What are the core benefits of Bitdefender XDR Sensor Identity Add-On?
Central management – Runs entirely from the GravityZone cloud console.
Identity coverage – Active Directory, Entra ID and Intune events.
Kerberos detection – Spots ticket theft, replay and brute force.
Direct response – Disable accounts or force password resets centrally.
Correlated incidents – Identity events merge into endpoint attack timelines.
Important note – Add-on only, needs a GravityZone Enterprise base.
Active Directory sensor – Detects Kerberos attacks and rogue domain controller registration
Entra ID sensor – Analyses sign-in patterns, locations and privileged group changes
Microsoft Intune sensor – Flags device ownership changes and new app configurations
Console response actions – Disable an account or force a password reset
Correlation into incidents – Identity events join endpoint activity in one timeline
Important – No protection component; needs a GravityZone Enterprise base licence
Bitdefender XDR Sensor Identity Add-On is a licence extension that connects Microsoft identity platforms to an existing GravityZone deployment, managed entirely from the GravityZone Control Center. Bitdefender documentation still labels the Entra ID connector as the Azure Active Directory sensor, which is the name most buyers will find in older guides.
No extra agents – Entra ID and Intune connect directly to GravityZone
Reuses existing agents – The AD sensor runs on domain controllers with EDR
Fewer separate alerts – One incident instead of unrelated identity and endpoint alerts
Faster credential containment – Lock a compromised account without opening Active Directory
Service provider ready – One console configures sensors across multiple tenants
Machine account visibility – Covers service and system accounts, not only users
Two things decide the fit here, and company size is only one of them. The first is whether you actually run Microsoft identity services, because the licence does nothing without Active Directory, Entra ID or Intune. The second is whether someone reviews incidents, since this add-on produces detections rather than blocking anything. Note that the Swiss reporting row below is driven by sector, not headcount: a thirty-person operator of critical infrastructure is covered while a five-hundred-person retailer is not.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | By sector | ✓ | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Active Directory or Entra ID in use | Often | ✓ | ✓ |
| This product fits | Via MSP | ✓ | ✓ |
The revised Information Security Act obliges designated operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity, BACS, within 24 hours of discovery. Meeting that deadline depends on noticing the attack in the first place, and identity abuse is one of the slowest categories to surface without dedicated telemetry, which is exactly where this add-on contributes: a stolen Kerberos ticket used for lateral movement or a sign-in from an unexpected location becomes a dated, attributable incident in the console rather than a line in a domain controller event log nobody reads. The correlated incident view also gives you the affected accounts and systems in one place, which is the substance a report actually needs. What the add-on does not do is produce the report, track the 24-hour clock, define who in your organisation is authorised to file it, or cover any identity platform other than Active Directory, Entra ID and Intune, so an incident response process with named responsibilities remains entirely your own work. It also cannot help at all with the parts of the obligation that concern governance, documented procedures or supplier oversight. This is a description of product capabilities and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures and management accountability rather than software features. NIS 2 requires covered entities to put in place measures across categories including risk analysis policies, incident handling, business continuity, supply chain security, access control policies, asset management, and the use of multi-factor authentication and secured communications. This add-on contributes to two of those categories in a concrete way: incident handling, through detection and correlation of identity-based attacks with response actions available from the console, and access control policies, through visibility into privileged group changes, over-permissive application registrations and administrative rights assignments. It contributes nothing to risk analysis policies, business continuity, supply chain security or asset management. It also does not provide multi-factor authentication itself; it observes authentication activity rather than enforcing it, so an MFA requirement still has to be met by your identity platform.
Partly, and only in one section of a typical questionnaire. It gives you defensible answers on privileged access monitoring, detection of credential-based attacks, whether administrative group changes are logged and reviewed, and whether you can disable a compromised account centrally and evidence when you did. Those are real answers backed by console records rather than assertions. It does not answer questions on multi-factor authentication enforcement, password policy, joiner-mover-leaver processes, access recertification, data classification, encryption, patching cadence, backup and restore testing, or subcontractor management, and it produces no policy documentation of any kind. If the gaps that block you are technical rather than procedural, the cheaper route is almost always to extend within the GravityZone family, since patch management, encryption and further XDR sensors are additional modules on the same console and the same reporting, and mixing a second vendor means a second console, a second agent to validate and a second set of evidence exports to reconcile. If the gaps are procedural, no licence purchase will close them.
The decisive difference is scope of telemetry, not detection quality: both feed the same correlation engine and the same Incident Advisor, but the Identity add-on brings only the Microsoft identity sensors while the Defense XDR bundle covers endpoints, identities, networks and productivity applications together. Bitdefender offers both routes deliberately, so you can start from GravityZone Business Security Enterprise and add only the sensors you need, or take the bundle when you know you want breadth. Choose the single add-on when your investigations keep stalling specifically on account activity and your endpoint coverage is already sound. Choose the bundle when unmanaged devices, Office 365 or Google Workspace are equally blind spots, because buying those sensors individually one at a time is the more expensive path.
| Sensor coverage | XDR Sensor Identity Add-On | GravityZone Defense XDR |
|---|---|---|
| Active Directory, Entra ID, Intune | ✓ | ✓ |
| Network sensor | ✕ | ✓ |
| Office 365 and Google Workspace | ✕ | ✓ |
| Cloud sensors for AWS, Azure, GCP | ✕ | Separate licence |
| Purchase model | Per sensor | Bundle |
The identity coverage is Microsoft-only. Active Directory, Entra ID and Intune are in scope; Okta, JumpCloud, Ping and any other directory are not, and Google Workspace identity activity falls under the separate Productivity sensor licence rather than this one, which is the single most common reason this add-on gets bought by the wrong customer. The Active Directory sensor is not agentless: it needs Bitdefender Endpoint Security Tools with the EDR module running on your domain controllers, so if your DCs are currently unprotected or licensed under a tier without EDR, that is an additional purchase and an additional deployment before you see any data. The add-on also contains no managed service; alert triage stays with your team, and the analyst-supported variant is a distinct product in the MDR range. Finally, remember what category this is: it detects, correlates and enables response, but it prevents nothing on its own and cannot replace endpoint protection.
No. The Google Workspace sensor belongs to the Productivity sensor licence, not the Identity licence. If your users authenticate through Google rather than Microsoft, this add-on will collect nothing useful for you.
The correlation engine builds a baseline of normal behaviour for your specific environment and merges identity events with endpoint activity into a single incident with a timeline, rather than leaving you to match a suspicious sign-in against process activity on a workstation by hand. In practice this is the difference between a queue of individually unremarkable alerts and one incident that shows the sequence.
Collects Active Directory, Entra ID and Intune events into GravityZone XDR incidents. Requires a Business Security Enterprise base licence.
Bitdefender XDR Sensor Identity Add-On, Bitdefender, GravityZone, identity sensor, active directory monitoring, entra id detection, xdr add-on, kerberos attack detection
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies