Microsoft Adds SIEM to Defender for E5 and E7 Users, Charging $2.40 per GB for Outside Data
Updated
Updated · Computerworld · Sep 24
Microsoft Adds SIEM to Defender for E5 and E7 Users, Charging $2.40 per GB for Outside Data
3 articles · Updated · Computerworld · Sep 24
Summary
Sept. 23 marked the public preview of Microsoft’s Integrated Security Operations Center, letting Microsoft 365 E5 and E7 customers run SIEM inside Defender with no separate Sentinel license.
The offer is aimed at customers already centered on Microsoft’s stack: telemetry from Defender, Entra, Azure and Office 365 comes without ingestion charges, while third-party and other external data will cost $2.40 per GB from Oct. 1.
Microsoft is bundling case management, workbooks and natural-language playbook generation into the Defender portal, with 30-day retention in preview rising to 90 days on Nov. 15.
The preview excludes organizations with an active Sentinel workspace, though eligible customers can choose to move to ISOC from Nov. 15; anything beyond the included features requires an Azure-backed ISOC workspace.
Analysts said the bundle could lower costs and simplify investigations for Microsoft-heavy environments, but mixed estates still need a full SIEM cost comparison and tighter controls as Microsoft pushes agent-driven security operations.