Microsoft Sentinel pricing in 2026: rates, commitment tiers, and how to cut the bill
Independent Sentinel pricing reference. Pay-as-you-go and commitment tier rates, the data lake tier, free Microsoft 365 data sources, head-to-head comparisons against Splunk Cloud, and the practical levers that actually cut your Sentinel bill. Note the Azure portal retires 31 March 2027, with Sentinel moving to the Defender portal. Rates re-verified against the Azure retail price list, August 2026.
Azure Sentinel pricing: is it the same as Microsoft Sentinel?
Azure Sentinel is the former name of Microsoft Sentinel (renamed in 2021); the pricing is identical, so a search for "Azure Sentinel pricing" returns the current Sentinel rates. Ingestion is billed per GB: pay-as-you-go is $4.30 per GB (East US, simplified tier), and commitment tiers cut that to $2.96 effective at 100 GB/day (31 percent off) down to $2.05 at 50,000 GB/day (52 percent off). Microsoft 365 audit logs, Azure Activity logs, and Defender XDR alerts ingest free, so the effective rate for Microsoft-heavy shops often runs 40-60 percent below the headline. The name change did not move the price; the meaningful shifts since have been the 2023 single-meter simplification and the 2025 Defender-portal data lake tier below.
M365 audit logs (E5/A5/G5), Azure Activity logs, and Defender XDR alerts ingest free and do not count toward billable volume. Microsoft-heavy shops routinely see 30-50%.
Cheapest plan at this volume: 50 GB commit (promo) at an effective $3.23/GB. Promotional tier; confirm the sign-up window is still open.
Commitment tier pricing in full
Microsoft publishes commitment tiers from 100 GB per day up to 50,000 GB per day, plus a promotional 50 GB per day tier in public preview (sign-up window runs to 31 December 2026, with pricing locked until 31 March 2027). The savings compound: every step up reduces the effective per-GB rate. The break-even from PAYG is roughly 38 GB per day for the 50 GB commit and 69 GB per day for the 100 GB commit. All rates East US; workspaces created since July 2023 use the simplified single-meter pricing shown here rather than separate Log Analytics and Sentinel charges.
| Commitment tier | Daily cost | Effective rate | Saving vs PAYG |
|---|---|---|---|
| Pay-as-you-go | - | $4.30/GB | 0% |
| 50 GB/day (promo) | $161.25/day | $3.23/GB | 25% |
| 100 GB/day | $296/day | $2.96/GB | 31% |
| 200 GB/day | $548/day | $2.74/GB | 36% |
| 300 GB/day | $800/day | $2.67/GB | 38% |
| 400 GB/day | $1,037/day | $2.59/GB | 40% |
| 500 GB/day | $1,265/day | $2.53/GB | 41% |
| 1,000 GB/day | $2,480/day | $2.48/GB | 42% |
| 5,000 GB/day | $11,550/day | $2.31/GB | 46% |
| 50,000 GB/day | $102,600/day | $2.05/GB | 52% |
The free data sources that change the maths
Sentinel ingests certain Microsoft data sources free, regardless of commitment tier. For Microsoft 365 organisations on E5 licensing, free ingest can account for 30-50 percent of total log volume.
Third-party log sources (firewalls, SaaS apps, custom apps) always count towards paid ingest. Custom transform rules at the data collection rule (DCR) layer let you drop unwanted fields before billing.
Sentinel cost scenarios
| Scenario | Profile | Licence | Total TCO | Notes |
|---|---|---|---|---|
| Startup | 5 GB/day, PAYG, 90-day retention | $7.8K/yr | $20K-$33K | Free 31-day trial covers initial deployment |
| Mid-market | 50 GB/day, 50 GB commit (promo), 365-day retention | $59K/yr | $200K-$300K | Promotional 50 GB tier beats PAYG from ~38 GB/day |
| Enterprise | 200 GB/day, 200 GB commit, 365-day retention | $200K/yr | $640K-$960K | Commitment tier locks 36 percent savings |
| Microsoft-first enterprise | 500 GB/day inclusive of free M365 logs | ~$115K/yr effective | $390K-$550K | Free M365 data drives effective rate well below PAYG |
| Large enterprise | 1 TB/day, 1,000 GB commit, 365-day retention | $905K/yr | $2.4M-$3.2M | Microsoft Copilot for Security adds 15-25 percent |
How to cut Microsoft Sentinel costs
Because Sentinel bills on the data you ingest, almost every real saving comes from controlling what reaches the analytics tier and where the rest lands. The three highest-impact levers are filtering data before ingest, routing low-value logs to the cheaper data lake tier, and catching ingestion spikes before they hit the bill. The rest tune the tier and add-ons. None of this requires a third-party pipeline product, though one can automate the filtering if you would rather not maintain the rules.
1. Filter data before it is ingested
Data Collection Rule (DCR) transforms drop unused fields and whole low-value event types before they hit the billing meter. Cutting 20-30 percent of bytes per record is normal, and it is the single biggest lever because it reduces paid volume at the source.
2. Route low-value tables to the data lake tier
Switch high-volume, low-fidelity tables (firewall, NetFlow, verbose app logs) from the analytics tier to the data lake tier, where ingestion and storage are a fraction of the $4.30/GB analytics rate. Keep primary detection telemetry in analytics so rules still fire.
3. Catch ingestion spikes before they bill
A misconfigured source or a new noisy connector can quietly double your daily volume. Set Azure cost alerts and an anomaly rule on daily ingest so a spike surfaces in hours, not on the monthly invoice.
Use Basic Logs for high-volume sources
Network firewall logs, NetFlow, and IIS logs ingest at $1.00 per GB instead of $4.30. Detection rules cannot fire from Basic Logs, so keep primary security telemetry in the standard tier.
Lean on the free Microsoft data sources
Microsoft 365 audit logs, Azure Activity logs, and Defender XDR alerts ingest free. In a Microsoft-heavy estate that is often 30-50 percent of volume, so connect them first before paying for third-party sources.
Right-size your commitment tier
Move up tiers as volume grows to lock the discount; you can lower the tier every 31 days if volume drops. The break-even from PAYG is roughly 38 GB/day for the 50 GB commit and 69 GB/day for the 100 GB commit.
Extend retention via the data lake, not hot storage
For 365-day retention with 90 days hot, hold the long tail in the data lake tier rather than paying analytics retention. On a 6:1 compression ratio, 600 GB of raw data bills as 100 GB stored.
Watch UEBA, Notebooks and Copilot add-ons
UEBA and Notebooks draw on the same workspace data with their own consumption; Microsoft Copilot for Security is SCU-priced and easy to overspend. Cap SCUs at the workspace level and review monthly.