Microsoft

Microsoft Sentinel

Security & identity

Cloud-native SIEM and SOAR — collect security logs at scale, detect, and automate response.

List price
Consumption — per GB of data ingested; commitment tiers reduce the rate
Billing
Azure consumption
Support
Managed by Madatech

Overview

Sentinel is Microsoft's SIEM: it collects security logs from across your estate, runs detections, and can trigger automated response. Cost is driven by how much you ingest, so the design conversation is mostly about what's worth collecting.

Key features

Connectors for Microsoft 365, Entra, Azure and third-party sourcesAnalytics rules and UEBA for detectionPlaybooks (Logic Apps) for automated responseIncident investigation with entity graphsData lake tier for cheap long-term retention

How we deploy it

1

Scope the data

Decide which sources to ingest and the retention each needs — this drives cost.

2

Build

Connect sources, enable analytics rules, write the first playbooks.

3

Run

Tune noise, set commitment tiers, and agree an on-call model.

Get pricing for Microsoft Sentinel

We'll prepare a quote in your local currency — no commitment.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin. Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session. Please retry or reload the page.