Webinar

Navigating Microsoft’s Latest Pricing Updates and Sentinel Data Lake

Recently, Microsoft announced the inclusion of Security Copilot as part of Microsoft 365 E5, unlocking broad access to agentic Security AI across the enterprise without requiring additional licensing.

And on August 12, 2025, Microsoft announced a significant update to its pricing model for Online Services under volume licensing programs. 

In the above webinar, Daniel Morris and Yannick Horvat unpack the recent changes to Microsoft’s pricing model, including licensing adjustments and service tier revisions and provide insights into the new Microsoft Sentinel Data Lake, including its pricing structure and strategic implications for security operations.

Understanding the Changes: Microsoft Pricing and Naming Updates

Microsoft has introduced several updates impacting its product names and licensing models. Notably, the Microsoft 365 E5 Security license is now known as the Microsoft Defender Suite, and the Microsoft 365 E5 Compliance license has been rebranded to the Microsoft Purview Suite. These changes may reflect in your tenant, and it’s advisable to stay informed about these developments, especially as you approach license renewals or work with a Cloud Solution Provider (CSP).

An infographic outlining Microsoft 365 E5 features divided into two suites: Microsoft Defender Suite and Microsoft Purview Suite, detailing various security and compliance tools under each suite.

Microsoft’s recent introduction of a three-year subscription plan for the Microsoft 365 E5 license ensures price consistency over the contract term. However, companies need to be cautious of the tier requirements, such as a minimum of 100 licenses, as flexibility is limited within this agreement.

A table listing changes for Microsoft 365 E5 subscriptions starting November 1, 2025. It includes sections on companies with less than 2000 users, those using or moving to Cloud Solution Providers, and a negatives section.

Implement AI and Security Copilot Features

Microsoft has added AI capabilities with the Security Copilot, which promises to enhance security operations. For those with the Microsoft 365 E5 license, there’s the integration of 400 Security Compute Units (SCUs) each month per thousand licenses. This addition broadens the scope for integrating AI into your security strategy, which is crucial for advanced threat detection and response.

Leverage the Microsoft Sentinel Data Lake

For customers aiming to manage costs without compromising on data ingestion, the introduction of the Microsoft Sentinel data lake is a significant development. Sentinel, Microsoft’s Security Information and Event Management (SIEM) solution, can incur high costs if data management strategies aren’t carefully deployed. Here’s how to optimize your approach:

  1. Segregate data types: Classify your data into two categories: high-fidelity (primary) data and high-volume (secondary) data. High-fidelity data should be the focal point for active security operations, whereas high-volume data, often carrying less frequent queries, should be reserved for deeper forensic investigations.
  2. Optimize data storage: Within the Sentinel framework, the high-fidelity data should be integrated into the analytics tier, while high-volume data can be efficiently archived in the data lake. From a user perspective, these actions are aimed at optimizing cost without compromising data availability or utility.
  3. Utilize ingestion savings: Taking advantage of Microsoft’s ingestion saving options can also lead to cost benefits. For example, customers with Microsoft 365 E5 or Microsoft Defender Suite (previously E5 Security) plans receive a grant of 5 MB per user per day for ingesting Microsoft 365 data.
A diagram illustrating two types of data: High fidelity data, including analytics logs for real-time monitoring, and high volume data, referring to data lakes for broader security insights. Each type is visually represented with corresponding descriptions.

Plan Your Transition Thoughtfully

With data storage largely influencing costs, remember to be conscious of the data you choose for ingestion. Planning your data transitions carefully can ensure you are not paying for data that offers limited security value and that low-priority events and false positives are kept at a minimum for the security analysts. Retention and storage strategies need to be planned meticulously to take advantage of Microsoft’s optimization options such as data lake and ingestion saving options.

Additional Resources

  1. Demo Video – New Data Lake in Microsoft Sentinel – YouTube
  2. Getting started – Onboarding to Microsoft Sentinel data lake and graph (preview) | Microsoft Learn
  3. More details about data lake – Microsoft Sentinel data lake overview | Microsoft Learn
  4. Join over 600 fellow MDE users in the Defender User Group on LinkedIn
Sharing