What are the core benefits of Avast Business Antivirus Pro?
Flexible management – Runs standalone per device or centrally managed.
Server protection – Windows Server plus on-premises Exchange and SharePoint.
Ransomware defence – Ransomware Shield and Remote Access Shield included.
Platform coverage – Windows workstations, Windows servers and macOS devices.
Current tier – Avast now delivers this as Premium Business Security.
Important note – No EDR, no Linux agent, no mobile management.
Multi-layer endpoint protection – File, Web, Mail and Behavior Shields on every device.
Exchange Server protection – Scans mailboxes on on-premises Exchange Server 2010 to 2019.
SharePoint Server protection – Scans files on on-premises SharePoint Server 2010 to 2019.
Avast Business Hub – Optional cloud console for policy, deployment and reporting.
Ransomware and firewall – Ransomware Shield, Remote Access Shield and centrally managed firewall.
Important – No EDR component, no Linux agent, no mobile device management.
Avast Business Antivirus Pro is endpoint antivirus for Windows workstations, Windows servers and macOS devices, with additional scanning for on-premises Exchange and SharePoint Server. It can run standalone on each device or be managed centrally from the cloud-based Avast Business Hub, and Avast has since moved this tier to the name Avast Premium Business Security, which existing activation codes now unlock.
One agent for servers – Removes the need for a separate mail-server scanner.
Optional central console – Add the Business Hub later without reinstalling the agents.
Remote deployment – Network discovery pushes the agent to unprotected Windows devices.
Shared detection engine – All three Business Security tiers use the same antivirus build.
VPN in this tier – SecureLine VPN is included for Windows devices.
Data Shredder – Erases files permanently before hardware leaves the company.
This is a prevention product for organisations that need solid malware protection on Windows and macOS without running a security operations team. The decisive question is whether anyone will ever ask you to reconstruct an incident after the fact, because that is where this product stops.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Mostly exempt | By sector | By sector |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Needs EDR and stored event telemetry | ✕ | Increasingly | ✓ |
| This product fits | ✓ | Partly | ✕ |
The Swiss reporting obligation does not apply to every company. Since 1 April 2025 the revised Information Security Act (ISG) requires operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and since 1 October 2025 a missed report can be sanctioned. If your organisation is in scope, this product helps at the detection stage: the Business Hub records which device raised which detection and at what time, which is the material you need for a first report inside the 24-hour window. It does not help you answer the questions that follow, because there is no EDR component, no stored event telemetry to query afterwards and no attack-path reconstruction, so the follow-up report within 14 days will depend on other sources. Whether your organisation falls under the obligation depends on your sector and your size, and this text is a description of product capabilities, not legal advice.
No security product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management rather than software features. NIS 2 requires in-scope entities to put measures in place across several categories, among them incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication. Avast Business Antivirus Pro covers a narrow slice of that list: malware prevention and detection on Windows workstations, Windows servers and macOS devices, plus firewall and web-filtering policy applied from one console. It contributes nothing to backup, which is a separate add-on, nothing to patch and vulnerability handling unless you buy that add-on or the Ultimate tier, and nothing at all to encryption, identity, multi-factor authentication or staff training. Because the directive is transposed separately in each member state, the exact scope and reporting timelines that apply to you depend on where your organisation is established.
Two authorities have issued binding decisions against Avast over the same underlying practice. On 22 February 2024 the US Federal Trade Commission announced an order, finalised on 27 June 2024, requiring Avast Limited to pay USD 16.5 million and prohibiting it from selling, disclosing or licensing web browsing data for advertising purposes; the order also requires an independently assessed privacy programme for twenty years, so it remains in force. On 10 April 2024 the Czech data protection authority made a fine of CZK 351 million final and binding for transferring pseudonymised browsing histories of roughly 100 million users to its subsidiary Jumpshot in 2019 without a lawful basis. Avast's own position is that it closed Jumpshot in January 2020 and that it considered the data anonymised at the time; it exhausted its appeals in the Czech proceedings. Both decisions concern consumer antivirus products and browser extensions, not the business endpoint line, and independent laboratory results for the business engine are unaffected: AV-Comparatives issued an Approved Business Security Product award in July 2024 and AV-TEST certified the Windows corporate endpoint build in June 2025. In practice this matters most if you sell into the public sector or answer supply-chain questionnaires that ask whether a supplier has been subject to a regulatory finding, because you will have to disclose and explain it; for a private company with no such reporting line it is background rather than a blocker.
Partly, and the gaps are large enough that you should know them before you commit. It answers the questions about deployed anti-malware on all workstations and servers, centrally enforced antivirus and firewall policy, real-time scanning of files, web traffic and inbound and outbound mail, protection of on-premises Exchange and SharePoint Server, removable-media control through USB Protection, and web filtering through Web Control. It does not answer the questions about endpoint detection and response, retention of security event logs for a defined period, forwarding of events to a SIEM or syslog collector, disk encryption and key management, multi-factor authentication, mobile device management, or protection of Linux servers, and patch management and backup are only answered if you buy those separately. Two of those gaps close inside the same product family, which is usually the cheaper route: patch management by moving to Avast Ultimate Business Security, and backup by adding Avast Business Cloud Backup. Endpoint detection and response, encryption management and identity are not offered anywhere in this line, so those answers have to come from a different vendor or from your existing Microsoft licensing.
The single decisive difference is patch management: Ultimate includes it, Premium requires it as a paid add-on. All three Business Security tiers use the identical antivirus and firewall engine, so the protection quality is the same and the difference is entirely in the services around it. Avast Business Antivirus Pro maps to the Premium tier, which adds SecureLine VPN, USB Protection and Web Control over the Essential tier. One practical consequence: the online management platform is optional for Essential and Premium, but required for Ultimate, because patch management only works as a managed service.
| Feature | Essential | Premium | Ultimate |
|---|---|---|---|
| Antivirus and firewall components | ✓ | ✓ | ✓ |
| Exchange and SharePoint Server protection | ✓ | ✓ | ✓ |
| Online management platform | Optional | Optional | Required |
| SecureLine VPN | ✕ | Windows only | Windows only |
| USB Protection | ✕ | Console only | Console only |
| Web Control | ✕ | Console only | Console only |
| Patch Management | Add-on | Add-on | ✓ |
| Cloud Backup | Add-on | Add-on | Add-on |
The most common follow-up purchase is caused by platform coverage: Linux is not part of this product line at all, it is a separately purchased unmanaged agent, and mobile device management no longer exists in any Avast Business Security tier. On macOS the agent protects the device but several components are Windows-only, including SecureLine VPN, Browser Shield, Patch Management and Cloud Backup, so a mixed fleet ends up with two different protection levels. Exchange and SharePoint Server protection applies to the on-premises server products, not to Exchange Online or SharePoint Online, and Windows Server Core installations are not supported. USB Protection and Web Control can only be configured through the cloud-based Business Hub, and the current line cannot be run from an on-premises console, so a fully self-hosted management setup is not possible. The largest structural gap is the absence of endpoint detection and response, which is what most buyers discover only when an insurer, an auditor or a large customer asks for incident forensics.
Windows Server 2012, 2016, 2019, 2022 and 2025 in 64-bit, in any edition with the latest service pack, with the exception of Server Core installations. Workstations are covered on Windows 10 and Windows 11.
No. The Exchange Server Protection component scans mailboxes on an on-premises Exchange Server; it does not connect to Exchange Online. If your mail runs in Microsoft 365, mail is still scanned when it reaches a protected endpoint through the Mail Shield, but there is no scanning at the cloud mailbox itself.
No. Ransomware Shield and the Data Shredder work on live files on the endpoint and do not create recoverable copies. Avast Business Cloud Backup is a separate add-on that must be purchased and enabled through the Business Hub.
Endpoint antivirus for Windows PCs, Windows servers and macOS, with Exchange and SharePoint Server protection. Central console is optional.
Avast Business Antivirus Pro, Avast, Avast Premium Business Security, Avast Business Hub, business antivirus, endpoint protection, exchange server protection, sharepoint server protection, server antivirus
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies