Cybersecurity · head to head
Microsoft Sentinel vs Semperis

Semperis
Cybersecurity
Identity threat detection and Active Directory forest recovery for AD, Entra ID and Okta, from a privately held US vendor.
- From
- On request
- Rated
- -
The short version
- Only Microsoft Sentinel has a free tier, so it costs nothing to try first.
- Each has a real cost: Microsoft Sentinel billing is driven by the volume of log data ingested per day, so cost scales with log noise rather than with users or protected assets; Semperis scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
- They diverge on capability: Microsoft Sentinel covers AI-powered analytics, Semperis covers Active Directory Forest Recovery.
- Prices and features above were last checked on 30 August 2026.
Where they differ
Only the attributes on which Microsoft Sentinel and Semperis actually diverge.
| Attribute | Microsoft Sentinel | Semperis |
|---|---|---|
| Starting price | Free | On request |
| Pricing model | usage-based | quote |
| Free tier | Yes | No |
| Platforms | Web, Api | Web |
| Founded | 1975 | Unknown |
Identical on both: user rating (Not yet rated), category (Cybersecurity).
What each one covers
Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.
Only in Microsoft Sentinel
- AI-powered analytics
- Fusion detection
- UEBA
- Automated response playbooks
- Threat intelligence
- Hunting queries
- Workbooks
- Incident management
Only in Semperis
- Active Directory Forest Recovery
- Malware-free restore
- Replication-stream monitoring
- Automated rollback
- Attack indicator scoring
- Entra ID and Okta coverage
- Purple Knight
- Forest Druid
What people use each for
The jobs each tool is most often brought in to do.
Microsoft Sentinel
- Cloud-based security information and event management (SIEM)not Semperis
- Extended detection and response (XDR) across enterprise infrastructurenot Semperis
- Data ingestion and long-term security analyticsnot Semperis
Semperis
- An organisation that cannot answer an auditor or insurer asking how long it would take to rebuild Active Directory after a destructive attacknot Microsoft Sentinel
- Post-incident recovery where domain controllers are compromised and restoring from system-state backup would reintroduce the attacker's footholdnot Microsoft Sentinel
- Continuous detection of privileged group changes and directory-level tampering that domain controller security logs missnot Microsoft Sentinel
- Hybrid estates where AD, Entra ID and Okta all matter and no single tool currently shows changes across the threenot Microsoft Sentinel
Where each one falls short
Documented limitations, not opinions. Every one is a constraint you would hit in normal use.
Microsoft Sentinel
- Billing is driven by the volume of log data ingested per day, so cost scales with log noise rather than with users or protected assets
- Commitment tier discounts require reserving daily ingestion capacity in advance, and a tier cannot be downgraded until 31 days have passed
- Commitment tiers start at 100 GB per day, above what smaller estates ingest
- Charges for Log Analytics, Logic Apps and Machine Learning are billed separately on top of Sentinel itself
- The free allowance is only up to 5 MB per user per day for selected Microsoft 365 security logs
- Promotional commitment pricing is time limited and locks in only until a stated end date
Semperis
- Scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
- The licence buys tooling, not a proven runbook: forest recovery is only worth what your last rehearsal demonstrated, and a plan that has never been executed end to end in a lab is an untested assumption regardless of what was purchased.
- It overlaps with backup and directory management products from Quest, Veeam, Commvault and others, so the buyer must argue internally why a dedicated product is needed alongside a backup contract that already claims to protect Active Directory.
- Running Directory Services Protector well requires someone who understands AD internals, replication metadata and Tier 0 attack paths, and without that person the alerts on privileged changes are either ignored or auto-reverted in ways that break legitimate administration.
- Licensing is driven by identity object counts, so directories carrying years of stale user accounts and service principals pay for objects that should have been deleted, and the cleanup project that would reduce the bill is the one nobody has time for.
Pricing, plan by plan
Microsoft Sentinel
Free- Pay-As-You-Go$2.46/day
- Per GB ingested
- 90-day retention
- First 31 days free for new workspaces
- Commitment TiersFree
- 100GB to 50TB tiers
- Up to 65% discount
- Predictable billing
- Microsoft 365 E5Free
- Free data ingestion for M365 logs
- Bundled with E5 license
Semperis
On requestNo published plan breakdown. See the Semperis review.
Which should you pick?
Choose Microsoft Sentinel if
- You need ai-powered analytics.
- You want to start without paying.
- You work on Web, Api.
- You also want fusion detection.
Choose Semperis if
- You need active directory forest recovery.
- You also want malware-free restore.
Questions people ask
- Is Microsoft Sentinel or Semperis better?
- Neither clearly leads. Microsoft Sentinel starts at Free and Semperis at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
- Which is cheaper, Microsoft Sentinel or Semperis?
- Microsoft Sentinel has a free tier; the other does not. Paid plans start at Free for Microsoft Sentinel and On request for Semperis.
- Does Microsoft Sentinel or Semperis run on more platforms?
- Microsoft Sentinel runs on Web, Api. Semperis runs on Web.
- Can I use Microsoft Sentinel for free?
- Yes. Microsoft Sentinel has a free tier, so you can try it without paying. Semperis starts at On request.
- What is Microsoft Sentinel best used for?
- Microsoft Sentinel is most often used for cloud-based security information and event management (siem), extended detection and response (xdr) across enterprise infrastructure, data ingestion and long-term security analytics. Of those, cloud-based security information and event management (siem) and extended detection and response (xdr) across enterprise infrastructure are not what Semperis is typically brought in for.
- What can Microsoft Sentinel do that Semperis cannot?
- Microsoft Sentinel covers AI-powered analytics, Fusion detection, UEBA, Automated response playbooks. Semperis covers Active Directory Forest Recovery, Malware-free restore, Replication-stream monitoring, Automated rollback.
Answered from the vendors’ own pages
Microsoft Sentinel: How is Microsoft Sentinel pricing calculated?
Microsoft Sentinel uses a pay-as-you-go usage-based model where you pay only for data ingested, stored, and consumed. Flexible commitment tiers are available to reduce total cost of ownership, with specific rates not published on the public pricing page. Source: https://www.microsoft.com/security/business/siem-and-xdr/microsoft-sentinel/
SourceSemperis: Does this replace my backups?
No. It replaces the Active Directory recovery procedure specifically. You still need backups for everything else, and the point of Semperis is that a generic system-state backup of a domain controller is a poor way to recover a forest because it restores the operating system along with whatever compromised it.
Microsoft Sentinel: Does Microsoft Sentinel require an Azure subscription?
Yes, Microsoft Sentinel requires a Microsoft Azure subscription to operate. Pricing is handled through Azure and varies based on data consumption and the commitment tier you select. Source: https://www.microsoft.com/security/business/siem-and-xdr/microsoft-sentinel/
SourceSemperis: Is it useful if we are cloud-only on Entra ID?
Partly. Directory Services Protector covers Entra ID and Okta for change tracking and posture, but the forest recovery product, which is the strongest reason to buy, applies to on-premises Active Directory. A genuinely cloud-only organisation should weigh it against Microsoft's own tooling.
Semperis: Are Purple Knight and Forest Druid really free?
Yes, both are free downloads with no licence requirement, and they are widely used by organisations that are not Semperis customers. They are also, transparently, the top of the sales funnel.
Semperis: How long does forest recovery actually take?
The honest answer is whatever your rehearsal took. The vendor's case is hours instead of days, and automation genuinely removes most manual steps, but the number that matters for your board is the one from a test in your own environment.
Semperis: Does it require agents on domain controllers?
It collects directory changes from the AD replication stream, which is what lets it see changes that bypass the security log. Deployment details vary by product and version, so confirm the exact architecture against your domain controller change-control rules.
Related pages
More on Microsoft Sentinel
Other head to heads
- Microsoft Sentinel vs Bitdefender Total Security
- Microsoft Sentinel vs Norton 360
- Microsoft Sentinel vs 1Password
- Microsoft Sentinel vs LastPass
- Microsoft Sentinel vs LogRhythm SIEM
- Microsoft Sentinel vs IBM QRadar
- Microsoft Sentinel vs CrowdStrike Falcon
- Microsoft Sentinel vs Splunk Enterprise Security
- Microsoft Sentinel vs SentinelOne Singularity
- Microsoft Sentinel vs Legit Security
- Microsoft Sentinel vs Sysdig
- Microsoft Sentinel vs Endor Labs
- Microsoft Sentinel vs Proton Mail
- Microsoft Sentinel vs Veriff
- Microsoft Sentinel vs Brave Browser
- Microsoft Sentinel vs March Networks
- Microsoft Sentinel vs Salient CompleteView
- Microsoft Sentinel vs Sumsub
- Microsoft Sentinel vs NICE Actimize
- Microsoft Sentinel vs Netwrix
- Microsoft Sentinel vs VMware Carbon Black
- Microsoft Sentinel vs One Identity
- Microsoft Sentinel vs Ping Identity
- Microsoft Sentinel vs Signicat
- Microsoft Sentinel vs Authy
- Microsoft Sentinel vs Baffle
- Microsoft Sentinel vs Beyond Identity
- Microsoft Sentinel vs BeyondTrust
- Microsoft Sentinel vs Burp Suite
- Microsoft Sentinel vs Bitdefender VPN
- Semperis vs Bitdefender Total Security
- Semperis vs Norton 360
- Semperis vs 1Password
- Semperis vs LastPass
- Semperis vs LogRhythm SIEM
- Semperis vs IBM QRadar
- Semperis vs CrowdStrike Falcon
- Semperis vs Splunk Enterprise Security
- Semperis vs SentinelOne Singularity
- Semperis vs Legit Security
- Semperis vs Sysdig
- Semperis vs Endor Labs
- Semperis vs Proton Mail
- Semperis vs Veriff
- Semperis vs Brave Browser
- Semperis vs March Networks
- Semperis vs Salient CompleteView
- Semperis vs Sumsub
- Semperis vs NICE Actimize
- Semperis vs Netwrix
- Semperis vs VMware Carbon Black
- Semperis vs One Identity
- Semperis vs Ping Identity
- Semperis vs Signicat
- Semperis vs Authy
- Semperis vs Baffle
- Semperis vs Beyond Identity
- Semperis vs BeyondTrust
- Semperis vs Burp Suite
- Semperis vs Bitdefender VPN

