<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender GravityZone Security for Exchange Servers?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Exchange Protection module</strong> – Installs with Bitdefender Endpoint Security Tools on the mail server.<br /> <strong>Antimalware scanning</strong> – Checks message bodies and attachments in the transport path.<br /> <strong>Antispam and antiphishing</strong> – Multi-layer filters backed by the Bitdefender Global Protective Network.<br /> <strong>Content and attachment filtering</strong> – Custom rules for subjects, bodies, file types and names.<br /> <strong>Exchange quarantine</strong> – Blocked messages held centrally and released from Control Center.<br /> <strong>Important</strong> – No coverage for Exchange Online or Microsoft 365 mailboxes.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender GravityZone Security for Exchange Servers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Bitdefender GravityZone Security for Exchange Servers is an email security module for on-premises Microsoft Exchange, delivered through the Bitdefender Endpoint Security Tools agent installed on the mail server itself. Policies, quarantine and reporting run in GravityZone Control Center, the same console used for endpoint protection.<br /> <br /> <strong>No mail rerouting</strong> – Filtering happens on the server, MX records stay unchanged.<br /> <strong>Internal mail scanned</strong> – Catches threats sent between your own internal mailboxes.<br /> <strong>Information Store scans</strong> – On-demand scanning of the Exchange mailbox databases.<br /> <strong>DAG compatible</strong> – Works on Database Availability Group members without extra components.<br /> <strong>Single console</strong> – Mail and endpoint events land in one report set.<br /> <strong>Conflict handling</strong> – The built-in Exchange antimalware agent is disabled automatically.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Microsoft products stops and what a dedicated security product adds on top of it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender GravityZone Security for Exchange Servers suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but architecture: this product is only relevant if you still run Microsoft Exchange on your own servers. A company of any size that has moved its mailboxes to Microsoft 365 gets nothing from it.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<thead>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
</thead>
<tbody>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually exempt</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually not</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Runs its own Exchange server</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Only with Exchange</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Exchange Servers meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Since 1 April 2025 the revised Information Security Act obliges operators of critical infrastructure in Switzerland, such as energy and drinking water suppliers, transport companies, data centres and cantonal and municipal administrations, to report cyberattacks, while most ordinary companies below the size and sector thresholds are not affected. Organisations in scope must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering the attack, and have 14 days to complete it. For the mail side of such a report, Exchange Protection is useful because every detection, quarantined message and policy change is recorded in GravityZone Control Center, so you can answer when a malicious message arrived, which mailboxes received it and what action was taken, instead of reconstructing this from raw Exchange transport logs under time pressure. What it does not do is equally clear: it sees nothing outside the Exchange transport path, it has no incident case management, it does not notify BACS for you, and it provides no evidence about endpoints, accounts or cloud mailboxes unless separate GravityZone components are licensed. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Exchange Servers meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive places obligations on the organisation and its management, not on a piece of software. NIS 2 requires risk management measures across categories such as incident handling, business continuity and backup, supply chain security, security in the acquisition and maintenance of network and information systems, policies on the use of cryptography, and multi-factor authentication. Security for Exchange Servers contributes to two of these in a concrete way: it is a technical control on the mail path, and its quarantine and event records feed the incident handling process with evidence about email-borne attacks. It contributes nothing to business continuity and backup, nothing to supply chain security, nothing to cryptography or multi-factor authentication, and it does not cover cloud mailboxes at all. Organisations in scope will therefore need to combine it with endpoint protection, a tested backup, identity controls and a documented incident process to address the remaining measure categories.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Exchange Servers help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, but only for the email section, which is typically a handful of items out of a hundred. It lets you answer that inbound and outbound mail is scanned for malware, spam and phishing; that filtering happens on the mail server itself through Exchange transport agents rather than at a third-party service; that blocked messages go to a central quarantine with a controlled release process; that policies are managed centrally with role-based console access; and that threat activity on the mail path can be exported as a report covering a defined period. It will not answer the items that carry the most weight in a supplier assessment: endpoint protection and detection and response, patch management and evidence of patch levels, disk encryption, multi-factor authentication and identity management, backup and restore testing, data classification, and protection of any mailboxes that already live in Microsoft 365. To close those gaps, moving up within the same family is usually cheaper and less work than mixing vendors, because everything stays in one console and one reporting set: GravityZone Business Security Premium or Business Security Enterprise cover endpoint protection and detection, and Bitdefender offers patch management and full disk encryption as add-ons to those packages.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="office-2024-backup-business-pst-windows"><strong>Planning Office 2024 Backups for Businesses the Right Way</strong><br />Covers how to back up files, Outlook PST archives, templates and the Windows system, which is the gap an email filter alone does not close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between GravityZone Security for Exchange Servers and GravityZone Extended Email Security?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is where the filtering happens and which mail platform it can protect. Security for Exchange Servers runs as a module of the Bitdefender agent on your own Exchange server and inspects mail inside the transport path, so it also sees internal traffic and needs no change to mail routing. Extended Email Security is Bitdefender's separate email platform for Microsoft 365 and Google Workspace, deployed either as a gateway in front of the mail flow or through an API-based integration, and it can also sit in front of an on-premises or hybrid Exchange environment. If your buyers still search for GravityZone Security for Email, that is the older platform that Extended Email Security replaced. Choose by architecture, not by feature list: mailboxes on your own Exchange server point to this product, mailboxes in the cloud point to Extended Email Security.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<thead>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Criterion</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Security for Exchange Servers</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Extended Email Security</th></tr>
</thead>
<tbody>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Filtering point</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">On the Exchange server</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Gateway or API</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">On-premises Exchange</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Microsoft 365 mailboxes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Google Workspace mailboxes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Change to mail routing needed</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Depends on mode</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Managed in</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">GravityZone Control Center</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Own console</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important one is platform scope: this product protects Microsoft Exchange running on your own servers and does nothing for mailboxes that have already moved to Exchange Online, so a hybrid environment is only half covered and the cloud side needs a separate Bitdefender product. It is a mail-path control and nothing more, which means no endpoint detection and response, no patch management, no disk encryption and no mailbox backup, so a mailbox that is compromised through a stolen password rather than an attachment is outside its reach entirely. It also requires GravityZone Control Center to be in place before the module can be deployed, and if you are not already a GravityZone customer that console has to be set up first, either as the Bitdefender-hosted cloud service or as an on-premises virtual appliance, the latter being the relevant option when management data has to stay in your own datacentre. The most common follow-up purchase is therefore not more email security but the endpoint side of the same platform, because auditors and large customers ask about endpoints long before they ask about mail filtering.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?</strong><br />Useful if your Exchange server is running on an older Windows Server release and you need to plan the underlying platform before the security layer.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender GravityZone Security for Exchange Servers</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which Exchange versions and server roles are supported?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Bitdefender supports Exchange Server 2019, 2016 and 2013, in each case with the Edge Transport or the Mailbox role, and only the features compatible with the detected role are installed. Deployment is also compatible with Database Availability Groups, so members of a DAG do not need a separate approach. Exchange Server 2010 was dropped from Exchange Protection on 30 April 2026 and is no longer supported.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Where do blocked emails go and who can release them?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Messages stopped by the antimalware, antispam or content filters are held in the Exchange quarantine and are visible on the quarantine page of GravityZone Control Center. An administrator can restore a message to the original recipient or release it, and because console access is role-based you can decide who is allowed to do that. This matters in practice because false positives on business mail need a fast, auditable release path rather than a support ticket to the mail administrator.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it also scan mail sent between internal colleagues?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Bitdefender states that the product secures the entire Exchange environment, including user, room, equipment and shared mailboxes, against both external and internal threats. This is the practical advantage over a pure perimeter gateway, which only inspects mail crossing the network boundary and never sees a malicious attachment forwarded from one internal mailbox to another after an account has been taken over.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-email,sec-server,sec-console" data-audience="b2b" data-count="3"> </div>