Incident Response Pricing for SOC & MSP Teams

Startup adoption pricing: simple plans designed to be below typical enterprise SOC/MDR entry costs.

Positioned against common market offerings from providers like CrowdStrike, Arctic Wolf, Expel, Rapid7, and Sophos.

Starter

Perfect for small teams

Free

Forever


  • 1 Connected Tenant
  • 7 Days Log Retention
  • Basic Alerts
  • Excel Export
  • API Access
  • Custom Detection Rules
Get Started
Most Popular

Professional

For growing MSPs

$79

per month


  • 10 Connected Tenants
  • 30 Days Log Retention
  • Advanced Alerts
  • Excel & PDF Export
  • API Access
  • Custom Detection Rules
Start Free Trial

Enterprise

For large organizations

From $249

per month (or custom)


  • 25+ Tenants (unlimited on custom)
  • 1 Year Log Retention
  • Custom Alerts
  • All Export Formats
  • Full API Access
  • Custom Detection Rules
Contact Sales

Need a larger or custom package?

If you need annual billing, tenant overages, or add-on services, get in touch with our Sales team for a tailored quote.

Get in touch with Sales Request a Demo

Frequently Asked Questions

AzureIR requires read-only access to Azure AD sign-in logs and audit logs through Microsoft Graph API. We need AuditLog.Read.All, Directory.Read.All, and Reports.Read.All permissions. We never modify any data in your tenant.

When connecting a customer tenant, a Global Administrator from that tenant must grant consent for AzureIR to access their Azure AD logs. This is done through Microsoft's secure OAuth 2.0 admin consent flow.

Yes! All data is encrypted at rest and in transit. We use industry-standard security practices and comply with SOC 2 Type II requirements. Your data is never shared with third parties.

Yes, you can cancel your subscription at any time. There are no long-term contracts or cancellation fees. Your data will be retained for 30 days after cancellation.