<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender XDR Sensor for MDR (Add-On) Identity?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Active Directory sensor</strong> – Collects domain controller events for attack detection.<br /> <strong>Entra ID sensor</strong> – Monitors cloud sign-ins, users and app permissions.<br /> <strong>Microsoft Intune sensor</strong> – Tracks device ownership, policy and app changes.<br /> <strong>Identity response actions</strong> – Disable an account or force a password reset.<br /> <strong>MDR SOC coverage</strong> – Bitdefender analysts watch identity telemetry around the clock.<br /> <strong>Important</strong> – No endpoint protection included; a GravityZone base licence is required.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender XDR Sensor for MDR (Add-On) Identity?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is a licence add-on that feeds Active Directory, Microsoft Entra ID and Microsoft Intune telemetry into GravityZone XDR, where it is managed centrally from the GravityZone Control Center and monitored by the Bitdefender MDR Security Operations Centre. Bitdefender lists it as GravityZone XDR Sensor for MDR – Identity, while the console still shows the components as the Active Directory sensor and the Azure AD sensor, the second name dating from before Azure Active Directory was renamed Microsoft Entra ID.<br /> <br /> <strong>Central console</strong> – All identity detections appear in GravityZone Control Center.<br /> <strong>Kerberos attack detection</strong> – Flags brute force, ticket theft and replay attempts.<br /> <strong>Rogue controller detection</strong> – Spots attackers registering an unauthorised domain controller.<br /> <strong>Cloud sign-in analysis</strong> – Detects sign-ins from unusual regions and locations.<br /> <strong>Pre-approved actions</strong> – SOC analysts can contain accounts without waiting for approval.<br /> <strong>Correlated incidents</strong> – Identity events joined with endpoint activity in one timeline.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender XDR Sensor for MDR (Add-On) Identity suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor here is not headcount but whether identity is a real attack surface: a Windows domain, a Microsoft 365 tenant, or both. A company with a handful of Entra ID accounts and no domain controller gains little from a dedicated identity sensor plus a managed SOC on top. From the point where privileged accounts, several locations or an on-premises domain controller exist, identity becomes the realistic route an attacker takes from one compromised laptop to the whole network.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Increasing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Active Directory or Entra ID in use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Identity meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure in Switzerland, which is a question of sector rather than company size. Affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. That deadline is the practical problem this add-on helps with: identity telemetry from Active Directory and Microsoft Entra ID shows which accounts were used, when, and from where, so a first report can name a concrete account and a concrete time window instead of a vague suspicion. Because the sensor feeds the Bitdefender MDR SOC, detection and initial triage do not depend on someone in your own team noticing an alert at two in the morning. What the product does not provide is the reporting process itself: there is no BACS report template, no deadline tracking, and no assessment of whether a given incident is reportable at all. This text is general information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Identity meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product creates NIS 2 compliance, because the directive addresses organisational measures, governance and management accountability rather than tooling. NIS 2 requires entities in scope to have measures covering incident handling, risk analysis, business continuity, supply chain security, access control policies and multi-factor authentication, with management bodies responsible for overseeing them. This add-on contributes concretely to two of those categories: incident handling, through round-the-clock detection and triage of identity attacks by the Bitdefender SOC, and access control, through visibility into privileged group changes, over-permissive application registrations and sign-ins from unusual locations. It contributes nothing to business continuity, backup, supplier assessment or governance documentation, and it does not implement multi-factor authentication, which the directive names explicitly among the required measures. Entities in scope should treat it as one detection control inside a wider management system, not as a NIS 2 measure package.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Identity help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a narrow but frequently asked set of questions. It lets you answer that identity systems are monitored for attacks, that monitoring runs 24/7 through an external SOC rather than during office hours only, that privileged account changes are detected, and that a compromised account can be disabled or forced through a password reset from a central console. It does not answer questions about encryption, patch management, backup and recovery, secure software development, supplier assessment, awareness training or certification status, and a questionnaire that asks for evidence of those will still come back with gaps. The cheaper route to closing them is usually a higher edition or a further sensor add-on inside the same GravityZone family, because the answers then come from one console and one reporting source; mixing vendors creates a second set of evidence you have to reconcile by hand every time a customer asks.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why detection alone does not restore data, and how backup planning covers the recovery gap this add-on leaves open.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the Identity Sensor for MDR and the standard XDR Identity Sensor?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is not what the sensor collects, but who looks at what it collects. Both variants gather the same identity telemetry from Active Directory, Microsoft Entra ID and Microsoft Intune, and both surface incidents in the same GravityZone Control Center. The standard XDR Identity Sensor assumes your own team triages those incidents and decides on the response. The MDR variant is intended for companies already enrolled in the Bitdefender MDR service, where the Bitdefender SOC monitors the identity telemetry as part of the managed service and can act through pre-approved actions. Choosing the MDR variant without an active MDR service leaves you paying for managed coverage you cannot use.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">XDR Sensor for MDR – Identity</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">XDR Identity Sensor</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Active Directory, Entra ID, Intune telemetry</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Incidents in GravityZone Control Center</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Monitored by Bitdefender SOC</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Containment through pre-approved actions</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Requires active MDR service</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is a sensor licence, not a protection product: it detects and reports identity attacks but blocks no malware, and it needs an active, compatible GravityZone base licence underneath it. The identity sensor category covers Microsoft identity platforms only, namely Active Directory, Microsoft Entra ID and Microsoft Intune; sensor categories are licensed separately, so buying Identity gives you no network, cloud or productivity application coverage. Response actions against Active Directory require at least one online domain controller running Bitdefender Endpoint Security Tools with the EDR module enabled, which means you must accept an agent on a domain controller. On the cloud side, forcing a password reset requires the registered Entra application to hold the User Administrator role, acting on administrator accounts requires Global Administrator, and the risky-user permissions depend on a Microsoft Entra ID P2 licence, which is a Microsoft cost that catches buyers out most often.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Sets out where built-in Windows security stops and where dedicated detection and response layers begin.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender XDR Sensor for MDR (Add-On) Identity</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the add-on work without an on-premises Active Directory?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The Entra ID and Intune sensors use a direct connection between GravityZone and your Microsoft tenant, set up through an app registration with Microsoft Graph permissions, and require no software on your side. Only the Active Directory sensor depends on an agent, since it reads events from the domain controller itself.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the Bitdefender SOC disable an account without asking you first?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Only within the pre-approved actions you agree in advance as part of the MDR service. These are defined containment steps, such as isolating a host or neutralising an account, that analysts may execute immediately so that response is not delayed by an approval call at night. Anything outside that agreed list is escalated to your contacts rather than actioned.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-console" data-audience="b2b" data-count="3"> </div>