This is the Trace Id: 7e4ab75ba9df864ca519145bb60e4a76
Skip to main content Why Microsoft Security AI-powered cybersecurity Cloud security Data security & governance Identity & network access Privacy & risk management Security for AI Unified SecOps Zero Trust Microsoft Defender Microsoft Entra Microsoft Intune Microsoft Priva Microsoft Purview Microsoft Sentinel Microsoft Security Copilot Microsoft Entra ID (Azure Active Directory) Microsoft Entra Agent ID Microsoft Entra External ID Microsoft Entra ID Governance Microsoft Entra ID Protection Microsoft Entra Internet Access Microsoft Entra Private Access Microsoft Entra Permissions Management Microsoft Entra Verified ID Microsoft Entra Workload ID Microsoft Entra Domain Services Azure Key Vault Microsoft Sentinel Microsoft Defender for Cloud Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Office 365 Microsoft Defender for Identity Microsoft Defender for Cloud Apps Microsoft Security Exposure Management Microsoft Defender Vulnerability Management Microsoft Defender Threat Intelligence Microsoft Defender Suite for Business Premium Microsoft Defender for Cloud Microsoft Defender Cloud Security Posture Mgmt Microsoft Defender External Attack Surface Management Azure Firewall Azure Web App Firewall Azure DDoS Protection GitHub Advanced Security Microsoft Defender for Endpoint Microsoft Defender XDR Microsoft Defender for Business Microsoft Intune core capabilities Microsoft Defender for IoT Microsoft Defender Vulnerability Management Microsoft Intune Advanced Analytics Microsoft Intune Endpoint Privilege Management Microsoft Intune Enterprise Application Management Microsoft Intune Remote Help Microsoft Cloud PKI Microsoft Purview Communication Compliance Microsoft Purview Compliance Manager Microsoft Purview Data Lifecycle Management Microsoft Purview eDiscovery Microsoft Purview Audit Microsoft Priva Risk Management Microsoft Priva Subject Rights Requests Microsoft Purview Data Governance Microsoft Purview Suite for Business Premium Microsoft Purview data security capabilities Pricing Services Partners Cybersecurity awareness Customer stories Security 101 Product trials Industry recognition Microsoft Security Insider Microsoft Digital Defense Report Security Response Center Microsoft Security Blog Microsoft Security Events Microsoft Tech Community Documentation Technical Content Library Training & certifications Compliance Program for Microsoft Cloud Microsoft Trust Center Service Trust Portal Microsoft Secure Future Initiative Business Solutions Hub Contact Sales Start free trial Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Marketplace Rewards Software development companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap

Get up to 5 MB of free Microsoft Sentinel data ingestion daily per user for key security logs.

Learn more
A close-up of a keyboard.
AI-powered SecOps

Microsoft Sentinel pricing

    Predict and stop attacks across clouds and platforms with Microsoft Sentinel. Unify AI, security orchestration and response, behavior analytics, threat intelligence, and a cost-effective data lake with one solution—now enhanced with graph technology for connected insights and rapid, precise response.
    OVERVIEW

    Transform your security operations with Microsoft Sentinel

    Flexible pricing plans

    Data tiers in Microsoft Sentinel offer flexibility, cost-efficiency, and comprehensive coverage.

    Analytics tier

    Supports all log types, with full analytics, alerts, and query capabilities. There are two payment options: Pay-As-You-Go and commitment tiers.

     Data lake tier

    Low-cost, long-term storage of security data used for investigations, querying, and compliance.
    PRICING TABLE

    Explore pricing options

    Prices are estimates only and are not intended as actual price quotes. Actual pricing may vary depending on the type of agreement entered with Microsoft, date of purchase, the currency exchange rate and taxes which may be applicable.1
    Region:
    The 50 GB commitment tier is available in public preview, with promotional pricing starting October 1, 2025, until June 30, 2026. Customers who sign up during this period will lock in promotional pricing until March 31, 2027. Promotional price varies by region and is subject to change.2
    Commitment tiers offer predictable costs and savings up to 52% over Pay-As-You-Go rates by allowing customers to reserve daily data ingestion capacity for the analytics tier, from 100 GB to 50,000 GB. They can be upgraded at any time and downgraded after 31 days. Usage exceeding the commitment tier will be billed at the same discounted rate.3
    Microsoft Sentinel is an AI-first platform built on a cost-effective, purpose built security data lake that centralizes all security telemetry for enhanced visibility, advanced analytics, graph based context, and MCP driven agentic defense. Sentinel data lake enables security teams to ingest, retain, and analyze massive volumes of security data cost effectively, and with separate compute and storage meters, it allows defenders to flexibly run advanced data insights, machine learning, and forensic investigations from a single point. Sentinel graph further enhances this by enabling security teams to visualize relationships across their security data. With custom graphs, teams can build their own graphs tailored to their unique security needs—to quickly surface risk.4
    Microsoft Sentinel solution for SAP® applications help monitor, detect, and respond to sophisticated threats throughout the business logic and application layers for SAP systems hosted on Azure, GCP, AWS, or on-premises. Learn more.
    GET STARTED

    Protect everything

    Make your future more secure. Explore your security options today.
    Person working on a laptop
    COST ESTIMATOR

    Microsoft Sentinel cost estimator

    Estimate Sentinel costs confidently with a guided experience that reflects your actual pricing, includes built‑in usage recommendations, and provides a 3‑year cost projection with growth modeling.
    RESOURCES

    Find more detailed information about Microsoft Sentinel

    Product capabilities

    Explore Microsoft Sentinel’s features and capabilities.

    Service-level agreement

    Review the SLA.

    Technical documentation

    Review technical tutorials, videos, and more resources.

    Frequently asked questions

    • Commitment tiers allow you to reserve a set amount of daily data ingestion capacity for Microsoft Sentinel for a fixed, predictable daily fee. You can upgrade your requested commitment at any time. Your new commitment tier will be effective at the start of the next UTC day. However, the minimum commitment period before you can opt out or reduce your capacity reservation is 31 days.
    • Commitment tiers are applicable at a workspace level and cannot be grouped across workspaces or subscriptions.
    • The analytics tier is ideal for ingesting high-value security data like identity logs, threat intelligence, and endpoint alerts to power real-time detections and investigations. The data lake tier is ideal for high-volume logs like network, firewall, and proxy logs that need long-term retention for forensics and historical analysis.3,4
    • Any Azure services that you use in addition to Microsoft Sentinel, such as Azure Log Analytics, Azure Logic Apps, Azure Machine Learning, and solutions, are charged according to their applicable pricing.
    • Customers who do not use the data lake should check the Azure Monitor pricing page for legacy Search Jobs, Search Queries, and Log Data Restore details. Learn more.
    • MCP server is an out-of-the-box interface that exposes Sentinel platform capabilities to AI agents. MCPs are similar to APIs, but designed specifically for AI agents. MCP tools invoke underlying Sentinel platform services such as data lake queries or graph operations, which are billed based on their respective meters. In addition, the entity analyzer MCP tool may consume Security Compute Units (SCUs) when AI reasoning is required (learn more). Customers are charged only for the underlying platform services and compute they actually use.
    • On October 1, 2025, Microsoft announced the public preview of a 50 GB commitment tier for Microsoft Sentinel. Customers can sign up for the 50 GB commitment tier from October 1, 2025, through June 30, 2026. Customers purchasing the 50 GB commitment tier during this timeframe will retain the promotional price until March 31, 2027. Promotional pricing varies by region and is available to all Microsoft Sentinel customers throughout the promotion.2
    1. [1]
      Prices are calculated based on US dollars. Prices are estimates only and are not intended as actual price quotes. Actual pricing may vary depending on the type of agreement entered with Microsoft, date of purchase, and the currency exchange rate. Sign in to the Azure pricing calculator to see pricing based on your current program/offer with Microsoft. Contact an Azure sales specialist for more information on pricing or to request a price quote. See frequently asked questions about Azure pricing.
    1. [2]
      The promo can be used with existing or new purchases of Microsoft Sentinel. The promo may not be combined with other Microsoft Sentinel discounts.
    2. [3]
      Logs in the Microsoft Sentinel analytics tier are stored within an Azure Monitor Log Analytics workspace. Upon enabling the Microsoft Sentinel data lake, new logs will automatically be stored in the data lake at no additional cost.
    3. [4]
      The data lake tier includes 30 days of free storage during preview. Data processing in the lake is also available at no cost during this time.

    Follow Microsoft Security