<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender XDR Sensor for MDR (Add-On) Cloud?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>AWS sensor</strong> – Collects CloudTrail and AWS Config events into GravityZone.<br /> <strong>Azure Cloud sensor</strong> – Collects subscription activity through a registered Entra ID application.<br /> <strong>Google Cloud sensor</strong> – Collects activity events from Google Cloud Platform projects.<br /> <strong>MDR analyst coverage</strong> – Bitdefender SOC analysts triage the resulting cloud detections.<br /> <strong>Correlation with endpoints</strong> – Cloud events are correlated with endpoint and identity telemetry.<br /> <strong>Important</strong> – No agent protection for cloud workloads is included here.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender XDR Sensor for MDR (Add-On) Cloud?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This add-on is a separately licensed sensor that brings Amazon Web Services, Microsoft Azure and Google Cloud Platform activity data into the GravityZone XDR correlation engine, where Bitdefender vendor documentation lists it as the GravityZone XDR Sensor for MDR Cloud. It is set up and managed centrally in GravityZone Control Center under Configuration and Sensors Management, and the events it delivers land in the same incidents the Bitdefender MDR security operations centre works on.<br /><br /> <strong>Cloud blind spot closed</strong> – Control plane actions become visible next to endpoint events.<br /> <strong>Fewer parallel consoles</strong> – Cloud detections appear in the same incident view.<br /> <strong>Analyst time saved</strong> – The SOC triages cloud alerts instead of your team.<br /> <strong>Faster attack reconstruction</strong> – Incidents show how a login led to cloud changes.<br /> <strong>Multi-cloud coverage</strong> – AWS, Microsoft Azure and Google Cloud are all supported.<br /> <strong>Evidence for reporting</strong> – Incident timelines document what happened and when.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where built-in protection stops and why detection and response layers exist above it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender XDR Sensor for MDR (Add-On) Cloud suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you actually run workloads in a public cloud and already pay for a managed detection service. A company with three virtual machines in Azure and no MDR subscription gains nothing from this add-on; a company with a growing AWS footprint and an existing MDR contract closes a real gap with it.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Workloads in AWS, Azure or Google Cloud</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Only with MDR</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Cloud meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The revised Information Security Act obliges operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and most other companies are not covered by that duty at all. Where cloud infrastructure is part of what you operate, this sensor shortens the time needed to establish the facts, because the incident already contains the surrounding cloud activity instead of requiring someone to pull CloudTrail or Azure activity logs by hand under time pressure. The MDR service contributes the second half of that: analysts who look at the detection at three in the morning rather than the next working day. What the add-on does not do is decide whether you are in scope, file anything with BACS, or protect the workloads themselves, which still requires the security agent on the instances. It also produces no register of your reporting obligations, so the organisational side stays with you. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Cloud meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company compliant with the NIS 2 Directive, because the directive addresses risk management measures and governance, not software features. NIS 2 asks entities in scope to cover risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, and access control including multi-factor authentication. This add-on contributes to exactly one of those categories: incident handling, through continuous collection of cloud activity, correlation with endpoint and identity events, and documented incident timelines that can be shown to an auditor. It contributes nothing to backup and business continuity, staff training, cryptography, access control, or the assessment of your own suppliers. Those measures require separate products and, more decisively, written processes that someone in your organisation owns.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Cloud help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only in one section of a typical questionnaire. It gives you a defensible answer to items on 24/7 monitoring, on whether cloud infrastructure activity is logged and reviewed, on who performs alert triage, and on whether incidents can be reconstructed after the fact, since the sensor plus the MDR service means a named provider does the watching rather than an unstaffed mailbox. It answers nothing on encryption at rest, backup and restore testing, patch timelines, identity and access management, multi-factor authentication, staff awareness training, penetration testing, or cloud misconfiguration reviews. The misconfiguration item is the one that most often trips buyers up, because it looks like something a cloud sensor should cover and it is not: posture management sits in Bitdefender Cloud Security (CSPM+), a separate product. Where several gaps remain, adding the matching modules from the same GravityZone family is usually cheaper and less work to evidence than assembling answers from three different vendors with three different report formats.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between XDR Sensor Cloud and XDR Sensor for MDR Cloud?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is who looks at the alerts. Both variants collect the same cloud activity data and feed the same GravityZone XDR correlation engine, so the technical coverage is not what separates them. The plain XDR Sensor Cloud assumes your own team opens the console and works the incidents. The MDR variant is intended for tenants where the Bitdefender MDR service is active, so the cloud telemetry falls inside what the security operations centre monitors, and setup includes confirming that the company is correctly enrolled in the MDR service with the required permissions granted. If you have no MDR subscription, the MDR variant is the wrong article.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">XDR Sensor Cloud</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">XDR Sensor for MDR Cloud</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">AWS, Azure and Google Cloud events</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Correlation in GravityZone XDR</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Alert triage by Bitdefender analysts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Active MDR service required</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Suitable without an in-house SOC</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This sensor reads the cloud platform's own activity and configuration logs; it does not protect the virtual machines and containers running inside those accounts, which still need the Bitdefender security agent and, for container environments, the separate container protection add-on. Cloud posture management and misconfiguration scanning belong to a different product, Bitdefender Cloud Security (CSPM+), and are licensed on their own. Identity events from Microsoft Entra ID are collected by the identity sensors rather than the cloud sensor, and that distinction is the single most common reason for an unplanned second purchase. Setup is not a one-click integration either: AWS expects CloudTrail, AWS Config, an S3 bucket, an SQS queue and an IAM policy with defined permissions, while Azure expects a registered Entra ID application holding the Reader role on the subscription, so plan a maintenance slot with someone who has cloud administrator rights. Finally, GravityZone Cloud runs on several separate cloud instances, so if the location of processed data is a requirement in your organisation, confirm which instance your tenant sits on before you order.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the recovery side that detection and response services deliberately leave out.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender XDR Sensor for MDR (Add-On) Cloud</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens if the sensor loses its permissions?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Sensors Management page shows a status for every integration: Active, Disabled, Action needed or Offline. Action needed and Offline usually mean one or more permissions are missing, and the sensor stops processing data until they are restored, which is worth putting on a monitoring checklist rather than discovering during an incident.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can a compromised AWS account be shut down from the console?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In AWS Control Tower environments, access keys belonging to a compromised IAM account can be disabled and removed from the Management Account, either from the alert details panel or from the Response tab of the incident. Which further response actions are available depends on the permissions you granted during integration.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does this sensor replace a SIEM?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. It delivers cloud events into GravityZone incidents for detection and correlation, not long-term log storage and free-form search across arbitrary sources. For that, Bitdefender offers the separate Security Data Lake product, along with integrations to SIEM platforms such as Splunk, Microsoft Sentinel and IBM QRadar.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-cloud" data-audience="b2b" data-count="3"> </div>