Identra

Solutions / Sentinel deployment

Microsoft Sentinel deployment that does not run away on ingestion cost.

Microsoft Sentinel is priced on ingested data volume. A naive deployment that turns on every connector produces a Sentinel bill three to five times what the security team actually needs. Identra deploys Sentinel with source-by-source data value assessment, commitment tier sizing, archive tier for cold data, and MITRE ATT&CK-mapped detection rules aligned to the connected data. Result: measurable coverage at controlled cost.

Product
Microsoft Sentinel (Log Analytics + SIEM)
License requirement
Sentinel per-GB or commitment tier
Delivery mode
Remote-first, US timezone
Delivery
Fixed scope, fixed price

01 / What we configure

Four workstreams for a controlled Sentinel deployment.

  • 01

    Data source assessment

    Every connector evaluated for detection value versus ingestion cost. Defender XDR raw data and security alerts (free), Azure Activity, Office 365 audit, Entra ID Protection (free) enabled first. Firewall, DNS, VPN, and endpoint noisier sources evaluated per source with filter rules to drop low-value events at ingest.

    Free connectorsFilter rulesValue/cost
  • 02

    Commitment tier and archive

    Ingestion volume forecast against the commitment tier ladder (100GB/day, 200, 300, 500, 1000, 2000, 5000+). Commitment tier locked in at the level that pays back within the first month, dropping effective rate 30 to 55 percent versus pay-as-you-go. Cold data moved to archive tier (14 days online, 12 years archive) at 1/10 the cost.

    Commitment tierArchiveCost savings
  • 03

    MITRE ATT&CK coverage

    Detection rules mapped to MITRE ATT&CK tactics and techniques. Coverage matrix identifies which techniques are covered by connected data sources and which have gaps. Priority detections built for Initial Access, Credential Access, Persistence, and Exfiltration tactics.

    MITRE ATT&CKCoverage matrixPriority detections
  • 04

    Playbooks and automation

    Logic Apps playbooks defined for common response actions: disable user, block IP, isolate device, notify tier-2. Playbooks tested end-to-end before production. Automation rules trigger playbooks on high-confidence incidents so the SOC operator arrives at a triaged case, not a raw alert.

    Logic AppsAutomation rulesSOC workflow

02 / What it looks like

Three Sentinel deployment engagements.

Different starting states, same cost and coverage discipline.

CISO at a 3,000-user US professional services firm

Situation. Sentinel enabled 6 months ago. Every Defender source connected without filtering. Monthly Sentinel bill running at $18k against a budgeted $6k. CFO asking to turn it off.

Outcome. Ingestion audit identified 60 percent of ingested data was low-value endpoint chatter. Filter rules dropped low-value data at source. 200 GB/day commitment tier replaced pay-as-you-go. New monthly bill $5.2k, under budget, with equal or better MITRE coverage.

IT Director at a US SaaS company

Situation. Preparing for SOC 2 Type II audit. Auditor asked for evidence of detection coverage on production infrastructure and formal incident response workflow. Existing environment used a mix of CloudWatch and Defender XDR alerts sent to Slack.

Outcome. Sentinel deployed with AWS CloudTrail and Defender XDR connectors. MITRE coverage matrix documented for the audit. Logic Apps playbooks defined for the SOC 2 incident response workflow. Type II observation window ran clean.

Security Operations Manager at a Texas-based healthcare system

Situation. Existing SIEM contract renewing at 40 percent increase. HIPAA-scoped detection coverage needed to remain equivalent or better. Move to Sentinel considered but no in-house KQL skills to make it work.

Outcome. Sentinel deployed with 300 GB/day commitment tier. HIPAA-aligned detection rules deployed with KQL library documented. Two-day training for the SOC team on Sentinel workbooks and Advanced Hunting. Existing SIEM contract cancelled at renewal.

03 / Frequently asked

What buyers ask first.

How is Microsoft Sentinel priced?
Sentinel is priced per GB of data ingested. Pay-as-you-go ranges from about $2.46/GB in lower-cost US regions to about $5.13/GB in higher-cost regions. Commitment tiers (100 GB/day and up) reduce the effective rate to $1.10 to $1.23 per GB depending on volume, saving up to 55 percent over PAYG. Free data sources include Defender XDR raw data and security alerts (Defender for Endpoint, Identity, Office 365, Cloud Apps), Azure Activity, Office 365 audit, and Entra ID Protection alerts.
How do we control Sentinel cost?
Four levers. First, only ingest data with detection value: many customers ingest firewall or DNS logs without a matching detection rule and pay for storage of unused data. Second, use commitment tier if daily ingest is 100 GB+, effective rate drops 40 to 55 percent. Third, archive cold data (14 days online, 12 years archive) at 1/10 the online storage cost. Fourth, use Auxiliary Logs (2023 GA) at a lower price tier for very high-volume, low-detection-value sources.
What is the relationship between Sentinel and Defender XDR?
Defender XDR is the endpoint, identity, email, and cloud app detection stack. Sentinel is the SIEM that can ingest Defender XDR alerts plus data from any other source (AWS, GCP, on-prem, third-party SaaS). Small tenants running only Microsoft workloads often do not need Sentinel; Defender XDR alone covers the detection surface. Multi-cloud, hybrid, or SIEM-required organisations need both.
Do you provide managed SOC services on top of the deployment?
Identra engagements are consultative: deploy, tune, hand over. We do not provide 24/7 managed SOC or MDR services. Customers who need managed operations typically pair Identra deployment with an MSSP for 24/7 tier-1 and tier-2 operations. We can refer to trusted US-based MSSP partners.
How long does a Sentinel deployment take?
Typical deployment runs 8 to 14 weeks. Weeks 1 to 3 assess data sources and forecast ingestion volume. Weeks 4 to 10 configure connectors, filter rules, and commitment tier. Weeks 11 to 14 build detection rules, playbooks, and workbooks. Multi-cloud or SIEM-migration engagements can run longer.

Next step

Book a Sentinel scoping call.

Thirty minutes on your data sources, current ingestion cost, and coverage gaps. Written scoping note within two business days.