Analyst working across several data screens
Microsoft Sentinel

Microsoft Sentinel pricing in 2026. The bill is set by where your logs land.

How the Sentinel meter reads, what ingests for free, how to size a commitment tier, and where ingestion tuning removes a quarter to nearly half of the cost.

Contact Us Microsoft Advisory
500+Enterprise clients
$2B+Under advisory
PublishedFebruary 20, 2024UpdatedSeptember 24, 2026
ContentsKey takeawaysHow Sentinel is pricedWhy discounts do not fix itWhere the saving comes fromA worked exampleWhat we have seenCheck your own ingestionWhat Microsoft will sayWhat to do nextFAQ

Sentinel bills per gigabyte ingested, with no seat license, so the invoice follows your routing choices. In our reviews, ingestion tuning removed close to half the cost in some workspaces without losing a detection, which no unit rate discount would have found.

Key takeaways
  • Priced on volume. Sentinel charges per GB ingested and analyzed, and features, connectors and analytics rules carry no license fee.
  • Tuning beats discounts. Moving and filtering ingestion removed up to 45 percent of cost with no loss of detection coverage, so that spend was buying no security.
  • Verbose logs drive the bill. Firewall, proxy and endpoint logs at full analytics rates made up most of the overruns we saw, and cheaper tiers hold the same data.
  • Free data goes unused. Defender XDR alerts and incidents are free and Microsoft 365 E5 grants a daily data allowance, yet two of three workspaces paid for that data anyway.
  • Size tiers to sustained volume. Commitment tiers run from 100 GB to 50,000 GB per day, and a tier bought for the worst week is paid for every week.
  • Retention is a separate decision. The first 90 days are included, and longer retention bills on its own curve at Log Analytics or data lake rates.

How is Microsoft Sentinel priced in 2026?

Microsoft Sentinel is billed per gigabyte of data you ingest and analyze. There is no per seat or per user license, and feature choice, connector count and the number of analytics rules carry no license fee at all.

Workspaces created since July 2023 default to the simplified pricing tier, which puts the Log Analytics ingestion charge and the Sentinel analysis charge on one meter. Older workspaces may still show both charges under the classic tiers. The combined meter is easier to read but does not change what drives the total.

What each part of the Sentinel meter charges (US list prices, East US region, September 2026)
ElementHow it billsWhat to watch
Analytics tier, pay as you go$4.30 per GB ingested and analyzedThe only variable that changes the total materially
Analytics tier, commitment tiersFixed daily price, from 100 GB per day ($296 a day) to 50,000 GB per dayUp to 52 percent below pay as you go at the top tier; raise any time, lower only every 31 days
Basic and auxiliary logs, Sentinel data lake tierFar less than the analytics tier; data lake ingestion lists at $0.05 per GBWhere verbose sources belong when no detection rule needs them
Defender XDR alerts and incidentsFreeCovers alerts and incidents only; raw Defender and Entra ID logs are paid
Microsoft 365 E5 data grantUp to 5 MB per user per day freeCovers named Microsoft data types only
RetentionFirst 90 days included; standard Log Analytics rates after thatA separate cost line from ingestion

What carries no license fee?

Nothing in that table is a license you negotiate. Enabling UEBA, adding a fortieth connector or writing another hundred rules costs nothing extra. The invoice is set by which sources land in which tier, a choice security engineering usually makes far from the people who read the bill.

Which data ingests for free?

Microsoft publishes a short list of sources that never touch the paid meter, plus a grant for E5 customers. Both are entitlements you already hold:

  • Always free. Azure Activity logs, Office 365 audit logs (SharePoint, Exchange admin and Teams), Sentinel health data, and alerts and incidents from Defender XDR, Defender for Endpoint, Identity, Office 365, Cloud Apps and Cloud.
  • Covered by the E5 grant. Entra ID sign in and audit logs, Defender for Cloud Apps discovery logs, Purview Information Protection logs and Microsoft 365 advanced hunting data. Microsoft 365 E7, A5, F5 and G5 qualify on the same terms.
  • Not covered by anything. Firewall, proxy, DNS, third party EDR and server logs, which are usually the largest tables in the workspace.

Microsoft applies the E5 grant automatically, but only to the listed data types. Entra or Defender data forwarded through a third party collector into a custom table does not count, and advanced hunting data above the allowance bills at the normal rate.

Watch the briefingResearch briefing · 4:06

Microsoft EA: Where the Leverage Really Is, and the Mistakes That Give It Away

Why can a better discount not fix a Sentinel bill?

A lower unit rate cannot rescue a workspace that routes everything into the analytics tier. In most enterprise software, a cost problem turns out to be a contract problem. Sentinel runs the other way, because the rates are published and the volume you send decides the invoice.

So the two functions that set the bill rarely meet. Procurement negotiates a rate against a volume it does not control. Security engineering picks the volume without seeing what each choice costs, often while standing up connectors under time pressure.

If nearly half the bill can be removed without weakening detection, then nearly half the bill was buying no security, and no discount on the unit rate would have found it.

The saving we measured from ingestion tuning is the size of that gap. Detection coverage did not drop, which is what makes the finding decisive. Volume you can remove without losing a detection was never contributing to one.

Why a bigger commitment tier is the wrong first step

The usual advice, often from the account team, is to step up a commitment tier to cut the per GB rate. We disagree when it comes first. A tier bought on today's volume locks in data that arrived by default, and it stays locked for at least a month. Fix the routing, let volume settle, then buy the tier.

How Sentinel spend sits next to your Azure commitment and E5 decisions is covered across our Microsoft practice library.

Free white paper

Microsoft EA Renewal Guide

The renewal preparation guide from our Microsoft practice, covering E5, Copilot, Azure commitments and contract terms.

Get the white paper →

Where does the ingestion tuning saving come from?

It comes from five routing and sizing changes, none of which touches a detection rule. The first usually matters most, because verbose sources drove most of the bill:

  1. Move verbose firewall, proxy and endpoint sources out of the analytics tier. The lower cost tiers hold the same data for a fraction of the price.
  2. Turn on the free Defender ingestion paths. Defender XDR alerts and incidents ingest at no charge through the native connector.
  3. Collect the Microsoft 365 E5 grant. Route Entra ID and Defender data through native connectors so the allowance applies.
  4. Size the commitment tier to sustained volume. A tier bought for the worst week is paid for every week of the year.
  5. Decide long term retention separately. Long tail storage bills at standard Log Analytics rates on its own curve.

Which logs belong outside the analytics tier?

Microsoft's own guidance names firewall, proxy, NetFlow, cloud storage access, TLS certificate and IoT logs as secondary data suited to the lower tier. Apply one test. If no analytics rule reads a table and analysts query it only during investigations, it does not need analytics pricing.

Keep the slice that feeds detections, such as firewall deny events and threat intelligence matches, in the analytics tier. Send the full allowed traffic record to the lower tier, and use KQL jobs or summary rules to lift aggregates back when a rule needs them.

Network switches and cabling in a technical facility
Perimeter and network devices log every allowed connection, not only the suspicious ones. Most of those records are read only when an investigation reaches back for them, which is the use the data lake tier is priced for.

How do the free paths go unused?

They usually go unused because of how the data arrives. The free and granted treatment applies only to data that lands in Microsoft's own tables, such as SecurityAlert or SigninLogs. Data sent through syslog or a third party forwarder lands in a custom table and bills in full.

How much does sizing to peak cost?

You pay the tier price every day whether you reach it or not. Overage bills at the tier's discounted rate, so a tier at or just below sustained volume usually beats one bought for the peak.

Smaller workspaces have a new option. Microsoft put a 50 GB per day tier into public preview on October 1, 2025, and buyers who sign up by December 31, 2026 keep its promotional price until March 31, 2027.

When does retention become its own problem?

Once the included period ends, analytics tier data bills at Log Analytics retention rates, $0.10 per GB per month in East US, for up to two years. The data lake tier holds data for up to 12 years at $0.026 per GB per month on compressed data. Give retention its own owner and review.

What does ingestion tuning save in a real bill?

Take a hypothetical company with 3,000 Microsoft 365 E5 users, ingesting 600 GB a day into the analytics tier on a 500 GB per day commitment tier. We use East US list prices. Your region and Azure discounts will change the dollar figures, while the proportions hold.

Hypothetical workspace before and after routing changes (GB per day)
SourceBeforeAfterWhat changed
Firewall and proxy260 analytics60 analytics, 200 data lakeAllowed traffic records moved; deny and threat events kept for rules
Endpoint telemetry120 analytics80 analytics40 GB of low value event types filtered by a data collection rule
Entra ID and Defender data40 analytics, via a third party forwarder40 analytics, via native connectors15 GB now covered by the E5 grant (3,000 users x 5 MB)
Windows security events and other180 analytics180 analyticsUnchanged
Billable analytics volume600345Grant and routing

Before: the 500 GB tier costs $1,265 a day, an effective $2.53 per GB. The extra 100 GB adds $253, so the workspace costs $1,518 a day, or $554,070 a year.

After: 345 GB fits a 300 GB tier at $800 a day ($2.67 per GB) plus $120 for 45 GB of overage. The 200 GB in the data lake costs $0.05 per GB to ingest plus $0.10 per GB for the transformation that splits it off, $30 a day. The total is $950 a day, or $346,750 a year.

  • Annual saving. $207,320, about 37 percent, with the same analytics rules running.
  • The cost of sizing to peak. A 1,000 GB tier bought for the busiest weeks would cost $2,480 a day, $905,200 a year, which is $351,130 more than the 500 GB tier for the same data.
  • What the example leaves out. Data lake storage, which Microsoft bills on data compressed 6 to 1. A year of the 200 GB feed comes to about 12,200 GB stored, roughly $316 a month once the year has built up.
  • The tier discount alone. The 100 GB tier at $296 a day is 31 percent below 100 GB at pay as you go ($430), but it discounts whatever you send, useful or not.

What have we seen in recent Microsoft Sentinel cost reviews?

Across roughly 20 to 30 Microsoft Sentinel cost reviews we advised in 2024 and 2025, the bill almost always traced back to undisciplined ingestion rather than the unit rate. Tuning alone removed 25 to 45 percent of cost with no loss of detection coverage. Three patterns recurred:

  • Verbose sources at full rate. Network and endpoint logs in the analytics tier drove most of the bill, routed there while connectors were stood up in a hurry.
  • Free paths left unused. Roughly two of three workspaces paid analytics rates for Defender data that ingests at no charge.
  • Tiers bought for the worst week. Sizing to peak rather than sustained volume locked the inflated number in for the year.

How the review changes with company size

How the Sentinel cost review shifts with scale
SituationTypical choiceWhat to check first
800 E5 users, about 40 GB a dayPay as you go ($172 a day before the grant) or the 50 GB preview tier ($161.25 a day)The 4 GB daily E5 grant, and what the 50 GB tier costs once the promotional price ends on March 31, 2027
3,000 E5 users, 300 to 600 GB a day100 GB to 500 GB commitment tiersFirewall and endpoint routing, as in the worked example
25,000 E5 users, 2,000 GB a day or more2,000 GB tier ($4,800 a day) and aboveA 125 GB daily grant, and whether several workspaces could share a dedicated cluster tier

How do you check what your Sentinel workspace is ingesting?

Start with the workspace's own records. It logs what it bills, table by table, and Microsoft provides the views to read it:

  • The Usage table. Query it for the last 30 days, filter to billable data, and sum Quantity (in MB) by DataType for a ranked list of the tables behind the bill.
  • The _BilledSize column. Every billable record carries it, so you can split a large table by device or event type before deciding what to filter.
  • The Workspace Usage Report workbook. From the Sentinel content hub, it charts ingestion by table over time and shows whether your peaks last a week or a season.
  • SOC optimization in the Defender portal. Its data value recommendations flag tables that no analytics rule uses.

Plan the portal change at the same time. Microsoft will stop supporting Sentinel in the Azure portal after March 31, 2027, and table tier settings sit in the Defender portal. Our Sentinel optimization guide sets out the tuning sequence.

What will the Microsoft account team say about Sentinel costs?

Expect the conversation to push volume and commitment upward. These lines come up most often:

  • "Step up a commitment tier and your per GB rate drops." Reply with your 30 day median volume after the routing changes, and step up only once that number has held for a full billing month.
  • "Bring every source in so the analytics have full context." Ask which rules would read each new table. Sources with no rule go to the data lake tier.
  • "Your E5 licenses cover Sentinel ingestion." They cover a daily allowance of named Microsoft data. Firewall, proxy, DNS and third party logs are not on the list.
  • "Commit the Sentinel spend inside your Azure consumption commitment." Size that commitment on post tuning volume. Our MACC sizing guide covers how to avoid committing to consumption you plan to remove.

Common mistakes that keep the bill high

  • Accepting connector defaults. Data lands in the analytics tier unless you change the table plan or add a transformation.
  • Negotiating before measuring. A rate agreed before the routing review fixes the wrong number for a year.
  • Treating E5 as a Sentinel license. The grant is a capped data allowance and does not touch third party sources; see whether E5 Security is worth the upgrade for how it fits the wider case.
  • Keeping firewall data in analytics retention for compliance. Two years at analytics rates costs far more than the data lake tier for the same rule.

What to do next

  1. Put security engineering and procurement in one review. One function chooses the volume and the other negotiates the price, so give both the per tier rates and the table volumes.
  2. Rank your tables by billed volume. Use the Usage table and the Workspace Usage Report workbook to list the ten largest sources and the rules that read each one.
  3. Move verbose sources out of the analytics tier. Send firewall, proxy and endpoint records that no rule reads to basic, auxiliary or data lake storage.
  4. Switch on the free Defender paths and collect the E5 grant. Replace forwarders with native connectors so Microsoft data stops being paid for twice.
  5. Fix the routing before you renegotiate anything. A good unit price cannot rescue a workspace that ingests everything at full analytics rates.
  6. Size the commitment tier to sustained volume. Wait for 30 days of post change data, then buy the tier and settle long term retention as a separate decision. The Microsoft practice runs the ingestion review with you.
When to bring in help

Is a Microsoft renewal or new agreement coming up? Our Microsoft EA negotiation team works only for buyers, for a fixed fee or 25 percent of what we save you.

Frequently asked questions

How is Microsoft Sentinel priced in 2026?

Per gigabyte ingested and analyzed, with no per seat license. Classic workspaces show a Log Analytics ingestion charge and a Sentinel analysis charge separately. The simplified tier, the default since July 2023, combines them on one meter listed at $4.30 per GB pay as you go in East US.

Can a better discount fix a Sentinel bill?

Rarely. Commitment tier discounts are published, and there is no seat count or feature bundle to trade, so procurement has little to win on price. The savings sit in the volume, so the architecture review has to come before any commercial conversation with Microsoft or your reseller.

How much can ingestion tuning actually save?

Between 25 and 45 percent in the reviews we advised, with detection coverage unchanged. Your result depends on how much verbose network and endpoint data sits in the analytics tier today, so rank your tables by billed volume before you estimate.

What drives most of the overrun?

Full volume firewall, proxy and endpoint logs in the analytics tier. Those sources are large, and most of their records are read only during investigations. Keeping the detection slice in analytics and sending the rest to basic, auxiliary or data lake storage cuts the cost of that data sharply.

What ingests for free?

Defender XDR alerts and incidents, Azure Activity logs, Office 365 audit logs and Sentinel health data never touch the paid meter. Microsoft 365 E5, A5, F5 and G5 customers also get up to 5 MB per user per day of Entra ID, advanced hunting and similar Microsoft data at no charge.

How should the commitment tier be sized?

On sustained daily volume, measured once the routing changes have settled. A slightly smaller tier costs little extra in a busy week because overage bills at the discounted rate. You can raise a tier whenever you like, but Microsoft allows a reduction only once every 31 days.

Does retention affect the bill separately?

Yes. Analytics data keeps 90 days of retention at no charge, then bills at standard Log Analytics retention rates for as long as you keep it, up to two years. Long compliance storage belongs in the data lake tier, which holds data for up to 12 years at a much lower monthly rate.

Is Microsoft Sentinel included in Microsoft 365 E5?

No. Sentinel is billed on consumption through Azure, so there is no Sentinel license for E5 to contain. E5 provides a data grant that offsets ingestion of specific Microsoft sources. Third party security logs and anything above the grant bill at normal Sentinel rates.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the Microsoft EA Renewal Guide.

How to prepare a Microsoft renewal, from E5 and Copilot decisions to Azure commitments and the terms worth asking for.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

Microsoft licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.