Use this page to separate the main Sentinel cost levers: ingestion commitment, table plans, retention, and Microsoft 365 data grants. Use the Azure pricing calculator for exact regional prices before quoting a customer.
Commitment Strategy
Choice
Use when
Planning note
Pay as you go
Variable or pilot workloads
No daily commitment; highest flexibility
100 GB/day+
Predictable production ingestion
Commitment tier pricing starts at 100 GB/day and overage is billed at the selected tier rate
Dedicated cluster
Large multi-workspace estates
Can aggregate eligible workspace ingestion but unused commitment is still billed
Pick the table plan by detection value first, then optimize verbose sources with Basic or Auxiliary when the documented query and feature limitations are acceptable.
Log table plan selection flow
flowchart TD
A[New log source] --> B{Used for detections}
B -->|Yes| C[Analytics table]
B -->|No| D{Needs frequent investigation}
D -->|Yes| E[Basic table]
D -->|No| F[Auxiliary table]
C --> G[Set interactive retention]
E --> H[Check query limitations]
F --> I[Use search jobs for rare investigations]
Plan
Use for
Constraint
Analytics
Security detections, incidents, hunting, automation, and multi-table KQL
Full Sentinel and Azure Monitor analytics behavior
Basic
Verbose troubleshooting data that still needs cheaper interactive access
Single-table query limitations; query charges are based on data scanned
Auxiliary
Low-touch audit/compliance data with infrequent searches
Lowest-cost ingestion pattern; unoptimized queries and feature limitations