Skip to content
English
  • There are no suggestions because the search field is empty.

Microsoft Sentinel Pricing: What to expect when you accept additional costs?

Attic MDR uses Azure Sentinel for log storage. While most logs are free, some essential ones incur additional costs.

The aditional cost comes from the following logs: 

  • EntraID Auditlogs (AuditLogs, ProvisioningLogs)
  • EntraID SingInLogs (SignInLogs, NonInteractiveUserSignInLogs, ServicePrincipalSignInLogs, ManagedIdentitySignInLogs, ADFSSignInLogs)

We often get asked what to expect. Current pricing (Feb 2026) is ~ 4,7 euro per gb per month. A common question we receive is: "How much data does a single employee generate?"

We analyzed actual usage data across our customer base to provide a concrete rule of thumb.

The Verdict: Expect €0.25 per user/month

Based on the average consumption of our clients, we see a consistent pattern. For 90% of organizations, the cost for Sentinel (including Log Analytics storage) comes down to approximately €0.25 per user per month.

The Calculation:

  • On average, a standard workplace environment generates 0.05 GB (50MB) of security logs per user per month.

  • The current market price for Sentinel (West Europe, Pay-As-You-Go) is approximately €4.80 per GB.

  • 0.05 GB x €4.80 = €0.24.

Cost Examples

To give you an idea of the monthly invoice based on company size:

Number of Employees Estimated Data Usage Estimated Monthly Cost
25 users 1.25 GB € 6.00
100 users 5.00 GB € 24.00
500 users 25.00 GB € 120.00

 

Stay in control: Set a Budget Alert

Because data usage can fluctuate (e.g., due to a new server or application generating unexpected logs), we highly recommend setting up a Budget Alert.

The setup consists of 3 distinct steps:

  1. Budget Details: What is the spending limit?

  2. Alert Conditions: When do you want to be warned?

  3. Actions: Who should receive the email?

Follow these steps:

  1. In the Azure Portal, Search Microsoft Sentinel and click it

  2. Click the Resource group name in the sentinel overview.

  3. In the left menu (under the section Cost Management), select Budgets and click + Add at the top. (if you see things suchs as "threat management", "Incidents" or "Analytics" you clicked the sentinel instance instead of the resource group name from step 2) 

Step 1: Budget Details

  • Name: Give it a logical name (e.g., Sentinel-Budget-Monthly).

  • Reset period: Set this to Billing month (so the counter resets every month).

  • Creation/Expiration date: You can leave the end date far in the future (e.g., 2030).

  • Amount: Enter your threshold amount here (e.g., €150.00).

  • Click 'Next'.

Step 2: Set Alerts (The Conditions)

  • Type: Leave this set to Actual.

  • % of budget: Enter 80. (You will receive an alert when 80% of your €150.00 budget is consumed).

  • Optional: You can add a second rule, for example at 100 %.

Step 3: Action Group (The Email)

  • This determines who receives the warning.

  • Option A (Quick): Simply enter the email addresses of the administrators in the Alert recipients (email) field (separated by semicolons).

  • Option B (Formal): If you already use an 'Action Group' for other alerts, select it under Action Group. If not, Option A is sufficient.