- Best for
- Microsoft-aligned enterprises or public-sector buyers that want Sentinel operated by an external SOC
They cover
- Endpoints
- Cloud Workloads
- Identity & Access
- Network
- SaaS Applications
Your team still owns
- Maintaining Azure, Microsoft Sentinel and required Microsoft licences
- Configuring log-source devices and network connectivity so logs reach the service
- Taking remediation and containment actions after BT advises on the incident
- Paying for extended log retention, platform usage or professional services outside the base order
Pricing
| Line | Figure |
|---|---|
| Published price | Public G-Cloud price from £6,275 per instance |
| Billing model | Flat-fee, Custom |
| Contract | Not published |
| Onboarding | Not published |
Tradeoffs
Works well
- Clear fit for buyers that specifically want Microsoft Sentinel managed
- Public G-Cloud listing exposes a starting price, support model and offboarding process
- BT documents buyer prerequisites and log-source responsibilities more clearly than many managed SIEM pages
- Keeps response authority with the buyer, which can suit regulated teams
Watch out for
- Not MDR or full SOC outsourcing by default
- Buyer still owns remediation and containment unless another service covers it
- Microsoft licensing, ingestion, retention and professional services can add cost beyond the public starting signal
- Managed Sentinel-specific customer review evidence is thin
What buyers say
Alert noise
Not assessed
Transparency
Not assessed
Reputation reads from public reviews, not vendor-published numbers.
Ask before buying
- Which incidents receive analyst investigation versus alert forwarding, and what are the notification targets by severity?
- Which remediation or response actions, if any, can BT execute without a separate XDR or professional-services scope?
- How much of the final cost sits in Microsoft licensing, data ingestion, retention, onboarding and professional services?
Integrations
Editorial notes
Why investigate-and-advise lane
BT's service definition says SOC analysts conduct incident investigation so they can advise the buyer on the course of action. That is more than monitoring, but public evidence does not show base-scope direct containment.
Microsoft-first boundary
The service fits buyers that want Microsoft Sentinel operated by an external SOC. Buyers without Azure, Sentinel or the required Microsoft licences should treat those prerequisites as part of the buying decision.
XDR boundary
BT sells Managed Sentinel and XDR language together in some materials. This profile keeps the label to Managed Sentinel because the core public service is Sentinel monitoring, triage, tuning and advice.
Pricing boundary
The public G-Cloud listing gives a useful starting signal, but it is not the full operating cost. Microsoft platform charges, log retention, onboarding, onsite support and professional services can change the real budget.