
Microsoft Sentinel
Microsoft Sentinel is Azure's cloud-native SIEM for log analytics, threat detection, investigation and automated SOC response.
0 upvotes · 0 downvotes
- Pricing
- Paid
- Platforms
- Web
- Reviewed
- Last reviewed 1 October 2026
- Links
- Website
What it is
Microsoft Sentinel is Microsoft's cloud-native security information and event management (SIEM) service, built on Azure. Security teams ingest logs and signals from Microsoft and third-party sources, run analytics and hunting, investigate incidents, and automate response with playbooks, with usage-based pricing tied to data ingested, stored and consumed.
What it helps with
- Consolidating security telemetry from cloud, identity, endpoint and network sources into one workspace.
- Detecting threats with built-in and custom analytics rules aligned to common attack patterns.
- Investigating incidents with entity timelines, hunting queries and graph-style context.
- Automating containment and enrichment through security orchestration and response playbooks.
- Managing SIEM cost with pay-as-you-go and commitment tiers, including data lake options where offered.
- Supporting SOC workflows that already use Microsoft Defender, Entra ID and Azure Monitor.
Who it's for
SOC analysts, detection engineers and security architects in organisations that want a cloud SIEM on Azure, especially those already invested in Microsoft security and Log Analytics workspaces.
Worth knowing
Microsoft Sentinel requires an Azure subscription and is billed primarily on data volume (analytics and related tiers), not a flat free SIEM. Microsoft publishes pay-as-you-go rates, commitment tiers and occasional promotions; a free trial may be available for evaluation. Official product and pricing pages are on Microsoft Security and Azure. Distinct from SentinelOne (a separate EDR vendor). This listing covers authorised defensive SIEM use only.