Previously, our Nishida was worried about the cost of Sentinel? I wrote an article called 3 Points to Reduce Log Analytics Fees, but this time I will explain how to use Sentinel with almost no cost in the first place.
If you are considering using SIEM and are interested in Sentinel, the same Microsoft product, because you are using Microsoft 365 in your company, but you are not very familiar with the pricing structure and cannot take the step to use it, please refer to it.
Conclusion
First of all, if you want to write a conclusion, you can only link Entra ID logs (sign-in logs and audit logs).
Set the log retention period to the default 90 days.
If the number of users is about 100, it is estimated that the usage fee is about 1,000 yen/month.
Also, if you have a Microsoft E5 license, you will most likely be able to use it for almost free.
The following is a detailed explanation.
Sentinel Pricing Structure
As mentioned in the article introduced above, there are two main charges for the following points.
(For more information , please check the official documentation)
Log ingestion (billed by data volume)
Log storage (billed for the number of days and amount of data)
However, log storage is free for 90 days, no matter how many GB you have, so if you want to wait and see, set it to the default 90 days.
Log Ingestion
It would be nice if there was a way to get logs cheaply, but I don't want to import too much because I am charged for the amount of logs.
However, if you can't take advantage of Sentinel's capabilities because you didn't capture any logs, you're putting the cart before the horse.
That's why I recommend ingesting Entra ID logs.
**Why Entra ID? **
There are two main reasons.
Not a large amount of logs
Sentinel has a wide variety of analysis rules
Not a large amount of logs
Based on our track record, we assume that if the number of users is about 100, the log volume will be about 0.7~1GB per month.
The ingest fee per 1GB is 903.68 yen (as of June 1, 2025), so it is assumed as follows.

If you can use it for less than 10,000 yen a month, wouldn't it be easy to get your hands on it?
Also, if you have a Microsoft 365 E5 license, some logs are free for up to 5 MB per user per day for logs ingested into Sentinel.

Entra ID logs are included in this free coverage, and probably no more than 5 MB per user/day.
Therefore, if you only want to get Entra ID logs, there is a high possibility that you can use it for free, no matter how many users you have.
Note: The amount of logs is an estimate based on our performance. The amount of logs varies depending on the number of applications connected to Entra ID.
Sentinel has a wide range of analytics rules
Sentinel has a strong integration with Microsoft products, especially with Entra ID, so there are plenty of rules for analysis.
One of the features you expect from a SIEM is that the SIEM analyzes your logs and alerts you if there is a security issue, and Entra ID makes it easy to realize that.
You can integrate with other products, but if you don't have an analytics rule for that product, Sentinel won't alert you unless you create your own.
This is true for all SIEMs, not just Sentinel, so if you're considering implementing a SIEM, it's very important to check if this analytics rule is available by default.
Conclusion
By narrowing down the integration target to Entra ID logs, we explained how to easily experience the features of Microsoft Sentinel while using it at a lower cost.
We hope this article helps you strengthen your company's security.
However, even if Sentinel can issue alerts and detect risks, whether the system is in place to correctly understand the content of the alert and respond appropriately is another issue.
If you leave the alert unattended without understanding the contents, you will not be able to fully utilize the Sentinel you have introduced, and your treasure will be spoiled.
Ideally, it is desirable to establish a 24/365 operating system (SOC) with security experts, but it may be difficult for many companies to secure human resources just for this purpose.
Therefore, we provide SOC services for companies using Microsoft 365 that support the monitoring and operation of the entire Microsoft environment, including Entra. You can also build Sentinels.
In addition to Microsoft 365, we also support the following security products, and by integrating monitoring and operating multiple products, we will strengthen your company's security posture.
・WAF (AWS WAF, Azure WAF, etc.)
EDR (Cybereason, CrowdStrike, etc.)
SaaS (Slack, Dropbox, etc.)
Firewall (Fortigate, Meraki, etc.)
PC operation log (SKYSEA Client) View, LANSCOPE Endpoint Manager, etc.)
Companies that want to achieve stronger defenses while reducing the operational burden of security should consider implementing Colorkrew Security.