This is the Trace Id: ffcc79ffb052a9ce4175643364d3045b
Skip to main content Explore View all products (200+) Microsoft Foundry Azure Copilot GitHub Copilot Azure Kubernetes Service (AKS) Azure Cosmos DB Azure Database for PostgreSQL Azure Arc Microsoft Fabric Linux virtual machines in Azure Foundry Models Foundry Agent Service Foundry IQ Foundry Tools Foundry Control Plane Observability in Foundry Control Plane Azure OpenAI in Foundry Models Azure Speech in Foundry Tools Azure Machine Learning View all databases Azure Cosmos DB Azure DocumentDB Azure SQL Azure Database for PostgreSQL Azure Managed Redis Microsoft Fabric Azure Databricks Linux virtual machines in Azure Windows Server on Azure Azure Functions Azure Virtual Machine Scale Sets Azure API Management Azure Container Apps Azure Kubernetes Service (AKS) Azure Kubernetes Fleet Manager Azure Container Registry Azure Red Hat OpenShift Azure Container Instances Azure Container Storage Azure Arc Azure Local Microsoft Defender for Cloud Azure Monitor Microsoft Sentinel Azure Migrate View all solutions (40+) Cloud solutions for small and medium businesses Cloud migration and modernization center Data analytics for AI Azure Databases AI apps and agents Microsoft Marketplace Microsoft Sovereign Cloud AI apps and agents Responsible AI with Azure AI Infrastructure Data analytics for AI Machine learning operations (MLOps) Low-code application development on Azure Integration Services Serverless computing DevOps Migration and modernization center .NET apps migration Databases on Azure Linux on Azure Oracle on Azure SAP on the Microsoft Cloud Adaptive cloud High-performance computing (HPC) Infrastructure as a service (IaaS) Resiliency Azure Essentials Azure Accelerate FinOps on Azure Microsoft Marketplace Azure pricing overview Create an Azure account Free Azure services Flexible purchase options Pricing calculator FinOps on Azure Maximize ROI from AI Azure savings plans Azure reservations Azure Hybrid Benefit Virtual Machines Azure SQL Microsoft Foundry Microsoft Fabric Azure Kubernetes Service (AKS) Microsoft Defender for Cloud Software Development Companies Microsoft Marketplace Find a partner Get started with Azure Customer stories Analyst reports, white papers, and e-books Videos Learn more about cloud computing Documentation Explore Azure portal Developer resources Quickstart templates Resources for startups Developer community Students Azure for partners Blog Events and Webinars Learn Support Contact Sales Get started with Azure Sign in

Microsoft Sentinel benefit for Microsoft 365 E5, A5, F5, and G5 customers

Save up to $2,200 per month on a typical 3,500 seat deployment of Microsoft 365 E5 for up to 5 MB per user per day of data ingestion into Microsoft Sentinel.1

Integrated threat protection with SIEM and XDR

Get the context and automation you need to stop sophisticated, cross-domain attacks across your entire organization with security information and event management (SIEM) and extended detection and response (XDR) from Microsoft. Microsoft 365 E5, A5, F5, and G5 and Microsoft 365 E5, A5, F5, and G5 Security customers can get a data grant of up to 5 MB per user per day of Microsoft 365 data ingestion into Microsoft Sentinel.

  • Comprehensive security

    Get end-to-end visibility across your resources, including users, devices, applications, and infrastructure.

  • Detect advanced threats

    Defend against modern attacks with AI-driven SIEM and XDR capabilities.

  • Investigate prioritized incidents

    Surface critical incidents and hunt suspicious activities at scale.

  • Enable efficient and effective response

    Respond to incidents rapidly with built-in orchestration and automation of common tasks.

Offer details

Microsoft 365 E5, A5, F5, and G5, and Microsoft 365 E5, A5, F5, and G5 Security customers can receive a data grant of up to 5MB per user per day to ingest Microsoft 365 data. This offer includes the following data sources:

  • Microsoft Entra ID (formerly Azure AD) sign-in and audit logs
  • Microsoft Defender for Cloud Apps Guard shadow IT discovery logs
  • Microsoft Purview Information Protection logs
  • Microsoft 365 advanced hunting data

The data grant will be calculated automatically and applied to your bill, covering the cost of up to 5 MB of data ingestion per user per day.

In addition to this data grant, the following Microsoft 365 data sources are always free for all Microsoft Sentinel users:

  • Azure Activity Logs
  • Office 365 Audit Logs (all SharePoint activity and Exchange admin activity)
  • Alerts from Microsoft Defender for Cloud, Microsoft Defender XDR, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Endpoint, and Microsoft Defender for Cloud Apps.
[1] Calculation based on pay-as-you-go prices for Microsoft Sentinel and Azure Monitor Log Analytics for US East region. Exact savings will depend on benefit utilization and customer's effective price after any applicable discounts.

Offer eligibility

This data grant is available to Microsoft 365 E5, A5, F5, and G5 and Microsoft 365 E5, A5, F5, and G5 Security customers who have Enterprise (EA), Enterprise Subscription (EAS), or Cloud Solution Provider (CSP) Agreements and Enrollments. New Microsoft 365 E5, A5, F5, and G5 or Microsoft 365 E5, A5, F5, and G5 Security customers are also qualified for this data grant. Once a customer becomes eligible, they will begin benefiting from the data grant starting with their first month of eligibility.

FAQ

    Microsoft 365 A5 and Microsoft 365 A5 Security

    Microsoft 365 A5 Security for faculty

    Microsoft 365 A5 for faculty

    Microsoft 365 A5 for students

    Microsoft 365 A5 Security for students

    Microsoft 365 A5 Suite features for faculty

    Microsoft 365 A5 Suite features for students

    Microsoft 365 A5 with Calling Minutes for Faculty

    Microsoft 365 A5 with Calling Minutes for Students

    Microsoft 365 A5 without Audio Conferencing for faculty

    Microsoft 365 A5 without Audio Conferencing for students

    Microsoft 365 E5 and Microsoft 365 E5 Security

    Microsoft 365 E5 Security

    Microsoft 365 E5

    Microsoft 365 E5 Security for EMS E5

    Microsoft 365 E5 Security_USGOV_GCCHIGH

    Microsoft 365 E5 Suite features

    Microsoft 365 E5 with Calling Minutes

    Microsoft 365 E5 without Audio Conferencing

    Microsoft 365 E5_USGOV_GCCHIGH

    Microsoft 365 F5 and Microsoft 365 F5 Security

    Microsoft 365 F5 Security + Compliance Add-on

    Microsoft 365 F5 Security + Compliance Add-on AR (DOD)_USGOV_DOD

    Microsoft 365 F5 Security + Compliance Add-on AR_USGOV_GCCHIGH

    Microsoft 365 F5 Security + Compliance Add-on GCC

    Microsoft 365 F5 Security Add-on

    Microsoft 365 F5 Security Add-on AR_USGOV_DOD

    Microsoft 365 F5 Security Add-on AR_USGOV_GCCHIGH

    Microsoft 365 F5 Security Add-on GCC

    Microsoft 365 Security and Compliance for FLW

    Microsoft 365 G5 and Microsoft G5 Security

    Microsoft 365 G5 Security GCC

    Microsoft 365 G5 GCC Suite features

    Microsoft 365 G5 Security_USGOV_DOD

    Microsoft 365 G5_USGOV_DOD

    Microsoft 365 G5_USGOV_DOD

    Microsoft 365 G5 GCC

    Data Connector Data Type

    Microsoft Entra ID (audit and sign-in logs)

    SigninLogs

    AuditLogs

    AADNonInteractiveUserSignInLogs

    AADServicePrincipalSignInLogs

    AADManagedIdentitySignInLogs

    AADProvisioningLogs

    ADFSSignInLogs

    Microsoft Defender for Cloud Apps

    McasShadowItReporting

    Azure Information Protection

    InformationProtectionLogs_CL

    Microsoft 365 Defender Suite

    CloudAppEvents

    EmailAttachmentInfo

    EmailEvents

    EmailPostDeliveryEvents

    EmailUrlInfo

    IdentityLogonEvents

    IdentityQueryEvents

    IdentityDirectoryEvents

    AlertEvidence

  • With this benefit, each user may ingest up to 5 MB of eligible data daily through free Azure meters. To verify that you're using the benefit, view your costs in a table format in the cost analysis tab under Subscription. Group your costs by meter and search for "M365". If you've used the offer in the selected time range, you'll see a zero-dollar charge for the Microsoft 365 meters.

  • Use the Microsoft Sentinel Cost workbook in the Workbooks gallery to estimate your total cost savings. Enter details such as your tenant's total number of eligible seats to calculate total potential savings for a custom time range or export your usage details to see the exact data volumes you've received for free so far.