★ First page of Microsoft's 100,000-partner directory, sorted by responsiveness✓ Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI● Microsoft partner since 2006◆ 1,100+ organizations under management

Microsoft Sentinel for a 100-User Organization: What Drives the Monthly Bill, and When a Managed Detection Service Is the Better Buy

2026-09-27·IT Partner·Security guidesNewSecurityMicrosoft SentinelAzureManaged Services

Microsoft Sentinel has no per-user price. It bills on the gigabytes of log data you send it, on how long you keep them, and on the Azure services around it. This article explains the billing model in words, lists the sources Microsoft does not charge for, walks through the log sources a Microsoft 365 shop actually connects, and then asks who will look at the incidents. Our [MDR article](/blog/mdr-why-siem-alone-isnt-enough) argues that a SIEM without operations is a log archive; this one does the sizing. Azure charges are metered and yours; we print no Azure prices because they change.

How Sentinel is billed, in words

Microsoft's Sentinel pricing page (opened 27 September 2026) describes two tiers of data and two ways to pay for the main one.

The analytics tier is where detection happens. Every gigabyte ingested into it is charged, and this is the number that drives most bills.

The data lake tier is the low-cost place for long retention: a lower ingestion and storage rate, with queries billed when you run them. Part of the data lake offer was still marked preview when we opened the page, so check the current terms.

For the analytics tier you either pay as you go per gigabyte or buy a commitment tier, which reserves a daily volume from 100 GB per day up to 50,000 GB per day at a lower effective rate; you can move up at any time and down after 31 days. Microsoft also lists a promotional 50 GB per day tier open for sign-up from 1 October 2025 through 31 December 2026, with the promotional price retained until 31 March 2027. A 100-user organization rarely reaches even that tier, so pay-as-you-go is the normal starting point.

The same bill carries retention beyond the included window and the Azure services Sentinel calls, such as Logic Apps for playbooks. An Azure subscription is required, and Sentinel now runs inside the Microsoft Defender portal, one incident queue with Defender XDR.

What Microsoft does not charge to ingest, and the E5 data grant

Two categories reduce the bill for a Microsoft 365 organization.

The first is data with no ingestion charge for every Sentinel customer. Azure Monitor's cost documentation (ms.date 2 September 2026, opened via the MicrosoftDocs GitHub source) names the Azure Activity, Heartbeat, Usage and Operation tables as exempt. Microsoft's Sentinel offer for Microsoft 365 customers adds the alerts from Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender XDR and Defender for Cloud as always exempt (as reported in search results on 27 September 2026; verify on the Azure pricing site). Alerts are small; the raw events behind them are charged.

The second is the Microsoft 365 E5 data grant. The Sentinel pricing page states that Microsoft 365 E5 customers get up to 5 MB of Sentinel ingestion per user per day at no charge for key security logs; the offer page extends the grant to A5, F5 and G5 and to the Microsoft Defender Suite, and lists Entra ID sign-in and audit logs among the covered sources (as summarized in search results; verify). For 100 E5 users that is up to 500 MB per day, usually enough for the identity logs, applied automatically.

Everything else is billed: identity logs in a Business Premium or E3 tenant, Windows security events, firewall and VPN syslog, DNS, and third-party connectors. E3 vs E5 covers the wider comparison.

The log sources a Microsoft 365 shop connects, and which ones cost money

A 100-user organization with five servers and one firewall usually ends up with this set.

  • Entra ID sign-in and audit logs. Sign-ins, Conditional Access results, role changes. Charged unless the E5 grant covers it.
  • Office 365 activity (Exchange, SharePoint, Teams). Mailbox rules, sharing changes, downloads. Historically not charged for the core logs; confirm on the pricing page.
  • Defender XDR alerts. No ingestion charge. Connect this first.
  • Defender for Endpoint raw events. Charged and heavy. Most 100-user tenants leave them in Defender XDR and stream only the alerts.
  • Windows security events from servers. Charged. Use the "Common" event set in the data collection rule, not "All events".
  • Firewall and VPN syslog. Charged and often the largest line. Send denies and VPN authentication, not every allowed session.
  • Azure Activity. No ingestion charge. Connect it if you run anything in Azure.
  • Third-party SaaS (identity providers, payroll, CRM). Charged, small.

From our deployments, a tuned tenant of this shape lands in the low single-digit gigabytes per day. Untuned firewall logging or raw endpoint events can multiply that several times.

The five settings that control the bill

  1. Filter at the source. Data collection rules, firewall log levels and connector options decide what enters the analytics tier.
  2. Route by value. Detection data goes to the analytics tier; high-volume, low-alert data (firewall allows, DNS, verbose application logs) goes to the data lake tier.
  3. Set retention per table. Regulated retention for SOC 2, NYDFS or cyber insurance is a lake question; our SOC 2 article explains why the retention start date matters.
  4. Separate operational logs. All data in a Sentinel-enabled workspace is subject to Sentinel charges, per Azure Monitor's documentation, so performance and application logs belong in another workspace.
  5. Watch automation. Playbooks run in Logic Apps and are billed per action.

Put a daily cap on the workspace for the first month, then remove it once the volume is known.

The staffing reality: someone has to look at it

Once the connectors are in, analytic rules create incidents. A tuned 100-user tenant produces a handful to a few dozen a week, most of them benign. Each needs a person to open it, decide, and close it with a note. Left alone, the queue ages and the real incident hides among stale ones.

Three ways to staff it. An internal administrator with a fixed weekly block covers business hours only, and most ransomware detonations happen at night or on weekends. Co-managed: your team handles business hours, a provider covers the rest, and the Defender XDR incident readiness engagement ($3,500 per project) writes the runbook both sides follow. Fully managed: our Microsoft Sentinel ongoing monitoring service is $15 per user per month, so $1,500 per month for 100 users; the Azure charges stay on your subscription.

The honest test: if the person who will own the queue cannot name the last three incidents they closed, the tenant needs the managed option or should not buy Sentinel yet.

When a managed detection service on Defender XDR is the better buy

Sentinel earns its place when at least one of these is true: log sources outside Microsoft (firewall, VPN, another identity provider, SaaS with regulated data); a framework or insurer that requires retained, searchable security logs; automation across systems; or Azure workloads whose activity should sit next to the tenant's.

If none is true, the tenant is a Microsoft 365 shop whose signals already flow into Defender XDR: endpoint, identity, email and cloud apps in one incident queue. For that organization a managed detection and response service that works the Defender XDR queue, with no ingestion bill, is usually the better purchase. Our Multi-Platform MDR service ($15 per user per month) does that.

Either path needs the ability to reconstruct what happened: what could you prove? explains why audit retention decides that, and what a post-incident report should contain shows the output.

Frequently asked questions

How much does Microsoft Sentinel cost for a small business?

There is no per-user price. You pay per gigabyte in the analytics tier, less in the data lake tier, plus retention and the Azure services around it. A tuned 100-user tenant lands in the low single-digit gigabytes per day, pay-as-you-go territory. Use the Azure pricing calculator with your own volumes.

Does Microsoft 365 E5 include Microsoft Sentinel?

No, but E5 customers receive a data grant of up to 5 MB per user per day at no charge, applied automatically, and Microsoft extends it to A5, F5, G5 and the Microsoft Defender Suite. For 100 users that is up to 500 MB per day.

Do I need Sentinel if I already have Defender XDR?

Not always. Defender XDR already correlates endpoint, identity, email and cloud-app signals into incidents. Sentinel adds non-Microsoft sources, long searchable retention, cross-system automation and Azure activity. Without those needs, a managed service on the Defender XDR queue is the cheaper way to get eyes on incidents.

What is the difference between Sentinel and MDR?

Sentinel is software: a SIEM and SOAR platform you pay Azure to run. MDR is a service: people who triage, investigate and respond, on Sentinel or on Defender XDR. You can staff Sentinel yourself, have a provider run it, or skip it and buy MDR on Defender XDR alone.

Sources

  • Microsoft, Microsoft Sentinel pricing page (opened 27 September 2026): analytics and data lake tiers, commitment tiers from 100 GB to 50,000 GB per day, the 31-day downgrade rule, the 50 GB promotional tier and its dates, the E5 data grant, the data lake preview note
  • Microsoft, Microsoft Sentinel product page (opened 27 September 2026): billing on data ingested, stored and consumed; Azure subscription required; the Defender portal
  • Microsoft Learn, "Azure Monitor Logs cost calculations and options" (ms.date 2 September 2026; opened via the MicrosoftDocs GitHub source): Sentinel meters, tables exempt from ingestion charges, Sentinel charges applying to all data in an enabled workspace
  • Microsoft Azure, "Microsoft 365 E5 benefit offer with Microsoft Sentinel" (not opened; the exempt Defender alert sources and covered log types as summarized in search results on 27 September 2026; verify on the Azure pricing site)
  • IT Partner blog: mdr-why-siem-alone-isnt-enough; microsoft-365-breach-forensics-prove-scope; what-a-microsoft-365-post-incident-report-should-contain-lessons-from-a-bec-case
  • IT Partner engineering notes from Sentinel deployments for 50 to 300-user tenants, September 2026 (the volume observations above are ours, not Microsoft's)
Log source Why you connect it Ingestion charge Where it belongs
Entra ID sign-in and audit logs Sign-ins, MFA, Conditional Access, role changes Charged; covered by the E5 grant where it applies Analytics tier
Defender XDR alerts and incidents One queue with Defender No charge for alerts Analytics tier
Defender for Endpoint raw events Deep hunting Charged, heavy Usually left in Defender XDR
Windows security events (servers) Server logons, privilege use Charged Analytics tier, "Common" set
Firewall and VPN syslog Perimeter and remote access Charged, often the largest line Denies and VPN auth to analytics; the rest to the data lake
Azure Activity Changes to Azure resources No charge Analytics tier

Key takeaways

  • Sentinel bills per gigabyte in the analytics tier, less in the data lake tier, plus retention and the Azure services around it; a 100-user tenant is normally pay-as-you-go.
  • Defender alerts and a few Azure tables carry no ingestion charge, and Microsoft 365 E5 tenants get a data grant of up to 5 MB per user per day; identity logs are billed in a Business Premium or E3 tenant.
  • Five decisions set the bill: filter at the source, route by value, set retention per table, keep operational logs in another workspace, and watch playbook actions.
  • A SIEM assumes someone closes incidents every day; if nobody will, buy the managed option or do not buy Sentinel yet.
  • A pure Microsoft 365 tenant with no outside log sources is often better served by managed detection on Defender XDR, with no ingestion bill at all.

If Sentinel is the right tool, the Microsoft Sentinel SIEM/SOAR Monitoring Implementation ($7,850 per project, two weeks) builds the workspace, connects the sources above with the filtering that keeps the bill sane, tunes the rules and hands over the runbook; Microsoft Sentinel SIEM/SOAR Ongoing Monitoring ($15 per user, billed monthly) then staffs the queue. If it is not, Defender XDR Incident Readiness and Automated Response ($3,500 per project, two weeks) gets the same outcome from the licenses you already own. After an incident, the Microsoft 365 Post-Incident Investigation and Report ($1,950 per project, one week) documents what happened. Azure ingestion, retention and automation charges are metered on your subscription in every case. Book a sizing call with your user count, server count and log sources; we estimate the daily volume before you commit.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.