You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/billing-pre-purchase-plan.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,18 +1,18 @@
1
1
---
2
-
title: Optimize costs with a pre-purchase plan
2
+
title: Optimize costs with a prepurchase plan
3
3
titleSuffix: Microsoft Sentinel
4
-
description: Learn how to save costs and buy a Microsoft Sentinel pre-purchase plan
4
+
description: Learn how to save costs and buy a Microsoft Sentinel prepurchase plan
5
5
author: EdB-MSFT
6
6
ms.topic: how-to
7
7
ms.date: 07/07/2025
8
8
ms.author: edbaynash
9
9
10
-
#customerintent: As a SOC administrator or a billing specialist, I want to know how to buy a pre-purchase plan and whether commit units will benefit us financially.
10
+
#customerintent: As a SOC administrator or a billing specialist, I want to know how to buy a prepurchase plan and whether commit units will benefit us financially.
11
11
---
12
12
13
13
# Optimize Microsoft Sentinel costs with a pre-purchase plan
14
14
15
-
Save on your Microsoft Sentinel analytics tier costs when you buy a prepurchase plan. Pre-purchase plans are commit units (CUs) bought at discounted tiers in your purchasing currency for a specific product. The more you buy, the greater the discount. Purchased CUs pay down qualifying costs in US dollars (USD). So, if Microsoft Sentinel generates a retail cost of $100, then 100 Microsoft Sentinel CUs (SCUs) are consumed.
15
+
Save on your Microsoft Sentinel analytics tier costs when you buy a pre-purchase plan. Pre-purchase plans are commit units (CUs) bought at discounted tiers in your purchasing currency for a specific product. The more you buy, the greater the discount. Purchased CUs pay down qualifying costs in US dollars (USD). So, if Microsoft Sentinel generates a retail cost of $100, then 100 Microsoft Sentinel CUs (SCUs) are consumed.
16
16
17
17
Your Microsoft Sentinel pre-purchase plan automatically uses your SCUs to pay for eligible analytics tier costs during its one-year term or until the SCUs run out. Your pre-purchase plan SCUs start paying for your Microsoft Sentinel workspace costs without having to redeploy or reassign the plan. By default, plans are configured to renew at the end of the one year term.
18
18
@@ -37,14 +37,14 @@ For example, suppose you choose a 200 GB/day commitment tier. With simplified pr
37
37
38
38
A $100,000 USD pre-purchase plan covers five months of that commitment tier but is valid for paying Microsoft Sentinel costs for 12 months. The pre-purchase plan is bought at a 22% discount for $78,000 USD.
39
39
40
-
The savings for the commitment tier and the pre-purchase plan combine. The original pay-as-you-go price for five months of 200 GB/day ingestion and analysis costs is for example, about $160,000 USD. With an accurate commitment tier and a pre-purchase plan, the cost is reduced to $78,000 USD for a combined savings of over 51%. Since the example plan is depleted after just five months, the best way to ensure continued savings is to purchase more SCUs with another plan.
40
+
The savings for the commitment tier and the pre-purchase plan combine. The original pay-as-you-go price for five months of 200 GB/day ingestion and analysis costs is, for example, about $160,000 USD. With an accurate commitment tier and a pre-purchase plan, the cost is reduced to $78,000 USD for a combined savings of over 51%. Since the example plan is depleted after just five months, the best way to ensure continued savings is to purchase more SCUs with another plan.
41
41
42
42
For more information, see the following articles:
43
43
-[Switch to simplified pricing](enroll-simplified-pricing-tier.md)
44
44
-[Set or change commitment tier](billing-reduce-costs.md#set-or-change-pricing-tier)
45
45
46
46
>[!IMPORTANT]
47
-
> The prices mentioned are for example purposes only. To determine the latest commitment tier prices, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
47
+
> The prices mentioned are for the purposes of example purposes only. To determine the latest commitment tier prices, see [Microsoft Sentinel pricing](https://azure.microsoft.com/pricing/details/microsoft-sentinel/).
48
48
49
49
All Microsoft Sentinel pricing tiers qualify for Microsoft Sentinel pre-purchase plans. From your Microsoft Sentinel bill, these costs are the entries with the **Sentinel** service name in the invoice details. These costs don't include Azure Monitor tiers, retention, restore, and search costs. Eligible Microsoft Sentinel usage is deducted from the prepurchased Microsoft Sentinel CUs automatically.
Copy file name to clipboardExpand all lines: articles/sentinel/graph/sentinel-lake-connectors.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,7 +33,7 @@ To configure retention and tiering for the data connector see [Configure data co
33
33
34
34
## Microsoft Sentinel XDR data
35
35
36
-
All tables from your Microsoft Sentinel XDR connector are enabled in the data lake with 30-day retention period. Navigate to **System** > **Data Management** > **Table management** in the Microsoft Defender portal to extend retention of the XDR tables without impacting the default retention of your analytics tier tables.
36
+
All tables from your Microsoft Sentinel XDR connector are enabled in the data lake with 30-day retention period. Navigate to **Microsoft Sentinel** > **Configuration** > **Tables** in the Microsoft Defender portal to extend retention of the XDR tables without impacting the default retention of your analytics tier tables.
37
37
38
38
Non-DCR/MMA-based custom tables aren't mirrored to the data lake. DCR-based custom tables are mirrored.
Copy file name to clipboardExpand all lines: articles/sentinel/graph/sentinel-lake-onboarding.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -93,7 +93,7 @@ Use the following steps to onboard to the Microsoft Sentinel data lake from the
93
93
:::image type="content" source="./media/sentinel-lake-onboarding/onboarding-banner.png" lightbox="./media/sentinel-lake-onboarding/onboarding-banner.png" alt-text="A screenshot showing the Defender portal home page with the onboarding banner for Microsoft Sentinel data lake.":::
94
94
95
95
> [!NOTE]
96
-
> If you accidentally close the banner, you can initiate onboarding by navigating to the data lake settings page under **System** > **Settings** > **Microsoft Sentinel** > **data lake**.
96
+
> If you accidentally close the banner, you can initiate onboarding by navigating to the data lake settings page under **System** > **Settings** > **Microsoft Sentinel** > **Data lake**.
97
97
98
98
99
99
1. If you don't have the correct roles to set up the data lake, a side panel appears indicating that you don't have the required permissions. Request that your administrator completes the onboarding process.
For the sake of the changes described in this section, new Microsoft Sentinel customers are customers who are [onboarding the first workspace in their tenant to Microsoft Sentinel](quickstart-onboard.md).
139
+
140
+
Starting **July, 2025**, such new customers who also have the permissions of a subscription [Owner](/azure/role-based-access-control/built-in-roles#owner) or a [User access administrator](/azure/role-based-access-control/built-in-roles#user-access-administrator), and are not Azure Lighthouse-delegated users, have their workspaces automatically onboarded to the Defender portal together with onboarding to Microsoft Sentinel.
141
+
142
+
Users of such workspaces, who also aren't Azure Lighthouse-delegated users, see links in Microsoft Sentinel in the Azure portal that redirect them to the Defender portal.
143
+
144
+
For example:
145
+
146
+
:::image type="content" source="media/overview/redirect-no-defender.png" alt-text="Screenshot of a redirect link from the Azure portal to the Defender portal.":::
147
+
148
+
Such users use Microsoft Sentinel in the Defender portal only.
149
+
150
+
New customers who don't have relevant permissions aren't automatically onboarded to the Defender portal, but they do still see redirection links in the Azure portal, together with prompts to have a user with relevant permissions manually onboard the workspace to the Defender portal.
151
+
152
+
The following table summarizes these experiences:
153
+
154
+
|Customer type| Experience|
155
+
|---------|---------|
156
+
|**Existing customers** creating new workspaces in a tenant where there is already a workspace enabled for Microsoft Sentinel | Workspaces are not automatically onboarded, and users don't see redirection links |
157
+
|**Azure Lighthouse-delegated users** creating new workspaces in any tenant | Workspaces are not automatically onboarded, and users don't see redirection links |
158
+
|**New customers** onboarding the first workspace in their tenant to Microsoft Sentinel | - **Users who have the required permissions** have their workspace automatically onboarded. Other users of such workspaces see redirection links in the Azure portal. <br><br>- **Users who don't have the required permissions** don't have their workspace automatically onboarded. All users of such workspaces see redirection links in the Azure portal, and a user with the required permissions must onboard the workspace to the Defender portal. |
159
+
136
160
## Related content
137
161
138
-
-[Quickstart: Onboard Microsoft Sentinel](quickstart-onboard.md)
162
+
-[Onboard Microsoft Sentinel](quickstart-onboard.md)
139
163
-[Deployment guide for Microsoft Sentinel](deploy-overview.md)
140
164
-[Plan costs and understand Microsoft Sentinel pricing and billing](billing.md)
Copy file name to clipboardExpand all lines: articles/sentinel/whats-new.md
+31-2Lines changed: 31 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,6 +21,8 @@ The listed features were released in the last six months. For information about
21
21
## July 2025
22
22
23
23
-[Microsoft Sentinel data lake (preview) ](#microsoft-sentinel-data-lake-preview)
24
+
-[Table management and retention settings in the Microsoft Defender portal](#table-management-and-retention-settings-in-the-microsoft-defender-portal)
25
+
-[Microsoft Sentinel data lake permissions integrated with Microsoft Defender XDR unified RBAC (Preview)](#microsoft-sentinel-data-lake-permissions-integrated-with-microsoft-defender-xdr-unified-rbac-preview)
24
26
-[No limit on the number of workspaces you can onboard to the Defender portal](#no-limit-on-the-number-of-workspaces-you-can-onboard-to-the-defender-portal)
25
27
-[Microsoft Sentinel in the Azure portal to be retired July 2026](#microsoft-sentinel-in-the-azure-portal-to-be-retired-july-2026)
26
28
@@ -33,10 +35,37 @@ Key benefits of the Microsoft Sentinel data lake include:
33
35
+ Separation of storage and compute for greater flexibility
34
36
+ Support for multiple analytics engines to unlock deeper insights from your security data
35
37
+ Native integration with Microsoft Sentinel, including the ability to select tiering for log data across analytics and lake tiers
38
+
For more information, see
36
39
37
-
Explore the data lake using KQL queries, or use the new Microsoft Sentinel data lake notebook for VS Code to visualize and analyze your data. For more information, see [Microsoft Sentinel data lake](graph/sentinel-lake-overview.md).
40
+
Explore the data lake using KQL queries, or use the new Microsoft Sentinel data lake notebook for VS Code to visualize and analyze your data.
41
+
42
+
For more information, see:
43
+
44
+
-[Microsoft Sentinel data lake](graph/sentinel-lake-overview.md)
45
+
-[KQL and the Microsoft Sentinel data lake (preview)](graph/kql-overview.md)
46
+
-[Jupyter notebooks and the Microsoft Sentinel data lake (preview)](graph/notebooks-overview.md)
47
+
-[Data lake tech blog](https://aka.ms/datalaketechblog)
48
+
49
+
### Table management and retention settings in the Microsoft Defender portal
50
+
51
+
Table management and retention settings are now available in the Microsoft Defender portals. You can view and manage table settings in the Microsoft Defender portal, including retention settings for Microsoft Sentinel and Defender XDR tables, and switch between analytics and data lake tiers.
52
+
53
+
For more information, see:
54
+
+[Manage data tiers and retention in Microsoft Sentinel (preview)](manage-data-overview.md)
55
+
+[Configure table settings in Microsoft Sentinel (preview)](manage-table-tiers-retention.md).
56
+
57
+
58
+
### Microsoft Sentinel data lake permissions integrated with Microsoft Defender XDR unified RBAC (preview)
59
+
60
+
Starting in July 2025, Microsoft Sentinel data lake permissions are provided through Microsoft Defender XDR unified RBAC. Support for unified RBAC is available in addition the support provided by global Microsoft Entra ID roles.
61
+
62
+
For more information, see:
63
+
64
+
-[Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/manage-rbac)
65
+
-[Create custom roles with Microsoft Defender XDR Unified RBAC](/defender-xdr/create-custom-rbac-roles)
66
+
-[Permissions in Microsoft Defender XDR Unified role-based access control (RBAC)](/defender-xdr/custom-permissions-details)
67
+
-[Roles and permissions for the Microsoft Sentinel data lake (Preview)](/azure/sentinel/roles#roles-and-permissions-for-the-microsoft-sentinel-data-lake-preview)
38
68
39
-
Learn more at [Data lake tech blog](https://aka.ms/datalaketechblog).
40
69
41
70
### No limit on the number of workspaces you can onboard to the Defender portal
0 commit comments