Skip to content

Commit df565a0

Browse files
authored
Merge pull request #280430 from austinmccollum/austinmc-sentinel-p3
create prepurchase plan article for Sentinel
2 parents ea48d7f + 4d5687b commit df565a0

11 files changed

+159
-43
lines changed

articles/cost-management-billing/reservations/prepare-buy-reservation.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,7 @@ You can purchase reservations from Azure portal, APIs, PowerShell, CLI. Read the
9393
- [Defender for Cloud - Pre-Purchase](/azure/defender-for-cloud/prepurchase-plan?toc=/azure/cost-management-billing/reservations/toc.json)
9494
- [Disk Storage](/azure/virtual-machines/disks-reserved-capacity)
9595
- [Microsoft Fabric](fabric-capacity.md)
96+
- [Microsoft Sentinel - Pre-Purchase](../../sentinel/billing-pre-purchase-plan.md?toc=/azure/cost-management-billing/reservations/toc.json)
9697
- [SAP HANA Large Instances](prepay-hana-large-instances-reserved-capacity.md)
9798
- [Software plans](/azure/virtual-machines/linux/prepay-suse-software-charges?toc=/azure/cost-management-billing/reservations/toc.json)
9899
- [SQL Database](/azure/azure-sql/database/reserved-capacity-overview?toc=/azure/cost-management-billing/reservations/toc.json)

articles/cost-management-billing/reservations/toc.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -120,12 +120,14 @@
120120
href: /azure/data-explorer/pricing-reserved-capacity
121121
- name: Dedicated Host
122122
href: /azure/virtual-machines/prepay-dedicated-hosts-reserved-instances?toc=/azure/cost-management-billing/reservations/toc.json
123-
- name: Defender for Cloud - Prepurchase
123+
- name: Defender for Cloud - Pre-Purchase
124124
href: /azure/defender-for-cloud/prepurchase-plan?toc=/azure/cost-management-billing/reservations/toc.json
125125
- name: Disk Storage
126126
href: /azure/virtual-machines/disks-reserved-capacity?toc=/azure/cost-management-billing/reservations/toc.json
127127
- name: Microsoft Fabric
128128
href: fabric-capacity.md
129+
- name: Microsoft Sentinel - Pre-Purchase
130+
href: /azure/sentinel/billing-prepurchase-plan?toc=/azure/cost-management-billing/reservations/toc.json
129131
- name: SAP HANA Large Instances
130132
href: prepay-hana-large-instances-reserved-capacity.md
131133
- name: Software plans

articles/sentinel/TOC.yml

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -476,8 +476,8 @@
476476
href: data-connectors/crowdstrike-falcon-data-replicator.md
477477
- name: Crowdstrike Falcon Data Replicator V2 (using Azure Functions)
478478
href: data-connectors/crowdstrike-falcon-data-replicator-v2.md
479-
- name: Cyber Blind Spot Intergration (using Azure Functions)
480-
href: data-connectors/cyber-blind-spot-intergration.md
479+
- name: Cyber Blind Spot Integration (using Azure Functions)
480+
href: data-connectors/cyber-blind-spot-integration.md
481481
- name: CyberArkAudit (using Azure Functions)
482482
href: data-connectors/cyberarkaudit.md
483483
- name: CyberArkEPM (using Azure Functions)
@@ -516,8 +516,8 @@
516516
href: data-connectors/eset-protect.md
517517
- name: Exabeam Advanced Analytics
518518
href: data-connectors/exabeam-advanced-analytics.md
519-
- name: Exchange Security Insights On-Premise Collector
520-
href: data-connectors/exchange-security-insights-on-premise-collector.md
519+
- name: Exchange Security Insights On-Premises Collector
520+
href: data-connectors/exchange-security-insights-on-premises-collector.md
521521
- name: Exchange Security Insights Online Collector (using Azure Functions)
522522
href: data-connectors/exchange-security-insights-online-collector.md
523523
- name: F5 BIG-IP
@@ -624,7 +624,7 @@
624624
href: data-connectors/microsoft-entra-id-protection.md
625625
- name: Microsoft Exchange Logs and Events
626626
href: data-connectors/microsoft-exchange-logs-and-events.md
627-
- name: Microsoft PowerBI
627+
- name: Microsoft Power BI
628628
href: data-connectors/microsoft-powerbi.md
629629
- name: Microsoft Project
630630
href: data-connectors/microsoft-project.md
@@ -1183,6 +1183,8 @@
11831183
href: billing-reduce-costs.md
11841184
- name: Switch to simplified pricing tiers
11851185
href: enroll-simplified-pricing-tier.md
1186+
- name: Optimize costs with pre-purchase plan
1187+
href: billing-pre-purchase-plan.md
11861188
- name: Tutorial - Configure data retention policy
11871189
href: configure-data-retention.md
11881190
- name: Auxiliary logs use cases
Lines changed: 93 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,93 @@
1+
---
2+
title: Optimize costs with a pre-purchase plan
3+
titleSuffix: Microsoft Sentinel
4+
description: Learn how to save costs and buy a Microsoft Sentinel pre-purchase plan
5+
author: austinmccollum
6+
ms.topic: how-to
7+
ms.date: 07/10/2024
8+
ms.author: austinmc
9+
ms.collection: usx-security
10+
#customerintent: As a SOC administrator or a billing specialist, I want to know how to buy a pre-purchase plan and whether commit units will benefit us financially.
11+
---
12+
13+
# Optimize Microsoft Sentinel costs with a pre-purchase plan
14+
15+
Save on your Microsoft Sentinel costs when you buy a pre-purchase plan. Pre-purchase plans are commit units (CUs) bought at discounted tiers in your purchasing currency for a specific product. The more you buy, the greater the discount. Purchased CUs pay down qualifying costs in US dollars (USD). So, if Microsoft Sentinel generates a retail cost of $100, then 100 Sentinel CUs (SCUs) are consumed.
16+
17+
Any eligible Microsoft Sentinel retail costs automatically deduct first from your SCUs over the course of its one year term or until they are depleted. Your pre-purchase plan SCUs start paying for your Microsoft Sentinel workspace costs without needing to redeploy or reassign the plan, and by default automatically renew to ensure you continue saving.
18+
19+
## Prerequisites
20+
21+
To buy a pre-purchase plan, you must have one of the following Azure subscriptions and roles:
22+
- For an Azure subscription, the owner role or reservation purchaser role is required.
23+
- For an Enterprise Agreement (EA) subscription, the [**Reserved Instances** policy option](../cost-management-billing/manage/direct-ea-administration.md#view-and-manage-enrollment-policies) must be enabled. To enable that policy option, you must be an EA administrator of the subscription.
24+
- For a Cloud Solution Provider (CSP) subscription, follow one of these articles:
25+
- [Buy Azure reservations on behalf of a customer](/partner-center/customers/azure-reservations-buying)
26+
- [Allow the customer to buy their own reservations](/partner-center/customers/give-customers-permission)
27+
28+
>[!NOTE]
29+
> Microsoft Sentinel Commit Units are different from Security Compute Units in Copilot for Security. Customers cannot use Sentinel Commit Units to run Copilot workloads and vice versa.
30+
31+
## Determine the right size to buy
32+
33+
Pre-purchase plans pair nicely with Microsoft Sentinel commitment tiers. Once you plan your Microsoft Sentinel ingestion volume, choose an appropriate commitment tier. Then it's easier to decide on the size of a pre-purchase plan to buy. Microsoft Sentinel pre-purchase plans have a term agreement of one year.
34+
35+
Here's an example of the decision making and cost savings for a pre-purchase plan. If you have a commitment tier of 200 GB/day, there's an associated monthly estimated cost for both the ingestion to the workspace and the analysis for Microsoft Sentinel. For example purposes, let's say that monthly cost is $20,000 USD with simplified pricing and provides a 39% savings over the pay-as-you-go tier with the same 200 GB/day.
36+
37+
A $100,000 USD pre-purchase plan covers five months of that commitment tier but is valid for paying Microsoft Sentinel costs for 12 months. That pre-purchase plan is bought at a 22% discount for $78,000 USD.
38+
39+
The savings for the commitment tier and the pre-purchase plan combine. The original pay-as-you-go price for five months of 200 GB/day ingestion and analysis costs is about $160,000 USD. With an accurate commitment tier and a pre-purchase plan, the cost is reduced to $78,000 USD for a combined savings of over 51%.
40+
41+
For more information, see the following articles:
42+
- [Switch to simplified pricing](enroll-simplified-pricing-tier.md)
43+
- [Set or change commitment tier](billing-reduce-costs.md#set-or-change-pricing-tier)
44+
45+
>[!IMPORTANT]
46+
> The prices mentioned are for example purposes only. To determine the latest commitment tier prices, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
47+
48+
All Microsoft Sentinel pricing tiers qualify for Microsoft Sentinel pre-purchase plans. From your Microsoft Sentinel bill, these costs are the entries with the **Sentinel** service name in the invoice details. These costs don't include Azure Monitor tiers, retention, restore and search costs. Eligible Microsoft Sentinel usage is deducted from the pre-purchased Microsoft Sentinel CUs automatically.
49+
50+
For more information on how to view Microsoft Sentinel simplified or classic pricing tiers in your invoice details, see [Understand your Microsoft Sentinel bill](billing.md#understand-your-microsoft-sentinel-bill).
51+
52+
Keep in mind, Microsoft Sentinel integrates with many other Azure services that have separate costs not eligible to use with the pre-purchase SCUs. For more information, see [Costs and pricing for other services](billing.md#costs-and-pricing-for-other-services).
53+
54+
## Purchase Microsoft Sentinel commit units
55+
56+
Purchase Microsoft Sentinel pre-purchase plans in the [Azure portal reservations](https://portal.azure.com/#view/Microsoft_Azure_Reservations/ReservationsBrowseBlade/productType/Reservations).
57+
58+
1. Go to the [Azure portal](https://portal.azure.com)
59+
1. Navigate to the **Reservations** service.
60+
1. On the **Purchase reservations page**, select **Microsoft Sentinel Pre-Purchase Plan**.
61+
1. On the **Select the product you want to purchase** page, select a subscription. Use the **Subscription** list to select the subscription used to pay for the reserved capacity. The payment method of the subscription is charged the upfront costs for the reserved capacity. Charges are deducted from the enrollment's Azure Prepayment (previously called monetary commitment) balance or charged as overage.
62+
1. Select a scope.
63+
- **Single resource group scope** - Applies the reservation discount to the matching resources in the selected resource group only.
64+
- **Single subscription scope** - Applies the reservation discount to the matching resources in the selected subscription.
65+
- **Shared scope** - Applies the reservation discount to matching resources in eligible subscriptions that are in the billing context. For Enterprise Agreement customers, the billing context is the enrollment.
66+
- **Management group** - Applies the reservation discount to the matching resource in the list of subscriptions that are a part of both the management group and billing scope.
67+
1. Select how many Microsoft Sentinel commit units you want to purchase.
68+
69+
`Need Sentinel screenshot here`
70+
:::image type="content" source="media/sentinel-pre-purchase-plan.png" alt-text="Screenshot showing Microsoft Sentinel pre-purchase plan discount tiers and their term lengths." lightbox="media/sentinel-pre-purchase-plan.png":::
71+
72+
1. Choose to automatically renew the pre-purchase reservation. *The setting is configured to renew automatically by default*. For more information, see [Renew a reservation](../cost-management-billing/reservations/reservation-renew.md).
73+
74+
## Change scope and ownership
75+
76+
You can make the following types of changes to a reservation after purchase:
77+
78+
- Update reservation scope
79+
- Update who can view or manage the reservation. For more information, see [Who can manage a reservation by default](../cost-management-billing/reservations/manage-reserved-vm-instance.md#who-can-manage-a-reservation-by-default).
80+
81+
You can't split or merge a **Microsoft Sentinel Pre-Purchase Plan**. For more information about managing reservations, see [Manage reservations after purchase](../cost-management-billing/reservations/manage-reserved-vm-instance.md).
82+
83+
## Cancellations and exchanges
84+
85+
Cancel and exchange isn't supported for **Microsoft Sentinel Pre-Purchase Plans**. All purchases are final.
86+
87+
## Related content
88+
89+
To learn more about Azure Reservations, see the following articles:
90+
- [What are Azure Reservations?](../cost-management-billing/reservations/save-compute-costs-reservations.md)
91+
- [Manage Azure Reservations](../cost-management-billing/reservations/manage-reserved-vm-instance.md)
92+
93+
To learn more about Microsoft Sentinel costs, see [Plan costs and understand Microsoft Sentinel pricing and billing](billing.md).

articles/sentinel/billing-reduce-costs.md

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
---
22
title: Reduce costs for Microsoft Sentinel
33
description: Learn how to reduce costs for Microsoft Sentinel by using different methods in the Azure portal.
4-
author: cwatson-cat
5-
ms.author: cwatson
4+
author: austinmccollum
5+
ms.author: austinmc
66
ms.custom: subject-cost-optimization
77
ms.topic: conceptual
8-
ms.date: 03/07/2024
8+
ms.date: 07/09/2024
99
appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
@@ -33,6 +33,14 @@ To learn more about how to monitor your costs, see [Manage and monitor costs for
3333

3434
For workspaces still using classic pricing tiers, the Microsoft Sentinel pricing tiers don't include Log Analytics charges. For more information, see [Simplified pricing tiers](billing.md#simplified-pricing-tiers).
3535

36+
## Buy a pre-purchase plan
37+
38+
Save on your Microsoft Sentinel costs when you pre-purchase Microsoft Sentinel commit units (CUs). Use the pre-purchased CUs at any time during the one year purchase term.
39+
40+
Any eligible Microsoft Sentinel costs deduct first from the pre-purchased CUs automatically. You don't need to redeploy or assign a pre-purchased plan to your Microsoft Sentinel workspaces for the CU usage to get the pre-purchase discounts.
41+
42+
For more information, see [Optimize Microsoft Sentinel costs with a pre-purchase plan](billing-pre-purchase-plan.md).
43+
3644
## Separate non-security data in a different workspace
3745

3846
Microsoft Sentinel analyzes all the data ingested into Microsoft Sentinel-enabled Log Analytics workspaces. It's best to have a separate workspace for non-security operations data, to ensure it doesn't incur Microsoft Sentinel costs.

articles/sentinel/data-connectors-reference.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -484,7 +484,7 @@ For more information about the codeless connector platform, see [Create a codele
484484
- [[Recommended] Forcepoint NGFW via AMA](data-connectors/recommended-forcepoint-ngfw-via-ama.md)
485485
- [Barracuda CloudGen Firewall](data-connectors/barracuda-cloudgen-firewall.md)
486486
- [Exchange Security Insights Online Collector (using Azure Functions)](data-connectors/exchange-security-insights-online-collector.md)
487-
- [Exchange Security Insights On-Premise Collector](data-connectors/exchange-security-insights-on-premise-collector.md)
487+
- [Exchange Security Insights On-Premises Collector](data-connectors/exchange-security-insights-on-premises-collector.md)
488488
- [Microsoft Exchange Logs and Events](data-connectors/microsoft-exchange-logs-and-events.md)
489489
- [Forcepoint DLP](data-connectors/forcepoint-dlp.md)
490490
- [MISP2Sentinel](data-connectors/misp2sentinel.md)

articles/sentinel/data-connectors/cyber-blind-spot-intergration.md renamed to articles/sentinel/data-connectors/cyber-blind-spot-integration.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: "Cyber Blind Spot Intergration (using Azure Functions) connector for Microsoft Sentinel"
3-
description: "Learn how to install the connector Cyber Blind Spot Intergration (using Azure Functions) to connect your data source to Microsoft Sentinel."
2+
title: "Cyber Blind Spot Integration (using Azure Functions) connector for Microsoft Sentinel"
3+
description: "Learn how to install the connector Cyber Blind Spot Integration (using Azure Functions) to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
66
ms.date: 04/26/2024
@@ -9,7 +9,7 @@ ms.author: cwatson
99
ms.collection: sentinel-data-connector
1010
---
1111

12-
# Cyber Blind Spot Intergration (using Azure Functions) connector for Microsoft Sentinel
12+
# Cyber Blind Spot Integration (using Azure Functions) connector for Microsoft Sentinel
1313

1414
Through the API integration, you have the capability to retrieve all the issues related to your CBS organizations via a RESTful interface.
1515

@@ -38,7 +38,7 @@ CBSLog_Azure_1_CL
3838

3939
## Prerequisites
4040

41-
To integrate with Cyber Blind Spot Intergration (using Azure Functions) make sure you have:
41+
To integrate with Cyber Blind Spot Integration (using Azure Functions) make sure you have:
4242

4343
- **Microsoft.Web/sites permissions**: Read and write permissions to Azure Functions to create a Function App is required. [See the documentation to learn more about Azure Functions](/azure/azure-functions/).
4444

articles/sentinel/data-connectors/exchange-security-insights-on-premise-collector.md renamed to articles/sentinel/data-connectors/exchange-security-insights-on-premises-collector.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: "Exchange Security Insights On-Premise Collector connector for Microsoft Sentinel"
3-
description: "Learn how to install the connector Exchange Security Insights On-Premise Collector to connect your data source to Microsoft Sentinel."
2+
title: "Exchange Security Insights On-Premises Collector connector for Microsoft Sentinel"
3+
description: "Learn how to install the connector Exchange Security Insights On-Premises Collector to connect your data source to Microsoft Sentinel."
44
author: cwatson-cat
55
ms.topic: how-to
66
ms.date: 04/26/2024
@@ -9,7 +9,7 @@ ms.author: cwatson
99
ms.collection: sentinel-data-connector
1010
---
1111

12-
# Exchange Security Insights On-Premise Collector connector for Microsoft Sentinel
12+
# Exchange Security Insights On-Premises Collector connector for Microsoft Sentinel
1313

1414
Connector used to push Exchange On-Premises Security configuration for Microsoft Sentinel Analysis
1515

@@ -36,7 +36,7 @@ ESIExchangeConfig_CL
3636

3737
## Prerequisites
3838

39-
To integrate with Exchange Security Insights On-Premise Collector make sure you have:
39+
To integrate with Exchange Security Insights On-Premises Collector make sure you have:
4040

4141
- **Service Account with Organization Management role**: The service Account that launch the script as scheduled task needs to be Organization Management to be able to retrieve all the needed security Information.
4242

@@ -67,8 +67,8 @@ In 'Run as Administrator' mode, launch the 'setup.ps1' script to configure the c
6767
3. Schedule the ESI Collector Script (If not done by the Install Script due to lack of permission or ignored during installation)
6868

6969
The script needs to be scheduled to send Exchange configuration to Microsoft Sentinel.
70-
We recommend to schedule the script once a day.
71-
The account used to launch the Script needs to be member of the group Organization Management
70+
We recommend scheduling the script once a day.
71+
The account used to launch the Script needs to be a member of the group Organization Management
7272

7373

7474

articles/sentinel/enroll-simplified-pricing-tier.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -154,8 +154,9 @@ Keep in mind, the simplified effective per GB price for a Microsoft Sentinel ena
154154
A Log Analytics workspace automatically configures its pricing tier to match the simplified pricing tier if Microsoft Sentinel is removed from a workspace while simplified pricing is enabled. For example, if the simplified pricing was configured for 100 GB/day Commitment tier in Microsoft Sentinel, the pricing tier of the Log Analytics workspace changes to 100 GB/day Commitment tier once Microsoft Sentinel is removed from the workspace.
155155

156156
### Will switching reduce my costs?
157-
Though the goal of the experience is to merely simplify the pricing and cost management experience without impacting actual costs, two primary scenarios exist for a cost reduction when switching to a simplified pricing tier.
157+
Though the goal of the experience is to merely simplify the pricing and cost management experience without impacting actual costs, three primary scenarios exist for a cost reduction when switching to a simplified pricing tier.
158158

159+
- Reduce Microsoft Sentinel costs with a [pre-purchase plan](billing-pre-purchase-plan.md). Commit units of a pre-purchase plan don't apply to Log Analytics costs in the classic pricing tier. Since the entire simplified pricing tier is categorized as a Microsoft Sentinel cost, your effective spend with the simplified pricing tier is reduced with a pre-purchase plan that approaches your commitment tier.
159160
- The combined [Defender for Servers](/azure/defender-for-cloud/faq-defender-for-servers#is-the-500-mb-of-free-data-ingestion-allowance-applied-per-workspace-or-per-machine-) benefit results in a total cost savings if utilized by the workspace.
160161
- If one of the separate pricing tiers for Log Analytics or Microsoft Sentinel was inappropriately mismatched, the simplified pricing tier could result in cost saving.
161162

95.7 KB
Loading

0 commit comments

Comments
 (0)