BT Managed Sentinel

MSSP

BT Managed Sentinel is a managed Microsoft Sentinel and SIEM service for buyers that want BT's SOC to monitor, tune and investigate Sentinel incidents. After an alert, BT analysts triage and investigate in Sentinel and Microsoft 365 Defender context, then advise the buyer on action while the buyer still owns Microsoft licensing, log-source configuration and remediation.

What they do
Investigate and advise
Works with
Your stack
Built for
Enterprise / Mid-Market
Price
Public G-Cloud price from £6,275 per instance
Best for
Microsoft-aligned enterprises or public-sector buyers that want Sentinel operated by an external SOC

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications

Your team still owns

  • Maintaining Azure, Microsoft Sentinel and required Microsoft licences
  • Configuring log-source devices and network connectivity so logs reach the service
  • Taking remediation and containment actions after BT advises on the incident
  • Paying for extended log retention, platform usage or professional services outside the base order

Pricing

Line Figure
Published price Public G-Cloud price from £6,275 per instance
Billing model Flat-fee, Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Clear fit for buyers that specifically want Microsoft Sentinel managed
  • Public G-Cloud listing exposes a starting price, support model and offboarding process
  • BT documents buyer prerequisites and log-source responsibilities more clearly than many managed SIEM pages
  • Keeps response authority with the buyer, which can suit regulated teams

Watch out for

  • Not MDR or full SOC outsourcing by default
  • Buyer still owns remediation and containment unless another service covers it
  • Microsoft licensing, ingestion, retention and professional services can add cost beyond the public starting signal
  • Managed Sentinel-specific customer review evidence is thin

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which incidents receive analyst investigation versus alert forwarding, and what are the notification targets by severity?
  2. Which remediation or response actions, if any, can BT execute without a separate XDR or professional-services scope?
  3. How much of the final cost sits in Microsoft licensing, data ingestion, retention, onboarding and professional services?

Integrations

Microsoft SentinelMicrosoft 365 DefenderMicrosoft Defender suiteAzureAWSGCPCEFSyslogMicrosoft 365 security incidentsThird-party data connectors

Editorial notes

Why investigate-and-advise lane

BT's service definition says SOC analysts conduct incident investigation so they can advise the buyer on the course of action. That is more than monitoring, but public evidence does not show base-scope direct containment.

Microsoft-first boundary

The service fits buyers that want Microsoft Sentinel operated by an external SOC. Buyers without Azure, Sentinel or the required Microsoft licences should treat those prerequisites as part of the buying decision.

XDR boundary

BT sells Managed Sentinel and XDR language together in some materials. This profile keeps the label to Managed Sentinel because the core public service is Sentinel monitoring, triage, tuning and advice.

Pricing boundary

The public G-Cloud listing gives a useful starting signal, but it is not the full operating cost. Microsoft platform charges, log retention, onboarding, onsite support and professional services can change the real budget.

Questions

Is BT Managed Sentinel an MDR service?
No. This profile treats it as Managed Sentinel and Managed SIEM. BT uses XDR language in some materials, but the core public service is Microsoft Sentinel monitoring, tuning, investigation and buyer guidance.
What does BT do after a Sentinel alert?
BT SOC analysts triage, correlate and investigate in Microsoft Sentinel and Microsoft 365 Defender context, then advise the buyer on action. Buyers should confirm whether any direct response actions require a separate XDR or professional-services scope.
Is BT Managed Sentinel pricing public?
The UK G-Cloud listing shows pricing from £6,275 per instance. Buyers should still price Microsoft licensing, data ingestion, storage, onboarding, recurring service charges and professional services before comparing it with MDR or full SOC providers.