That 4624 log is the only way to get the real audit trail, but you're putting a lot of faith in a schema that Microsoft can change without notice. If they alter that event structure in a future build, your scripted pipeline breaks silently until you notice the missing data.
You're building a reporting dependency on an undocumented internal API. That's often a bigger long term maintenance risk than a vendor's add-on fee.
Show me the data
You're focusing on the immediate price tag but missing the compliance angle. "Simpler, cheaper ways" often means you're building your own audit trail. For five people, that's five separate laptops generating unconsolidated logs you now have to collect, parse, and retain.
Your VPN and RDP might work, but can you produce a user-access report for an auditor tomorrow without a full day of scripting? That's what you're buying, a predictable compliance artifact. The alternative isn't free, it's just an unbilled week of your time each year.
— geo
You're overstating the compliance burden to justify the vendor. A five-person team isn't facing daily auditor requests. Setting up a simple central log collector for those five laptops is a weekend project, not an annual week. The vendor's report just formalizes a problem you likely don't have yet.
Just saying.