Independent cost reference. Not affiliated with any security vendor or MSSP.

Microsoft Sentinel Cost 2026: Pricing per GB and M365 Free Tier

Microsoft Sentinel pricing is anchored on Azure consumption ($4.30/GB list) plus a Microsoft-shop discount: Azure Activity logs, Office 365 audit logs, and Defender alerts ingest free (though Entra ID sign-in logs do not). Here is the full TCO picture including commitment tiers, archive storage, and when Sentinel beats Splunk.

Quick Answer

Sentinel list price is $4.30/GB consumption, dropping to $2.48/GB at 1 TB/day commitment. Azure Activity logs, O365 audit logs, and Defender alerts ingest free (Entra ID sign-in logs are paid).

$15K - $80K

SMB Microsoft shop (under 30 GB/day non-M365)

$60K - $200K

Mid-market (50-100 GB/day commit)

$200K - $1.5M+

Enterprise (500+ GB/day commit)

Sentinel commitment tier pricing

CommitmentIndicative per-GB rateMonthly cost (at commit)Best fit
Pay-as-you-go$4.30/GBVariableSub-30 GB/day, variable volume
100 GB/day~$2.96/GB~$8.9KMid-market entry
200 GB/day~$2.74/GB~$16.4KMid-market mature
500 GB/day~$2.53/GB~$38KLarge mid-market / small enterprise
1 TB/day~$2.48/GB~$74KEnterprise
2 TB/dayCustomCustomLarge enterprise

Indicative rates per Microsoft Azure public pricing page. Subject to Microsoft enterprise agreement discounts and regional surcharges. Always verify with Azure cost management before committing.

M365 free-tier ingestion (the major Sentinel wedge)

A defined set of Microsoft-native sources is free to ingest into Sentinel (per Microsoft's published free-data-sources list). The free-ingest sources are:

  • Azure Activity logs (all customers, no licence required)
  • Office 365 audit logs (Exchange Online, SharePoint Online, OneDrive, Teams)
  • Microsoft Defender XDR security alerts (Defender for Endpoint, Identity, Office 365)
  • Microsoft Defender for Cloud and Defender for Cloud Apps security alerts
  • Microsoft Sentinel health logs

Not free, despite the common assumption: Microsoft Entra ID (Azure AD) sign-in and audit logs, and the raw advanced-hunting tables from Defender for Endpoint and Identity, are billed at the standard per-GB rate. Only the alerts from those products are free, not the underlying raw logs. Microsoft 365 E5 / A5 / F5 / G5 licences include a capped daily data grant (per user) that can offset some of the paid Entra ID and Defender volume.

For Microsoft-shop SOCs the free alert and Office 365 ingestion lowers the SIEM bill versus a comparable Splunk or Elastic deployment ingesting the same data at full per-GB rate. The saving is real but often overstated: the highest-volume Microsoft sources (Entra ID sign-in logs, raw endpoint telemetry) are paid, so free ingestion trims the bill rather than collapsing it. Combined with its native Azure integration, this is a structural reason Sentinel has won broad adoption in Microsoft-centric enterprises despite Splunk's deeper query language and longer market history.

When Sentinel is the right call

Sentinel wins when

  • Microsoft-shop estate (M365, Azure, Defender are bulk of telemetry)
  • Variable log volume and want pay-as-you-go without minimums
  • Azure-native infrastructure where Sentinel-Logic Apps-Notebooks integration replaces SOAR purchase
  • Strong Azure cost-management discipline and existing EA discount
  • Compliance archive needs (Sentinel archive tier is cost-efficient)

Look elsewhere when

  • AWS-shop or GCP-shop where Sentinel pulls cross-cloud data through brittle connectors
  • Splunk-skill team where Sentinel KQL retraining cost is significant
  • Heterogeneous non-Microsoft estate where free M365 ingest does not apply
  • High-query workloads where Splunk Workload Pricing fits better
  • Compliance regimes that require on-premises log control beyond Azure region residency

Related cost references

Frequently Asked Questions

How much does Microsoft Sentinel cost?
Microsoft Sentinel uses Azure consumption pricing at $4.30 per GB ingested (US East simplified-tier list price). Volume commitment tiers discount this rate: 100 GB/day commitment works out around $2.96/GB, 200 GB/day around $2.74/GB, 1 TB/day around $2.48/GB. Several Microsoft-native sources are free to ingest: Azure Activity logs, Office 365 audit logs (Exchange, SharePoint, Teams), and the security alerts from Microsoft Defender XDR. Note the common budgeting trap: Microsoft Entra ID (Azure AD) sign-in and audit logs and the raw advanced-hunting tables from Defender for Endpoint and Identity are billed at the standard rate; only the alerts are free. The free alert and Office 365 ingestion is still a differentiator versus Splunk, where the same data would carry full ingest cost.
What logs are free to ingest in Microsoft Sentinel?
The free-ingest sources are Azure Activity logs, Office 365 audit logs (Exchange, SharePoint, Teams), and the security alerts from Microsoft Defender XDR, Defender for Cloud, and Defender for Cloud Apps. The caveat that trips up budgets: Microsoft Entra ID (Azure AD) sign-in and audit logs, and the raw advanced-hunting tables from Defender for Endpoint and Identity, are paid at the standard rate. Only the Defender alerts are free, not the underlying raw logs. M365 E5 / A5 / F5 / G5 licences add a capped daily data grant (per user) that can offset some of the paid Entra ID and Defender telemetry. For a Microsoft-shop SOC the free alert and Office 365 ingestion still cuts the bill versus a third-party SIEM, but the saving is often overstated because the highest-volume Microsoft sources (Entra ID sign-in logs, raw endpoint telemetry) are paid. Non-Microsoft logs (network appliances, third-party SaaS, on-prem servers) are at the standard $4.30/GB rate.
What are the Microsoft Sentinel commitment tiers?
Microsoft offers commitment tier pricing for predictable volumes: 100 GB/day, 200 GB/day, 300 GB/day, 400 GB/day, 500 GB/day, 1 TB/day, and 2 TB/day. Each tier discounts the per-GB rate progressively. Commitment is monthly and overage above the committed volume reverts to pay-as-you-go. Typical Microsoft-shop mid-market SOC commits at 100-200 GB/day; large enterprise commits at 1 TB/day.
Does Microsoft Sentinel include long-term storage?
Sentinel data retention is 90 days included with ingest cost, then $0.10/GB/month for archived (interactive) data and cheaper for archive tier. For PCI DSS 12-month retention or HIPAA 6-year retention, archive-tier storage is the cost-efficient path. Sentinel archive supports search and rehydration of archived data for incident response. Microsoft Defender XDR alerts have separate retention rules and feed into Sentinel without the standard ingest meter.
When does Microsoft Sentinel beat Splunk on total cost?
Sentinel beats Splunk on TCO in three patterns. (1) Microsoft-shop estates where M365 + Azure + Defender logs are the bulk of telemetry; free ingestion of those logs collapses the cost base. (2) SOCs that want consumption-billing predictability and have variable log volumes (Sentinel's pay-as-you-go has no minimum commitment, unlike Splunk Cloud). (3) Azure-native infrastructure where the Sentinel-Logic Apps-Sentinel Notebooks integration replaces a separate SOAR purchase. Sentinel loses to Splunk on non-Microsoft heterogeneous estates with high-query workloads where Workload Pricing fits.

Microsoft Sentinel rates verified against the Azure Retail Prices API (prices.azure.com, US East, simplified pricing tier) in June 2026: Pay-as-you-go Analysis $4.30/GB; 100 GB/day $296/day; 200 GB/day $548/day; 500 GB/day $1,265/day; 1 TB/day $2,480/day. Per-GB and monthly figures derived from those daily reservation rates. No per-customer EA-discounted pricing cited. SecurityOperationsCost.com has no commercial relationship with Microsoft.

Updated 2026-06-09