 3,000 Microsoft 365 E5 users, ingesting 600 GB a day into the analytics tier on a 500 GB per day commitment tier. We use East US list prices. Your region and Azure discounts will change the dollar figures, while the proportions hold.
| Source | Before | After | What changed |
|---|---|---|---|
| Firewall and proxy | 260 analytics | 60 analytics, 200 data lake | Allowed traffic records moved; deny and threat events kept for rules |
| Endpoint telemetry | 120 analytics | 80 analytics | 40 GB of low value event types filtered by a data collection rule |
| Entra ID and Defender data | 40 analytics, via a third party forwarder | 40 analytics, via native connectors | 15 GB now covered by the E5 grant (3,000 users x 5 MB) |
| Windows security events and other | 180 analytics | 180 analytics | Unchanged |
| Billable analytics volume | 600 | 345 | Grant and routing |
Before: the 500 GB tier costs $1,265 a day, an effective $2.53 per GB. The extra 100 GB adds $253, so the workspace costs $1,518 a day, or $554,070 a year.
After: 345 GB fits a 300 GB tier at $800 a day ($2.67 per GB) plus $120 for 45 GB of overage. The 200 GB in the data lake costs $0.05 per GB to ingest plus $0.10 per GB for the transformation that splits it off, $30 a day. The total is $950 a day, or $346,750 a year.
- Annual saving. $207,320, about 37 percent, with the same analytics rules running.
- The cost of sizing to peak. A 1,000 GB tier bought for the busiest weeks would cost $2,480 a day, $905,200 a year, which is $351,130 more than the 500 GB tier for the same data.
- What the example leaves out. Data lake storage, which Microsoft bills on data compressed 6 to 1. A year of the 200 GB feed comes to about 12,200 GB stored, roughly $316 a month once the year has built up.
- The tier discount alone. The 100 GB tier at $296 a day is 31 percent below 100 GB at pay as you go ($430), but it discounts whatever you send, useful or not.
What have we seen in recent Microsoft Sentinel cost reviews?
Across roughly 20 to 30 Microsoft Sentinel cost reviews we advised in 2024 and 2025, the bill almost always traced back to undisciplined ingestion rather than the unit rate. Tuning alone removed 25 to 45 percent of cost with no loss of detection coverage. Three patterns recurred:
- Verbose sources at full rate. Network and endpoint logs in the analytics tier drove most of the bill, routed there while connectors were stood up in a hurry.
- Free paths left unused. Roughly two of three workspaces paid analytics rates for Defender data that ingests at no charge.
- Tiers bought for the worst week. Sizing to peak rather than sustained volume locked the inflated number in for the year.
How the review changes with company size
| Situation | Typical choice | What to check first |
|---|---|---|
| 800 E5 users, about 40 GB a day | Pay as you go ($172 a day before the grant) or the 50 GB preview tier ($161.25 a day) | The 4 GB daily E5 grant, and what the 50 GB tier costs once the promotional price ends on March 31, 2027 |
| 3,000 E5 users, 300 to 600 GB a day | 100 GB to 500 GB commitment tiers | Firewall and endpoint routing, as in the worked example |
| 25,000 E5 users, 2,000 GB a day or more | 2,000 GB tier ($4,800 a day) and above | A 125 GB daily grant, and whether several workspaces could share a dedicated cluster tier |
How do you check what your Sentinel workspace is ingesting?
Start with the workspace's own records. It logs what it bills, table by table, and Microsoft provides the views to read it:
- The Usage table. Query it for the last 30 days, filter to billable data, and sum Quantity (in MB) by DataType for a ranked list of the tables behind the bill.
- The _BilledSize column. Every billable record carries it, so you can split a large table by device or event type before deciding what to filter.
- The Workspace Usage Report workbook. From the Sentinel content hub, it charts ingestion by table over time and shows whether your peaks last a week or a season.
- SOC optimization in the Defender portal. Its data value recommendations flag tables that no analytics rule uses.
Plan the portal change at the same time. Microsoft will stop supporting Sentinel in the Azure portal after March 31, 2027, and table tier settings sit in the Defender portal. Our Sentinel optimization guide sets out the tuning sequence.
What will the Microsoft account team say about Sentinel costs?
Expect the conversation to push volume and commitment upward. These lines come up most often:
- "Step up a commitment tier and your per GB rate drops." Reply with your 30 day median volume after the routing changes, and step up only once that number has held for a full billing month.
- "Bring every source in so the analytics have full context." Ask which rules would read each new table. Sources with no rule go to the data lake tier.
- "Your E5 licenses cover Sentinel ingestion." They cover a daily allowance of named Microsoft data. Firewall, proxy, DNS and third party logs are not on the list.
- "Commit the Sentinel spend inside your Azure consumption commitment." Size that commitment on post tuning volume. Our MACC sizing guide covers how to avoid committing to consumption you plan to remove.
Common mistakes that keep the bill high
- Accepting connector defaults. Data lands in the analytics tier unless you change the table plan or add a transformation.
- Negotiating before measuring. A rate agreed before the routing review fixes the wrong number for a year.
- Treating E5 as a Sentinel license. The grant is a capped data allowance and does not touch third party sources; see whether E5 Security is worth the upgrade for how it fits the wider case.
- Keeping firewall data in analytics retention for compliance. Two years at analytics rates costs far more than the data lake tier for the same rule.
What to do next
- Put security engineering and procurement in one review. One function chooses the volume and the other negotiates the price, so give both the per tier rates and the table volumes.
- Rank your tables by billed volume. Use the Usage table and the Workspace Usage Report workbook to list the ten largest sources and the rules that read each one.
- Move verbose sources out of the analytics tier. Send firewall, proxy and endpoint records that no rule reads to basic, auxiliary or data lake storage.
- Switch on the free Defender paths and collect the E5 grant. Replace forwarders with native connectors so Microsoft data stops being paid for twice.
- Fix the routing before you renegotiate anything. A good unit price cannot rescue a workspace that ingests everything at full analytics rates.
- Size the commitment tier to sustained volume. Wait for 30 days of post change data, then buy the tier and settle long term retention as a separate decision. The Microsoft practice runs the ingestion review with you.
Is a Microsoft renewal or new agreement coming up? Our Microsoft EA negotiation team works only for buyers, for a fixed fee or 25 percent of what we save you.
Frequently asked questions
How is Microsoft Sentinel priced in 2026?
Per gigabyte ingested and analyzed, with no per seat license. Classic workspaces show a Log Analytics ingestion charge and a Sentinel analysis charge separately. The simplified tier, the default since July 2023, combines them on one meter listed at $4.30 per GB pay as you go in East US.
Can a better discount fix a Sentinel bill?
Rarely. Commitment tier discounts are published, and there is no seat count or feature bundle to trade, so procurement has little to win on price. The savings sit in the volume, so the architecture review has to come before any commercial conversation with Microsoft or your reseller.
How much can ingestion tuning actually save?
Between 25 and 45 percent in the reviews we advised, with detection coverage unchanged. Your result depends on how much verbose network and endpoint data sits in the analytics tier today, so rank your tables by billed volume before you estimate.
What drives most of the overrun?
Full volume firewall, proxy and endpoint logs in the analytics tier. Those sources are large, and most of their records are read only during investigations. Keeping the detection slice in analytics and sending the rest to basic, auxiliary or data lake storage cuts the cost of that data sharply.
What ingests for free?
Defender XDR alerts and incidents, Azure Activity logs, Office 365 audit logs and Sentinel health data never touch the paid meter. Microsoft 365 E5, A5, F5 and G5 customers also get up to 5 MB per user per day of Entra ID, advanced hunting and similar Microsoft data at no charge.
How should the commitment tier be sized?
On sustained daily volume, measured once the routing changes have settled. A slightly smaller tier costs little extra in a busy week because overage bills at the discounted rate. You can raise a tier whenever you like, but Microsoft allows a reduction only once every 31 days.
Does retention affect the bill separately?
Yes. Analytics data keeps 90 days of retention at no charge, then bills at standard Log Analytics retention rates for as long as you keep it, up to two years. Long compliance storage belongs in the data lake tier, which holds data for up to 12 years at a much lower monthly rate.
Is Microsoft Sentinel included in Microsoft 365 E5?
No. Sentinel is billed on consumption through Azure, so there is no Sentinel license for E5 to contain. E5 provides a data grant that offsets ingestion of specific Microsoft sources. Third party security logs and anything above the grant bill at normal Sentinel rates.