Getting started with Microsoft Sentinel on a budget
How small organisations can get real value from Microsoft Sentinel while keeping ingestion costs under control: free data sources, selective logging and cost monitoring.
Microsoft Sentinel is a cloud-native SIEM built on Azure Log Analytics. You pay mainly for the data you ingest and keep, which means a small organisation can run a useful SOC capability on a modest budget — if it is deliberate about which data goes in. This article walks through a cost-conscious starting point.
Understand what drives cost
- Ingestion volume into the analytics tier is the main cost driver, billed per GB.
- Retention beyond the included period (Sentinel-enabled workspaces include 90 days of analytics retention) adds cost.
- Automation with Logic Apps playbooks is billed per execution; automation rules themselves are free.
- Lower-cost tiers exist for high-volume, low-value logs (for example Basic / Auxiliary logs and the Sentinel data lake), with trade-offs in query and detection capabilities.
Step 1 — Decide what you want to detect
Start from risks, not from data sources. For most small Microsoft 365 organisations the priorities are compromised identities, malicious email, risky admin activity and endpoint threats. That list tells you which logs actually matter.
Step 2 — Create one workspace
Create a single Log Analytics workspace in a region that fits your data-residency needs (for Nordic organisations, e.g. Sweden Central or another EU region) and enable Microsoft Sentinel on it. Microsoft is unifying Sentinel into the Microsoft Defender portal, so plan to operate it there alongside Defender XDR. New workspaces typically come with a free trial period — use it to measure your real ingestion before costs start.
Step 3 — Turn on the free and high-value sources first
| Source | Cost note | Why it matters |
|---|---|---|
| Azure Activity | Free to ingest | Who changed what in your Azure subscriptions |
| Microsoft 365 (Office 365) audit logs — Exchange, SharePoint, Teams | Free to ingest | Mailbox rules, file sharing, admin changes |
| Microsoft Defender XDR incidents & alerts | Alerts/incidents free; raw advanced-hunting tables are billable | Brings existing Defender detections into one queue |
| Microsoft Entra ID sign-in & audit logs | Billable — but usually worth it | The core of identity threat detection |
Some Microsoft 365 E5-type licences include a data-ingestion benefit for certain Microsoft data sources. Check whether yours does before you estimate costs.
Step 4 — Be selective with noisy sources
- Windows security events: use the Azure Monitor Agent with a data collection rule set to Common or Minimal — or a custom XPath filter — rather than All events.
- Firewall, proxy and syslog data: filter at the source or with data collection rule transformations; consider a lower-cost tier for verbose logs you rarely query.
- Raw Defender advanced-hunting tables: stream only the tables you actually use in detections.
Step 5 — Use built-in content
Install the relevant solutions from the Content hub and enable analytics rule templates for the data you ingest. Start with a small set, tune out noise, and add rules gradually. Built-in workbooks give quick visibility without custom development.
Step 6 — Watch your ingestion
Run this query in the workspace to see which tables drive your bill over the last 30 days:
Usage
| where TimeGenerated > ago(30d)
| where IsBillable == true
| summarize IngestedGB = sum(Quantity) / 1000 by DataType
| sort by IngestedGB desc
Pair it with an Azure Cost Management budget and alert on the resource group. Be careful with a workspace daily cap: it stops data collection once reached, which can blind your detections exactly when an incident is generating extra logs.
Step 7 — Automate the boring parts
Use automation rules (free) to assign, tag and close known-benign incidents. Add Logic Apps playbooks only where they save real analyst time — for example notifying a Teams channel or enriching an incident.
A realistic small-tenant starting point
- Sentinel on one workspace, operated from the Defender portal.
- Free connectors: Azure Activity, Microsoft 365, Defender XDR incidents.
- Entra ID sign-in and audit logs.
- A short list of tuned analytics rules and automation rules.
- A monthly review of the
Usagequery and the cost budget.
From there you can grow coverage deliberately — adding endpoints, network devices or third-party SaaS only when you know what you will detect with them.