← Back to Blog
    BlogCybersecurityApril 25, 20267 min readBy Mirage Informatique

    Microsoft Sentinel Pricing for SMBs: What Is Actually Free

    "Sentinel is free with E5" merges two unrelated things and blows SIEM budgets. Here is what the grant covers, what the 50 GB tier really is, and where the savings actually come from.

    Share
    Microsoft Sentinel Pricing for SMBs: What Is Actually Free

    Your Azure invoice says Microsoft Sentinel, the number has four figures, and someone on the leadership team wants to know why. The answer is usually the same misunderstanding, repeated across two unrelated licensing facts.

    Those two facts get compressed into one sentence: "Sentinel is free with E5." There is a Sentinel data grant attached to Microsoft 365 E5. There is also a 50 GB per day pricing tier that gets talked about a great deal. They have nothing to do with each other, and merging them is the fastest route to a SIEM budget that misses by an order of magnitude.

    Key Takeaways

    • The Microsoft 365 E5 Sentinel grant is 5 MB per user per day, not 50 GB.
    • The 50 GB per day option is a paid commitment tier, currently in public preview.
    • Its promotional signup window runs to December 31, 2026.
    • Sign up inside that window and the promotional price holds until March 31, 2027.
    • Sentinel leaves the Azure portal after March 31, 2027, so plan the Defender portal move.

    What the Microsoft 365 E5 grant actually gives you

    Microsoft's E5 benefit offer grants up to 5 MB per user per day of Microsoft 365 data ingested into Sentinel (Microsoft Azure). Megabytes, not gigabytes.

    Run the arithmetic on a 100 seat business. One hundred users at 5 MB each is 500 MB per day, roughly half a gigabyte. Worth claiming, genuinely free, and nowhere near enough to fund a SIEM on its own.

    Eligibility is also narrower than most people assume. You need Microsoft 365 E7, E5, A5, F5 or G5, or the matching Security SKUs, held under an Enterprise Agreement, Enterprise Subscription, or Cloud Solution Provider agreement.

    The grant then applies to four data types only:

    • Microsoft Entra ID sign-in and audit logs
    • Microsoft Defender for Cloud Apps shadow IT discovery logs
    • Microsoft Purview Information Protection logs
    • Microsoft 365 advanced hunting data

    Firewall syslog does not count. Neither does telemetry from any third party appliance.

    The sources that cost nothing at all

    Separately from the grant, a set of connectors carries no ingestion charge whatsoever (Microsoft Learn):

    • Azure Activity logs
    • Microsoft Sentinel Health
    • Office 365 audit logs, including SharePoint, Exchange admin and Teams activity
    • Security alerts from Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps and Defender for Cloud

    One caveat catches almost everyone. The alerts are free, but the raw underlying logs for several of those same products are billable. "Defender for Endpoint is free in Sentinel" is true of the alert. It is not true of the device telemetry sitting behind it.

    There is no expiry on the E5 grant

    Microsoft's offer page lists no end date. If someone has told you your Sentinel benefit expires on a particular day, they are almost certainly describing the commitment tier promotion below, which is a different thing with a different deadline.

    IT security analyst reviewing Microsoft Sentinel log ingestion and query results on screen, focused workstation lighting, professional cybersecurity environment
    IT security analyst reviewing Microsoft Sentinel log ingestion and query results on screen, focused workstation lighting, professional cybersecurity environment

    The 50 GB tier is a discount, not a giveaway

    Commitment tiers let you reserve a daily ingestion volume in exchange for a lower effective rate than pay as you go. Microsoft quotes savings of up to 52 percent against pay as you go across the tier range.

    Historically the smallest commitment tier was 100 GB per day, far more than a typical small business produces. The 50 GB per day tier, currently in public preview, halves that entry point. The operative word is commitment. You pay for the reserved volume whether you fill it or not, and anything above it bills at the same effective rate.

    The promotional terms are specific (Microsoft Sentinel pricing):

    • Signup window runs October 1, 2025 through December 31, 2026
    • The promotional price holds until March 31, 2027 for customers who sign up inside that window
    • The promotional price varies by region and is subject to change

    So the date that matters is December 2026, not June 2026. And what you receive is a discounted rate, not free capacity.

    Is 50 GB per day the right commitment for you?

    For most Quebec businesses under roughly 200 seats, no. Committing to 50 GB per day while ingesting 12 means paying for 38 GB of nothing, every single day. Pay as you go combined with disciplined table tiering usually lands lower.

    A commitment tier earns its keep once your steady state ingestion sits consistently close to the tier you are reserving. Work that out from your own workspace rather than a rule of thumb. Microsoft publishes a cost estimator, and your existing Log Analytics usage data already tells you your real daily volume per table.

    Three levers that move the bill more than any promotion

    Based on field observations, the largest Sentinel savings come from what you ingest, not from which pricing tier you sit on.

    Put low value logs in a cheaper tier

    Sentinel separates analytics tier data, which is queryable and alertable at full price, from lake tier data, which is built for high volume and low value at a much lower storage cost. High fidelity tables such as sign-in logs and device process events belong in analytics. Chatty firewall and proxy logs usually do not.

    Filter before the data lands

    Azure Monitor supports transformations at ingestion time, so you can drop or trim events before they reach the workspace and before they are billed. If you take a large volume of audit logs but only alert on a handful of operation types, a transformation removes the remainder without weakening a single detection.

    Set retention per table

    The first 90 days of retention are included. Past that you pay, which makes retention a per table decision rather than a workspace wide one. Keep sign-in logs long enough to satisfy an insurer or a Law 25 inquiry, and let noisy operational tables expire on schedule.

    Business team reviewing cloud service costs and usage reports on a laptop in a bright meeting room, natural window light, professional atmosphere
    Business team reviewing cloud service costs and usage reports on a laptop in a bright meeting room, natural window light, professional atmosphere

    The deadline nobody is talking about

    Sitting in Microsoft's billing documentation is a date with more operational impact than any pricing promotion. After March 31, 2027, Sentinel will no longer be supported in the Azure portal and will run only in the Microsoft Defender portal (Microsoft Learn).

    If your runbooks, screenshots and internal training all assume the Azure portal, that is a migration to schedule rather than to discover. Our cybersecurity team folds the portal move into any Sentinel engagement instead of treating it as a separate project, and our managed IT services cover the tuning work that follows.

    For the architecture side of this, meaning how Sentinel and Defender for Business fit together for a smaller team, see our guide to building an SMB security operations capability.

    FAQ

    Is Microsoft Sentinel free if we have Microsoft 365 E5?

    Not in the way it is usually described. E5 includes a grant of up to 5 MB per user per day covering four specific Microsoft 365 log types, plus a set of always free connectors. Everything else is billed at standard rates.

    How much data does the 5 MB per user grant actually cover?

    For 100 users it works out to roughly 500 MB per day. That typically absorbs Entra ID sign-in and audit logs for a business that size, and not much more. Endpoint telemetry and firewall logs sit outside it entirely.

    What happens after the 50 GB promotional window closes?

    Customers who sign up before December 31, 2026 keep the promotional price until March 31, 2027. Microsoft has not published pricing beyond that date, and notes the promotional rate varies by region and may change.

    Should a 75 person business choose a commitment tier?

    Usually not at first. Measure your actual daily ingestion across a full month, apply table tiering and ingestion filters, then compare. A commitment tier only pays off once your sustained volume sits close to the tier you reserve.

    Do we need a Microsoft partner to get these prices?

    No. Commitment tiers are available through Enterprise Agreement, Cloud Solution Provider and direct subscriptions. A partner can help with sizing and tuning, but partner status is not a condition of the pricing.

    Sources

    Check two numbers this week: whether the E5 grant is actually applied to your workspace, and what your real daily ingestion looks like table by table. Those two figures decide everything else about your Sentinel bill. If you would like a second pair of eyes on them, book an IT assessment and we will come back with a costed plan.

    Share

    Related Articles