Microsoft Sentinel Cost 2026: Pricing per GB and M365 Free Tier
Microsoft Sentinel pricing is anchored on Azure consumption ($4.30/GB list) plus a Microsoft-shop discount: Azure Activity logs, Office 365 audit logs, and Defender alerts ingest free (though Entra ID sign-in logs do not). Here is the full TCO picture including commitment tiers, archive storage, and when Sentinel beats Splunk.
Quick Answer
Sentinel list price is $4.30/GB consumption, dropping to $2.48/GB at 1 TB/day commitment. Azure Activity logs, O365 audit logs, and Defender alerts ingest free (Entra ID sign-in logs are paid).
$15K - $80K
SMB Microsoft shop (under 30 GB/day non-M365)
$60K - $200K
Mid-market (50-100 GB/day commit)
$200K - $1.5M+
Enterprise (500+ GB/day commit)
Sentinel commitment tier pricing
| Commitment | Indicative per-GB rate | Monthly cost (at commit) | Best fit |
|---|---|---|---|
| Pay-as-you-go | $4.30/GB | Variable | Sub-30 GB/day, variable volume |
| 100 GB/day | ~$2.96/GB | ~$8.9K | Mid-market entry |
| 200 GB/day | ~$2.74/GB | ~$16.4K | Mid-market mature |
| 500 GB/day | ~$2.53/GB | ~$38K | Large mid-market / small enterprise |
| 1 TB/day | ~$2.48/GB | ~$74K | Enterprise |
| 2 TB/day | Custom | Custom | Large enterprise |
Indicative rates per Microsoft Azure public pricing page. Subject to Microsoft enterprise agreement discounts and regional surcharges. Always verify with Azure cost management before committing.
M365 free-tier ingestion (the major Sentinel wedge)
A defined set of Microsoft-native sources is free to ingest into Sentinel (per Microsoft's published free-data-sources list). The free-ingest sources are:
- Azure Activity logs (all customers, no licence required)
- Office 365 audit logs (Exchange Online, SharePoint Online, OneDrive, Teams)
- Microsoft Defender XDR security alerts (Defender for Endpoint, Identity, Office 365)
- Microsoft Defender for Cloud and Defender for Cloud Apps security alerts
- Microsoft Sentinel health logs
Not free, despite the common assumption: Microsoft Entra ID (Azure AD) sign-in and audit logs, and the raw advanced-hunting tables from Defender for Endpoint and Identity, are billed at the standard per-GB rate. Only the alerts from those products are free, not the underlying raw logs. Microsoft 365 E5 / A5 / F5 / G5 licences include a capped daily data grant (per user) that can offset some of the paid Entra ID and Defender volume.
For Microsoft-shop SOCs the free alert and Office 365 ingestion lowers the SIEM bill versus a comparable Splunk or Elastic deployment ingesting the same data at full per-GB rate. The saving is real but often overstated: the highest-volume Microsoft sources (Entra ID sign-in logs, raw endpoint telemetry) are paid, so free ingestion trims the bill rather than collapsing it. Combined with its native Azure integration, this is a structural reason Sentinel has won broad adoption in Microsoft-centric enterprises despite Splunk's deeper query language and longer market history.
When Sentinel is the right call
Sentinel wins when
- Microsoft-shop estate (M365, Azure, Defender are bulk of telemetry)
- Variable log volume and want pay-as-you-go without minimums
- Azure-native infrastructure where Sentinel-Logic Apps-Notebooks integration replaces SOAR purchase
- Strong Azure cost-management discipline and existing EA discount
- Compliance archive needs (Sentinel archive tier is cost-efficient)
Look elsewhere when
- AWS-shop or GCP-shop where Sentinel pulls cross-cloud data through brittle connectors
- Splunk-skill team where Sentinel KQL retraining cost is significant
- Heterogeneous non-Microsoft estate where free M365 ingest does not apply
- High-query workloads where Splunk Workload Pricing fits better
- Compliance regimes that require on-premises log control beyond Azure region residency
Related cost references
Frequently Asked Questions
How much does Microsoft Sentinel cost?
What logs are free to ingest in Microsoft Sentinel?
What are the Microsoft Sentinel commitment tiers?
Does Microsoft Sentinel include long-term storage?
When does Microsoft Sentinel beat Splunk on total cost?
Microsoft Sentinel rates verified against the Azure Retail Prices API (prices.azure.com, US East, simplified pricing tier) in June 2026: Pay-as-you-go Analysis $4.30/GB; 100 GB/day $296/day; 200 GB/day $548/day; 500 GB/day $1,265/day; 1 TB/day $2,480/day. Per-GB and monthly figures derived from those daily reservation rates. No per-customer EA-discounted pricing cited. SecurityOperationsCost.com has no commercial relationship with Microsoft.