What are the key advantages of Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps?
Console managed – Centrally configured in the GravityZone cloud console.
MDR required – Only works with an active MDR subscription.
SOC monitoring – Bitdefender analysts watch Microsoft 365 around the clock.
Workspace coverage – Google Workspace accounts and files are included.
Guided response – Analysts delete malicious mail and suspend accounts.
Important note – It does not filter or block email.
Office 365 sensor – Collects account, SharePoint, OneDrive and Exchange Online events.
Google Workspace sensor – Monitors logins, admin changes, file uploads and sharing.
Behaviour baselining – Flags activity that deviates from a user's normal pattern.
SOC coverage – Bitdefender analysts triage these alerts around the clock.
Response actions – Delete malicious email and suspend accounts from GravityZone.
Important – Requires an active Bitdefender MDR or MDR PLUS subscription.
This add-on licence allows the Bitdefender MDR security operations centre to ingest and act on activity from Microsoft 365 and Google Workspace, configured from the GravityZone cloud console rather than per device. Since May 2024 the underlying service has been sold as Bitdefender MDR and MDR PLUS, replacing the earlier MDR Foundations, MDR Premium and MDR Enterprise tiers, so older quotes and internal documents may still carry those names.
Closes the SaaS gap – Endpoint agents cannot see mailbox rules or sharing abuse.
Correlated incidents – Mailbox events link to endpoint and identity activity.
Faster containment – Analysts remove malicious mail before more users open it.
No extra agent – The sensor connects directly to your tenant.
Evidence for audits – After-action and monthly reports document what analysts did.
One console – Sensor status and alerts sit beside endpoint data.
Company size matters less here than two other facts: whether your business runs Microsoft 365 or Google Workspace, and whether you already pay for Bitdefender MDR. Without the base service there is no analyst team to receive the alerts this sensor produces, which is why the smallest companies rarely reach it.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Occasionally | Often | Standard |
| Microsoft 365 or Google Workspace in daily use | ✓ | ✓ | ✓ |
| This product fits | Only with MDR | ✓ | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: since April 2025 the revised Information Security Act has required them to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and sanctions for failing to report have been in force since October 2025. The practical difficulty with a 24-hour clock is that a compromised Microsoft 365 account often leaves no trace on any endpoint, so without this sensor the mailbox rule change, the mass file access and the unusual administrative activity never reach an analyst at all. Where it helps concretely is speed and documentation: for critical and high-severity incidents the MDR team contacts your designated people within 30 minutes, and the later after-action report gives you a written timeline of what was detected and what was done. Where it does not help is the reporting itself, because the sensor neither decides whether an incident is reportable nor files anything with BACS, and it sees only Microsoft 365 and Google Workspace, so endpoint, identity and network evidence has to come from other components. This text describes product capabilities and is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses essential and important entities as organisations and holds their management accountable for the measures taken. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, access control and multi-factor authentication, cryptography, basic cyber hygiene and training, and a way to assess whether the measures actually work. This sensor contributes to one of those categories: incident handling, specifically the detection, analysis and containment of account and email compromise inside cloud productivity suites, with analysts reviewing the alerts outside office hours. It contributes nothing to business continuity or backup, nothing to supply chain and supplier risk assessment, nothing to access control or multi-factor authentication, and nothing to cryptography. It also produces no policies and no staff training, which entities are expected to maintain themselves.
Yes, for a narrow but frequently asked block of questions. It lets you answer that cloud email and collaboration platforms are monitored for account compromise, that this monitoring is staffed around the clock rather than during office hours, that a malicious message can be removed from all mailboxes in the tenant, and that written incident records exist, since the MDR service produces after-action reports per incident and a monthly report. It does not answer questions about email filtering and anti-spam, data loss prevention, backup and restore of Microsoft 365 content, enforcement of multi-factor authentication, device or disk encryption, patch levels, or the management of your own suppliers and subcontractors. Where a questionnaire fails you on those points, adding the matching Bitdefender component is usually cheaper and less disruptive than introducing a second vendor: Security for Email for filtering, the Identity Sensor for Active Directory and Entra ID, and the Network Sensor for lateral movement, all managed from the same console.
The decisive difference is not what the sensor collects but who looks at the results. Both variants gather the same Microsoft 365 and Google Workspace telemetry and offer the same response actions. The MDR variant attaches to the managed service, so Bitdefender analysts triage the alerts and act on pre-approved response actions; the self-managed variant attaches to GravityZone Business Security Enterprise and hands the alerts to your own administrators. Choose the MDR variant if nobody in your company is on call at three in the morning.
| Property | XDR Sensor for MDR | GravityZone XDR sensor |
|---|---|---|
| Base product required | MDR or MDR PLUS | Business Security Enterprise |
| Microsoft 365 and Google Workspace | ✓ | ✓ |
| Alerts reviewed by Bitdefender analysts | ✓ | ✕ |
| Response carried out by | SOC, pre-approved | Your administrators |
| Written incident reports from analysts | ✓ | ✕ |
This is a detection and response sensor, not an email security product: it does not filter, quarantine or block incoming messages before delivery, so phishing still lands in the mailbox and is removed afterwards rather than stopped at the gateway. It also stores nothing, so it is no substitute for a backup of mailbox, SharePoint or OneDrive content. One response action, marking a user as compromised, is only available to customers holding a Microsoft E5 licence, and visibility into Active Directory, network traffic or cloud workloads requires the corresponding Identity, Network and Cloud sensors, each licensed separately. Bitdefender publishes no country restriction for this sensor, but the service around it is delivered follow-the-sun from security operations centres in the United States, Romania and Singapore, while the GravityZone console itself is available as an EU-hosted option; Swiss and European buyers with data residency requirements should raise both points before signing.
No. The Office 365 and Google Workspace sensors use a direct connection between GravityZone and the platform, set up under Configuration and Sensors Management in the console. Nothing is deployed into the tenant itself.
For incidents classified as critical or high, the MDR team sends an email to your designated contacts within 30 minutes to arrange a call, and telephones again when the investigation starts. Containment through pre-approved actions can begin without waiting for your reply, if you have authorised those actions in advance.
No. This licence covers the Office 365 and Google Workspace sensors only. Detection of Kerberos attacks, stolen tickets and rogue domain controllers comes from the Identity Sensor, which is a separate add-on.
The sensor has no standalone function. It exists to feed telemetry to the managed service, so without an active Bitdefender MDR or MDR PLUS subscription there is no analyst team receiving its alerts.
Add-on sensor that feeds Microsoft 365 and Google Workspace activity into Bitdefender MDR. Requires an active MDR subscription to work.
Bitdefender XDR Sensor for MDR Productivity Apps, Bitdefender, GravityZone, MDR Foundations, managed detection and response, xdr sensor add-on, microsoft 365 monitoring, google workspace monitoring, email threat detection
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies