Sentinel + Defender for Business: A SOC for SMBs
Enterprise-grade SIEM and XDR are now realistic for small businesses. Here's how Quebec SMBs can build a real SOC without an enterprise budget, and what it actually costs.

You run a 40-person accounting firm in Quebec City. Your cyber-insurance renewal lands on your desk and asks whether you have "24/7 threat detection, log retention of 90+ days, and automated incident response." You stare at the form. Your IT provider does patching and backups, not threat hunting. A real Security Operations Center costs six figures a year. So you tick "no," pay a higher premium, and hope nothing breaks.
That gap, between what insurers and clients now demand and what SMBs can realistically afford, is what the Microsoft security stack has been closing. Two pieces matter most: Microsoft Sentinel as the log and detection layer, and Defender for Business Premium as the endpoint layer.
One thing to get straight first, because it derails more SMB security budgets than anything else. Sentinel is not free with E5. The Microsoft 365 E5 benefit grants up to 5 MB per user per day of Microsoft 365 data ingested into Sentinel, and a separate set of connectors carries no ingestion charge at all. That is genuinely useful. It is not a 50 GB per day allowance, and the 50 GB per day figure you may have seen refers to a paid commitment tier. We work through the real numbers in Microsoft Sentinel pricing for SMBs.
Key Takeaways
- Sentinel is not free with E5. The grant is 5 MB per user per day.
- Office 365 audit logs and Defender alerts ingest at no charge at all.
- A 100-seat environment typically generates 10 to 25 GB per day.
- Sentinel leaves the Azure portal after March 31, 2027.
- Budget analyst time, not just licensing. The human layer costs more.
What actually changed for SMB security
Three shifts matter for Quebec SMBs:
- Defender for Business Premium reached general availability, adding attack surface reduction reports, vulnerability management dashboards, and tighter Intune integration. Those were previously Enterprise-only features.
- The unified SOC experience in the Defender portal now ingests Sentinel data natively, so analysts work from one console instead of pivoting between Azure and security.microsoft.com.
- Sentinel is moving to the Defender portal permanently. After March 31, 2027, Sentinel will no longer be supported in the Azure portal (Microsoft Learn). Anything you build now should assume the Defender portal.
The practical effect: a Quebec SMB running Microsoft 365 Business Premium plus Defender for Business Premium plus Sentinel can do log-based detection, automated response, and 90-day retention on a predictable monthly cost.
Why this matters more for a 50-person business than a 5,000-person one
Large enterprises already had SOCs. They paid for Splunk or QRadar, staffed three shifts of analysts, and absorbed the cost. SMBs had two options: buy a watered-down MDR service, or accept the risk.
Sentinel changes the entry price rather than removing it. You are not buying a platform licence and a professional services engagement before you see your first alert. You stand up a workspace, connect the free Microsoft connectors, and pay only for what you ingest beyond them.
What your log volume actually looks like
Based on field observations, a 100-seat environment tends to sit in these ranges:
- Microsoft 365 unified audit log: 0.5 to 2 GB per day
- Entra ID sign-in and audit logs: 1 to 3 GB per day
- Defender for Endpoint and Defender for Business: 2 to 5 GB per day across 100 endpoints
- Defender for Office 365 email events: 1 to 2 GB per day
- Azure activity and NSG flow logs: 2 to 8 GB per day in a small environment
A 100-seat Quebec SMB typically lands between 10 and 25 GB per day in total. Now note carefully what the free connectors cover and what they do not. Office 365 audit logs and Defender alerts cost nothing. The raw Defender device telemetry, and Entra ID sign-in logs beyond the 5 MB per user grant, are billable. Budget for that difference rather than assuming it away.
A practical 30-day rollout plan
Here's the sequence we use for clients moving from "Business Premium only" to a real detection-and-response posture. This assumes you already have Microsoft 365 Business Premium or E5.
Week 1: Licensing and baseline
- Add Defender for Business Premium, or confirm it's included in E5.
- Apply the Microsoft 365 E5 Sentinel data grant if you hold qualifying licences. It is not applied automatically, and it requires an Enterprise Agreement, Enterprise Subscription, or CSP agreement.
- Create a dedicated Log Analytics workspace in Canada Central. Data residency matters for Law 25 and for CMMC-aligned clients.
- Turn on Microsoft 365 unified audit logging and Entra ID diagnostic settings pointed at the workspace.
Week 2: Connectors and content
- Enable the Microsoft 365, Entra ID, Defender XDR, and Azure Activity data connectors. Azure Activity and the Office 365 audit logs ingest free. The others draw on your grant or bill at standard rates.
- Install the Microsoft-supplied analytics rule templates, starting with the essentials: impossible travel, MFA fatigue, OAuth consent abuse, suspicious inbox rules.
- Deploy the default Defender for Business policies to all endpoints and force a compliance check via Intune.
Week 3: Automation and response
- Build two to three automation playbooks: auto-disable user on confirmed account takeover, auto-isolate endpoint on high-severity Defender alert, and auto-ticket to your help desk system.
- Configure notification rules so your on-call engineer gets SMS alerts for severity-high incidents only. Noise kills SOCs faster than attackers do.
- Test the incident flow end to end with a tabletop exercise.
Week 4: Tuning and handoff
- Review the first week of incidents. Expect a large share to be benign but noisy on day one. Tune analytics rules and suppression lists accordingly.
- Document runbooks for the five most common alert types.
- Decide between in-house monitoring during business hours and outsourced 24/7 coverage. Most SMBs under 200 seats choose co-managed detection with a partner rather than hiring a night-shift analyst.
Where the costs actually land
Licensing is the obvious line item. These are the ones that surprise people:
- Ingestion beyond the free connectors and the E5 grant. The line most often underestimated, because someone said it was zero. Measure per table before you commit to a number.
- Retention beyond 90 days. The first 90 days are included, then you pay Log Analytics retention rates. If your insurer wants 12 months, budget for it, and set retention per table rather than workspace-wide.
- Lake tier for high-volume, low-value logs. Cheaper storage with query capability built in, useful for chatty tables you still have to keep.
- Automation runs. Logic App actions cost pennies, but a badly designed playbook that fires thousands of times in an hour becomes a surprise invoice.
- Analyst time. The tooling is now affordable. The human layer is not, which is why most SMBs pair Sentinel with a managed service rather than staffing it solo.
Model your own numbers with Microsoft's cost estimator before committing to any pricing tier. Our managed IT services include that sizing exercise.
What this doesn't replace
Sentinel and Defender for Business are detection and response tools. They do not:
- Replace backups. Ransomware that gets past detection still needs tested, immutable backups to recover from.
- Replace identity hygiene. Conditional Access, phishing-resistant MFA, and least-privilege admin roles still do most of the defensive work.
- Replace patching. An unpatched Exchange server is still an unpatched Exchange server.
Think of this as lowering the floor of what "reasonable security" means for a Canadian SMB. Cyber insurance questionnaires, federal RFPs, and large-enterprise vendor assessments now routinely ask about SIEM and EDR capability. "Yes, Sentinel with 90-day retention and Defender XDR" is a realistic answer for a 50-person firm.
FAQ
Do we need Microsoft 365 E5 to run Sentinel?
No. Sentinel is an Azure service billed on ingestion, so any tenant can use it. E5 adds the 5 MB per user per day data grant and bundles the Defender workloads that feed it, which improves the economics without being a prerequisite.
Can a business without a security team actually operate this?
Partly. Deployment and tuning are a project with an end date. The ongoing triage is the harder commitment. Most businesses under 200 seats run detection in-house during office hours and contract out after-hours coverage rather than staffing a night shift.
How long before Sentinel produces useful alerts?
Expect meaningful signal within the first week of connecting Microsoft 365 and Entra ID, then about a month of tuning before the noise settles. A busy first fortnight of benign alerts is normal, not a sign of misconfiguration.
Does our data stay in Canada?
Only if you create the Log Analytics workspace in a Canadian region. That is a choice made at workspace creation and awkward to change later, so decide before you deploy if Law 25 or client contracts require it.
What happens to our existing antivirus?
Defender for Business replaces it on Windows endpoints. Running two endpoint protection products at once causes conflicts and performance complaints, so plan removal of the incumbent as part of the rollout rather than afterwards.
Getting started without overcommitting
The fastest wins: confirm whether your licences qualify for the E5 data grant and apply it, then turn on the connectors that ingest free. Logs accumulate quietly and become forensic gold the moment you need them. Prioritize Entra ID and email analytics rules, since identity and phishing are where most SMB incidents begin.
If you'd like a second set of eyes on your tenant, our team runs a fixed-scope Microsoft 365 security assessment that maps your current posture against the current Defender and Sentinel baselines and hands you a costed rollout plan. Reach out when you're ready. Licensing benefits only help if someone turns them on.
Related Articles

Patch Tuesday May 2026: 138 Flaws to Fix Fast
Microsoft fixes 138 vulnerabilities in May 2026, including 30 critical ones. Learn how to protect your SMB and prioritize essential patches.
OAuth App Attacks Are the New Phishing in Microsoft 365
OAuth app attacks stole CRM data in June 2026, no passwords needed. Learn how to lock down app consent in Microsoft 365 before your tenant is next.
Cyber Insurance Requirements for SMBs: Pass the Questionnaire
Learn how to meet cyber insurance requirements for your SMB: MFA, EDR, immutable backups and more, mapped to Microsoft 365 tools you already own.