MICROSOFT SENTINEL · PRICING · INR · TCO · CSP PARTNER

Microsoft Sentinel Pricing India — INR Quote & 3-Year TCO Model

Sentinel pricing is per-GB ingested with four cost levers — commit tier, Auxiliary Logs tier, Data Collection Rules, and the M365 E5 ingestion benefit. Ogma is an authorized Microsoft CSP partner. We size, quote, and bill Sentinel in INR + GST with no FX exposure to your finance team. Free TCO model on your actual workload.

Request the TCO Model
Per-GB Ingest
Commit-tier 15-65% off
100 MB/user/day
Free E5 benefit
90 Days Free
Analytics retention
INR + GST
CSP-partner billing

Pricing Reference card

Pricing model
Per-GB ingested. Analytics tier ~₹275/GB pay-as-you-go (USD $2.80 at ₹98). Commitment-tier 100/200/500/1000 GB/day discounts the per-GB rate 15-65%.
M365 E5 benefit
100 MB/user/day FREE ingestion for Microsoft 365 sources (M365 audit, Defender XDR, Defender for Cloud Apps, Entra sign-ins). 5,000-user tenant = 500 GB/day free.
Cost levers
(1) Commit tier; (2) Auxiliary Logs tier ~₹50/GB for high-volume low-value sources; (3) DCR filtering at agent layer; (4) E5 benefit for M365 sources.
Retention
90 days FREE on Analytics tier. Additional retention ~₹10/GB/month Analytics or ~₹2-5/GB/month Archive tier. CERT-In 180-day floor costs ~₹0.9-1.0/GB total extra.
Region
Azure Central India (Pune) or South India (Chennai). Data residency stays in selected region.
Indian compliance fit
DPDP Act 2023, CERT-In Direction 20(3)/2022, RBI Cyber Security Framework, SEBI CSCRF, IRDAI ICS guidelines. Sentinel + Compliance Manager produces evidence.
Commercial via Ogma
Microsoft CSP partner — INR invoicing, Indian entity contract, GST, monthly billing, no FX exposure. Single quote covers Sentinel licence + Ogma services.

The Four Cost Levers — How We Right-Size Your Sentinel Bill

Each lever is independent. Stacked, they typically cut Sentinel TCO 30-50% vs naive pay-as-you-go.

Commitment-Tier Sizing

Match daily ingest to nearest commit tier — 100, 200, 500, 1000+ GB/day — for 15-65% per-GB discount. Ogma runs 30-day pay-as-you-go baseline, then flips to commit tier with confidence.

Data Collection Rules

DCR filters noisy events at the Azure Monitor Agent layer before ingest. Typically cuts Analytics ingest 20-30% without losing detection coverage. We tune DCRs per source type.

Auxiliary Logs Tier

High-volume low-value sources (CDN logs, Azure Activity, telemetry) route to Auxiliary Logs at ~₹50/GB vs Analytics ~₹150-275/GB. Same searchability for compliance use cases.

M365 E5 Ingest Benefit

100 MB/user/day FREE for Microsoft 365 sources. For 5K-user E5 tenant = 500 GB/day free. Most TCO models miss this entirely; we put it line-by-line in your quote.

Retention Tier Optimisation

Analytics tier first 90 days FREE. Beyond that — Archive tier at ~₹2-5/GB/month for compliance retention. CERT-In 180-day floor optimally stacked: 90 days Analytics + 90 days Archive.

INR + GST Quote Format

Single line-item INR quote covering Sentinel commit licence + commit-tier + retention + Logic Apps + Ogma's deployment + managed-SOC fees. No hidden FX. GST + TDS handled cleanly.

Why Choose Ogma for Sentinel Pricing & Deployment?

Microsoft CSP Partner

Authorized Microsoft CSP partner — Sentinel licence + Azure consumption billed under Ogma's CSP agreement. INR invoicing, GST handled, no FX exposure for your finance team.

Real-Workload TCO Model

We run 30 days of pay-as-you-go ingest against your actual telemetry, then build your INR TCO with commit-tier recommendation + E5 ingest-benefit math + 3-year projection.

SC-200 Certified Engineers

Sentinel deployment + KQL detection-rule authoring + Logic Apps SOAR playbook engineering led by SC-200 certified architects. Sentinel-native solutions, not generic SIEM advice.

How Ogma Quotes & Sizes Your Sentinel Deployment

1
Workload Discovery

We inventory your data sources — M365 + Defender, firewall, cloud platform, on-prem telemetry — and estimate per-source daily GB based on user count + activity profile + your Azure Activity Log baseline.

2
30-Day Baseline

Sentinel workspace provisioned + connectors enabled in pay-as-you-go mode. 30-day actual ingest measured by source. M365 E5 ingest-benefit applied + Auxiliary Logs candidates identified.

3
INR TCO Model

Commit-tier recommendation tied to measured ingest. M365 E5 benefit math + DCR filtering opportunities + Auxiliary Logs split. 3-year TCO projection with renewal cycle anchors.

4
Flip to Commit + Managed SOC

Commit-tier procurement. Logic Apps playbook library. Optional Ogma Managed SOC: 24x7 monitoring + KQL rule tuning + monthly compliance reporting in INR + GST.

Sentinel Pricing FAQ

Sentinel meters per-GB ingested with commit-tier discounts; no separate SOAR/Phantom licence; M365 E5 ingest-benefit covers 100 MB/user/day for Microsoft sources free. For 200 GB/day mid-market, typical Sentinel TCO ~₹0.7-1.0 cr/year vs Splunk ES ~₹1.8-2.5 cr/year. Migration playbook on the blog.

100 GB/day commit tier is the entry point with meaningful discount (~15-25%). Below ~70 GB/day, pay-as-you-go is the right answer until volume grows. We monitor + flip at the right threshold.

Microsoft direct billing for Azure runs in INR for India tenants but invoice + support is via Microsoft direct. CSP-partner billing through Ogma delivers INR + GST + single-vendor accountability (licence + deployment + managed SOC on one PO).

No — the 100 MB/user/day FREE benefit covers only Microsoft 365 + Entra ID + Defender XDR + Defender for Cloud Apps. AWS / GCP / firewall / endpoint telemetry from non-Microsoft sources bills on commit tier.

Per-EPS or per-GB or flat-fee depending on scope. Typical mid-market: ₹6-15 lakh/month for 24x7 monitoring + rule tuning + threat hunting + monthly compliance reporting. Sized against your Sentinel commit tier.

Foundation (workspace + Microsoft connectors + 30-day baseline) — 30 days. KQL detection-rule library + Logic Apps playbooks — additional 30 days. Managed SOC onboarding — 14 days. 90-day end-to-end for Sentinel-only deployment.

Yes. Splunk → Sentinel migration is our highest-frequency engagement. 90-day playbook with SPL → KQL re-authoring (Uncoder.io first pass + senior analyst review), Logic Apps SOAR migration, 30-day parallel-run.

No — Copilot for Security is separately priced per-Security-Compute-Unit (SCU). Sentinel is the prerequisite data layer; Copilot adds AI-assisted incident triage + KQL generation. Typically Day 90+ rollout after Sentinel is stable.

Free Sentinel TCO model on your actual workload

Ogma sizes your Sentinel deployment against measured ingest, applies the M365 E5 benefit + commit-tier math, returns a 3-year INR + GST TCO model with renewal anchors. 5 working days.

Also see: Microsoft Sentinel India · Microsoft Security Stack · Sentinel pricing blog