Softwr
Microsoft Sentinel logo

Microsoft Sentinel

Cloud-native SIEM and SOAR solution

Overview

What Microsoft Sentinel does

Microsoft Sentinel is a scalable, cloud-native SIEM and SOAR solution that delivers intelligent security analytics across the enterprise. It provides AI-powered threat detection and automated response capabilities.

What people use it for

  • Cloud native SIEM collecting security logs across Azure, Microsoft 365 and third party sources
  • Threat detection, hunting and incident investigation over pooled log data
  • Automating incident response with playbooks built on Logic Apps

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Microsoft Sentinel.

  • Billing is driven by the volume of log data ingested per day, so cost scales with log noise rather than with users or protected assets
  • Commitment tier discounts require reserving daily ingestion capacity in advance, and a tier cannot be downgraded until 31 days have passed
  • Commitment tiers start at 100 GB per day, above what smaller estates ingest
  • Charges for Log Analytics, Logic Apps and Machine Learning are billed separately on top of Sentinel itself
  • The free allowance is only up to 5 MB per user per day for selected Microsoft 365 security logs
  • Promotional commitment pricing is time limited and locks in only until a stated end date

Pricing

What Microsoft Sentinel costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Pay-As-You-Go

$2.46 /day

  • Per GB ingested
  • 90-day retention
  • First 31 days free for new workspaces

Commitment Tiers

Free

  • 100GB to 50TB tiers
  • Up to 65% discount
  • Predictable billing

Microsoft 365 E5

Free

  • Free data ingestion for M365 logs
  • Bundled with E5 license

Capabilities

Features

  • AI-powered analytics

    AI-powered analytics capability

  • Fusion detection

    Fusion detection capability

  • UEBA

    UEBA capability

  • Automated response playbooks

    Automated response playbooks capability

  • Threat intelligence

    Threat intelligence capability

  • Hunting queries

    Hunting queries capability

  • Workbooks

    Workbooks capability

  • Incident management

    Incident management capability

  • Microsoft 365

    Integration with Microsoft 365

  • Azure services

    Integration with Azure services

  • AWS

    Integration with AWS

  • Google Cloud

    Integration with Google Cloud

Behind it

Who makes Microsoft Sentinel

Company
Microsoft Corporation
Based in
Redmond, Washington, USA

Keep looking

Where to go from Microsoft Sentinel

Other Security Cybersecurity software

Softwr does not host reviews and shows no star rating for Microsoft Sentinel, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Microsoft Sentinel