AzureHow-To & HardeningRetrospectives

How to Plan a Microsoft Sentinel Deployment: Workspaces, Connectors and Costs

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2019, written in 2026 with the benefit of hindsight.

A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's own deployment guidance follows, simplified for mid-sized organizations.

Step 1: Define use cases

List the top threats you want to detect: account takeover, business email compromise, ransomware precursors, cloud admin abuse, data exfiltration. Each use case tells you which data you need.

Step 2: Design the workspace

  • Most mid-sized organizations need one Log Analytics workspace in a region that meets data residency requirements.
  • Use separate workspaces only for clear reasons: regulatory separation, multiple tenants, or very different retention needs.
  • Place the workspace in a dedicated security subscription or resource group with restricted access.

Step 3: Prioritize data connectors

High value, often low or no cost:

  • Microsoft Entra ID sign-in and audit logs.
  • Microsoft Defender XDR incidents and alerts.
  • Microsoft 365 (Office 365) audit logs.
  • Azure Activity logs.

Then add: AWS CloudTrail, firewalls, VPNs, and critical servers.

Step 4: Plan roles

Use built-in roles (Microsoft Sentinel Reader, Responder, Contributor) and grant the least privilege needed.

Step 5: Estimate costs

Estimate daily ingestion per source. Compare pay-as-you-go with commitment tiers, and identify data that can go to lower-cost tiers.

Step 6: Deploy and tune

Enable Sentinel, install solutions from the Content Hub, connect sources, enable analytics rules for your use cases, and spend two weeks tuning false positives.

Common mistakes

  • Connecting verbose sources first and blowing the budget.
  • Enabling hundreds of rules nobody triages.
microsoft sentinel deploymentAzure Sentinel preview2019

More on this story