Skip to main content

Compare

WitFoo and Microsoft Sentinel

Microsoft documents Sentinel’s billing more thoroughly than most vendors document anything, and publishes its rates. The difficulty is not that the pricing is hidden. It is how many separate meters you have to forecast, and the fact that one of them reads every query you run.

The short answer

Sentinel is an Azure service. You enable it on an Azure Monitor Log Analytics workspace, and it “runs on Azure infrastructure that accrues costs when you deploy new resources”. There is no self-hosted build, which makes this the one comparison on this site where deployment is a genuine dividing line rather than a point we have to concede.

The analytics tier has two ways to pay — pay-as-you-go or a commitment tier — and that is the part most people price out. Underneath it sit more: data lake ingestion, data processing, data lake storage, data lake query, advanced data insights, graph compute, retention past 90 days, Logic Apps for automation, and Azure Functions for some connectors. Each is documented, each has its own rate, and each is a line on the invoice.

WitFoo Analytics has one. $25,000 per appliance per year to start, unlimited data rates, retention included, and no unit that moves when an analyst runs a query. If your telemetry is mostly Microsoft’s, Sentinel’s free tiers may beat that outright — the section near the bottom of this page explains when.

The two models, question by question

Every Sentinel claim below is quoted from Microsoft’s own billing documentation, with a link. None of them is a price — Azure rates are regional and move, and the third-party trackers already disagree about them. Checked 19 September 2026 — pricing moves, so verify before you sign anything.

How many meters run at once?

WitFoo Analytics

One. An annual fee per appliance covering ingestion, retention, search and reporting, with unlimited data rates in every tier.

Microsoft Sentinel

The analytics tier is one decision; the data lake tier alone adds five more meters, before graph compute, Logic Apps automation and Azure Functions connectors.

“Data lake ingestion is charged per GB … Data processing is charged per GB … Data lake storage charges are applied per GB per month … Data lake query charges apply per GB of uncompressed data scanned … Advanced data insights charges apply per compute hour used.”
Microsoft Sentinel documentation

Does running a query cost money?

WitFoo Analytics

No. There is no query meter, so an investigation has no marginal cost.

Microsoft Sentinel

Against the data lake tier, yes — charged on uncompressed volume scanned, so an imprecise KQL query costs more than a precise one.

“Data lake query charges apply per GB of uncompressed data scanned using Kusto Query Language (KQL) queries or KQL jobs.”
Microsoft Sentinel documentation

Is retention a separate charge?

WitFoo Analytics

No. Retention is a function of the appliance you bought, not a second meter.

Microsoft Sentinel

Free for 90 days, charged after that at Log Analytics retention prices, with a lower-cost lake tier for long-term data charged on both volume stored and volume scanned.

“Retain all data ingested into the workspace at no charge for the first 90 days. Retention beyond 90 days is charged per the standard Log Analytics retention prices.”
Microsoft Sentinel documentation

Can you reduce your commitment if you over-buy?

WitFoo Analytics

There is no commitment to reduce. The licence is per appliance, per year.

Microsoft Sentinel

Commitment tiers discount heavily against pay-as-you-go, and Microsoft describes the saving as substantial. Coming back down is rate-limited.

“Lowering the Commitment tier is only allowed every 31 days.”
Microsoft Sentinel documentation

Can it run on infrastructure you own, or air-gapped?

WitFoo Analytics

Yes — on-premises, hypervisor, bare metal or your own cloud account, including fully air-gapped, with no cloud callbacks and an AI assistant that can run against a local model.

Microsoft Sentinel

No. Sentinel is an Azure service enabled on a Log Analytics workspace. If your environment cannot reach Azure, Sentinel is not an option at any price.

“Microsoft Sentinel runs on Azure infrastructure that accrues costs when you deploy new resources.”
Microsoft Sentinel documentation

What comes in free?

WitFoo Analytics

Everything, in the sense that nothing is metered — but there is no free tier either. The licence starts where it starts.

Microsoft Sentinel

A genuinely valuable list: Azure Activity, Sentinel Health, Office 365 audit logs, and Defender security alerts. The nuance Microsoft documents itself is that alerts are free while the underlying raw logs often are not.

“Although alerts are free, the raw logs for some Microsoft Defender XDR, Defender for Endpoint/Identity/Office 365/Cloud Apps, Microsoft Entra ID, and Azure Information Protection (AIP) data types are paid.”
Microsoft Sentinel documentation

What happens when you turn it off?

WitFoo Analytics

The appliance stops costing you anything at renewal. There is nothing else running.

Microsoft Sentinel

Removing Sentinel leaves the workspace behind, and the workspace keeps billing.

“Removing Microsoft Sentinel doesn’t remove the Log Analytics workspace Microsoft Sentinel was deployed on, or any separate charges that workspace might be incurring.”
Microsoft Sentinel documentation

When Microsoft Sentinel is the better answer

Six cases where Sentinel is the right purchase — and the first one covers a very large number of organisations.

  • Your estate is mostly Microsoft. Azure Activity, Office 365 audit logs and Defender alerts ingest free, and the Microsoft 365 E5 benefit grants up to 5 MB per user per day for Entra sign-in and audit logs, Defender for Cloud Apps shadow IT discovery, Purview Information Protection and advanced hunting data. At enough seats that grant is a large amount of free ingestion, and no flat licence competes with free.

  • You do not want to run infrastructure at all. There is no appliance, no capacity planning and no upgrade window — Sentinel scales elastically and Microsoft operates it. We ship you a box to look after.

  • You need native depth into Entra, Defender XDR and Purview. Cross-product correlation inside Microsoft’s own security stack is something a third party integrates with rather than owns.

  • Your volume is genuinely unpredictable or seasonal. A consumption meter absorbs a quiet quarter; a fixed annual licence does not.

  • You want a very large community content library. The Sentinel repository of analytics rules, hunting queries, workbooks and playbooks is extensive and free.

  • You are already committed to Azure. If your data lives there, keeping security analytics next to it avoids an egress problem and a second operational surface.

When WitFoo Analytics is the better answer

Held to the same standard, which on this page produces a shorter list than the one above.

  • You cannot reach Azure, or you have decided not to. Air-gapped, classified, sovereign or contractually on-premises — for these, Sentinel is not a more expensive option, it is not an option. This is the clearest dividing line between the two products.

  • You want investigation to be free at the margin. No query meter means an imprecise search during an incident costs nothing, and nobody has to write efficient KQL to protect a budget.

  • You want one number a year ahead. One line item per appliance, published, with no tier to right-size, no commitment to ratchet and no second product’s meters underneath.

  • Your telemetry is mostly not Microsoft’s. Sentinel’s free tiers are what make it cheap, and they apply to Microsoft sources. A firewall-and-Linux estate pays full freight for nearly all of it.

  • You want to keep Sentinel and spend less on it. Conductor sits in front, deduplicates and reduces before the meter reads, and forwards what is worth analysing as CEF or syslog. Your workbooks and analytics rules are untouched.

  • You are buying several appliances, or you are government, nonprofit or education. Volume discounts apply automatically per product line, and the public-sector discount stacks on the order total.

When Sentinel simply wins on cost

This is not a close call in every case, and pretending otherwise would waste your time.

If you are an all-Microsoft shop with E5, do the arithmetic before you talk to us. Defender alerts, Office 365 audit logs and Azure Activity cost nothing, and the E5 grant adds up to 5 MB per user per day on top. At a few thousand seats that is a lot of free ingestion, and a flat annual licence cannot beat free. The case for us gets stronger the more of your telemetry comes from something other than Microsoft.

Microsoft also deserves credit on transparency. The billing documentation is detailed, the meters are named, the rates are published per region, and the cost estimator is public. Our complaint is about the number of meters you have to forecast, not about anyone hiding them — and a commitment tier, sized correctly, is genuinely predictable.

And flat rate is not automatically cheaper. Analytics starts at $25,000 a year whether you send it a terabyte or a trickle, and an appliance has finite capacity — “unlimited data rates” means we do not meter you, not that one box absorbs arbitrary growth. Past a point you add another appliance and your cost steps up. What changes is the shape of the curve: cost steps when you add capacity, rather than rising every time you add evidence or run a query.

Questions people actually ask

Can Microsoft Sentinel run on-premises or air-gapped?

No. Sentinel is enabled on an Azure Monitor Log Analytics workspace and, in Microsoft’s words, “runs on Azure infrastructure that accrues costs when you deploy new resources”. There is no self-hosted build. For an air-gapped, classified or sovereign environment that cannot reach Azure, Sentinel is not a more expensive option — it is not an option. This is the sharpest difference between Sentinel and WitFoo Analytics, which is air-gap capable with no cloud callbacks.

How is Microsoft Sentinel priced?

The analytics tier has two ways to pay: pay-as-you-go, based on data volume, or a commitment tier that reserves daily capacity at a discount and starts at 100 GB per day. Beneath that sit further meters — data lake ingestion, data processing, data lake storage, data lake query, advanced data insights, graph compute — plus retention beyond 90 days, Logic Apps for automation, and Azure Functions for some connectors. All are documented by Microsoft, and all are separate line items.

Does Microsoft Sentinel charge for running queries?

Against the data lake tier, yes: “Data lake query charges apply per GB of uncompressed data scanned using Kusto Query Language (KQL) queries or KQL jobs.” Because the meter reads uncompressed volume scanned, a broad query costs more than a narrow one. Queries against the analytics tier are not separately metered. WitFoo Analytics has no query meter at all.

What is free in Microsoft Sentinel?

Azure Activity logs, Sentinel Health, Office 365 audit logs including SharePoint, Exchange and Teams activity, and security alerts from the Microsoft Defender products. Microsoft also documents the catch worth knowing: “Although alerts are free, the raw logs for some Microsoft Defender XDR, Defender for Endpoint/Identity/Office 365/Cloud Apps, Microsoft Entra ID, and Azure Information Protection (AIP) data types are paid.” Separately, Microsoft 365 E5, A5, F5 and G5 customers on EA, EAS or CSP agreements get a grant of up to 5 MB per user per day.

Can I lower my Sentinel commitment tier if I over-commit?

Yes, but not freely: “Lowering the Commitment tier is only allowed every 31 days.” Raising it is unrestricted. It is worth sizing the tier against a real month of data rather than a forecast, because the adjustment is asymmetric.

Can I reduce my Sentinel bill without replacing Sentinel?

Usually, and for a Microsoft-centric SOC that is often the sensible move. WitFoo Conductor sits in front of Sentinel, deduplicates and reduces on the way in, and forwards what is worth analysing as CEF or syslog — CEF lands in the CommonSecurityLog table. Your analytics rules, workbooks and playbooks are untouched; what changes is how much data reaches the meter.

Some SOCs cannot reach the cloud at all.

WitFoo Analytics starts at $25,000 per appliance per year — air-gap capable, no cloud callbacks, no query meter, and an AI assistant that can run against a local model. Or keep Sentinel and put Conductor in front of it.