Azure Sentinel Pricing Clarification

%3CLINGO-SUB%20id%3D%22lingo-sub-1431585%22%20slang%3D%22en-US%22%3EAzure%20Sentinel%20Pricing%20Clarification%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1431585%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20just%20on-boarded%20a%20customer%20to%20my%20tenant%20and%20I%20have%20used%20ARM%20template%20to%20get%20a%20delegation%20access%20of%20a%20resource%20group%20from%20my%20customers%20tenant.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20resource%20group%20contains%20a%20LogAnalyticsWorkspace%20and%20I%20am%20using%20that%20in%20my%20Azure%20Sentinel%20Workspace.%20It%20is%20like%20I%20have%20got%20the%20delegated%20access%20of%20it%20and%20now%20I%20am%20using%20Azure%20Sentinel%20at%20my%20tenant%20to%20go%20through%20the%20logs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20question%20is%20that%20if%20I%20connect%20%22Azure%20AD%20Data%20Connector%22%20and%20started%20getting%20the%20logs%20into%20the%20Azure%20Sentinel%20then%20could%20anyone%20please%20let%20me%20know%20that%20how%20the%20pricing%20will%20work%20%3F%20like%20customer%20will%20be%20charged%20for%20it%20or%20I%20will%20be%20getting%20the%20cost%20of%20data%20ingestion%20as%20I%20have%20used%20Azure%20Sentinel%20at%20my%20workspace.%20Also%2C%20if%20there%20is%20any%20cost%20that%20will%20add%20up%20to%20the%20customer%20apart%20from%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1431585%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eimportant%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

I have just on-boarded a customer to my tenant and I have used ARM template to get a delegation access of a resource group from my customers tenant.

 

Customer resource group contains a LogAnalyticsWorkspace which I use in my Azure Sentinel Workspace. since I have delegated access. I am using Azure Sentinel of my tenant to go through the logs.

 

My question is that if I connect "Azure AD Data Connector" and start ingesting the customer logs into my Azure Sentinel, then would I be charged for log ingestion or will the customer be charged. Also, if there is any additional cost that will be charged from the customer.

 

I could not locate the correct microsoft azure documentation which covers this scenario. Your help will be much appreciated.

8 Replies
Hi

If you are using Lighthouse and configure the AAD Connector for their workspace, you will not be charged.
As long as the data resides in the tenant of the customer

@Rajkamal1960 You would not want to ingest the data into your tenant (but you would pay the ingestion charges and your client would pay egress charges if in a different region).  Like @Thijs Lecomte said, use Azure Lighthouse to interact with your customers.  

 

This article will get you started:

https://docs.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers

 

also take a look at module 3 in the training - MSSP  

 

https://techcommunity.microsoft.com/t5/azure-sentinel/become-an-azure-sentinel-ninja-the-complete-le...

 

"...A special use case is providing service using Azure Sentinel, for example by an MSSP (Managed Security Service Provider) or by a Global SOC in a large organization. "

@Gary Bushey  Thanks for the clarification.

 

It means that I will be charged if I am working on Azure Sentinel at my tenant on the LogAnanlyticsWorkspace of my client's tenant. As I have already got the delegated access of that resource group of client's workspace. Please let me know if my understanding is correct.

 

Also it would be much appreciated if you can tell me more about egress charges if in a different region. 

 

Thanks

@Rajkamal1960 *IF* you do not use Azure Lighthouse, and again that is the preferred method, you will be charged for the data coming into your Azure Sentinel instance.  With Lighthouse, all the data stays on the client side.

 

You can go here to see more on egress charges: https://azure.microsoft.com/en-us/pricing/details/bandwidth/

@Gary Bushey If I am not using Azure Lighthouse then what other methods I have to ingest logs in to my Azure Sentinel Workspace from my client's AD.

 

Because if I am not using Azure Lighthouse then I will not be able to get the delegated access of their resource groups and will not be able to get the access of their LogAnalyticsWorkspace.

 

 

@Rajkamal1960 Your other options would include having an account setup on their tenant (or use B2B) or ingest the data into your Azure Sentinel instance.

 

The additional accounts would be preferable to ingesting the data into your account

Hi @Rajkamal1960,
I have experience with your problem.

1. With the ARM template, you established the "Azure Light House" between you and your customer tenant. Well, done! From now, everything that your customer connects to their tenant you will be able to access it.
2. Anything (see 3) that is connected to the customer tenant is billed to the customer tenant. Therefore if the Azure AD Data Connector appeared turned on in the customer tenant you already know who will pay the bill. Note that as the ARM template is established you can query the data and create monitoring rules (KQL).
3. At https://azure.microsoft.com/en-us/pricing/details/azure-sentinel/ it is saying that "Azure Activity Logs, Office 365 Audit Logs (all SharePoint activity and Exchange admin activity) and alerts from Microsoft Threat Protection products (Azure Security Center, Office 365 ATP, Azure ATP, Microsoft Defender ATP, Microsoft Cloud App Security, Azure Information Protection) can be ingested at no additional cost into both Azure Sentinel, and Azure Monitor Log Analytics. Please Note: Azure Active Directory (AAD) audit data is not free and is billed for ingestion into both Azure Sentinel, and Azure Monitor Log Analytics." Therefore, if it says nothing regarding a connector (for example Azure AD Connector) then it is paid!

I hope I was helpful.