How to Plan a Microsoft Sentinel Deployment: Workspaces, Connectors and Costs
Retrospective: this article looks back at events from February 2019, written in 2026 with the benefit of hindsight.
A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's own deployment guidance follows, simplified for mid-sized organizations.
Step 1: Define use cases
List the top threats you want to detect: account takeover, business email compromise, ransomware precursors, cloud admin abuse, data exfiltration. Each use case tells you which data you need.
Step 2: Design the workspace
- Most mid-sized organizations need one Log Analytics workspace in a region that meets data residency requirements.
- Use separate workspaces only for clear reasons: regulatory separation, multiple tenants, or very different retention needs.
- Place the workspace in a dedicated security subscription or resource group with restricted access.
Step 3: Prioritize data connectors
High value, often low or no cost:
- Microsoft Entra ID sign-in and audit logs.
- Microsoft Defender XDR incidents and alerts.
- Microsoft 365 (Office 365) audit logs.
- Azure Activity logs.
Then add: AWS CloudTrail, firewalls, VPNs, and critical servers.
Step 4: Plan roles
Use built-in roles (Microsoft Sentinel Reader, Responder, Contributor) and grant the least privilege needed.
Step 5: Estimate costs
Estimate daily ingestion per source. Compare pay-as-you-go with commitment tiers, and identify data that can go to lower-cost tiers.
Step 6: Deploy and tune
Enable Sentinel, install solutions from the Content Hub, connect sources, enable analytics rules for your use cases, and spend two weeks tuning false positives.
Common mistakes
- Connecting verbose sources first and blowing the budget.
- Enabling hundreds of rules nobody triages.
- Azure Sentinel Preview (Feb 2019): Microsoft Enters the Cloud SIEM Market Platform Changes
- Sentinel Data Connector Priority Checklist How-To & Hardening
- CIO Brief: Cloud-Native SIEM vs. Legacy SIEM — The Cost and Coverage Trade-Off CIO Briefings