<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Office 365 sensor</strong> – Collects account, SharePoint, OneDrive and Exchange Online events.<br /> <strong>Google Workspace sensor</strong> – Monitors logins, admin changes, file uploads and sharing.<br /> <strong>Behaviour baselining</strong> – Flags activity that deviates from a user's normal pattern.<br /> <strong>SOC coverage</strong> – Bitdefender analysts triage these alerts around the clock.<br /> <strong>Response actions</strong> – Delete malicious email and suspend accounts from GravityZone.<br /> <strong>Important</strong> – Requires an active Bitdefender MDR or MDR PLUS subscription.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This add-on licence allows the Bitdefender MDR security operations centre to ingest and act on activity from Microsoft 365 and Google Workspace, configured from the GravityZone cloud console rather than per device. Since May 2024 the underlying service has been sold as Bitdefender MDR and MDR PLUS, replacing the earlier MDR Foundations, MDR Premium and MDR Enterprise tiers, so older quotes and internal documents may still carry those names.<br /><br /> <strong>Closes the SaaS gap</strong> – Endpoint agents cannot see mailbox rules or sharing abuse.<br /> <strong>Correlated incidents</strong> – Mailbox events link to endpoint and identity activity.<br /> <strong>Faster containment</strong> – Analysts remove malicious mail before more users open it.<br /> <strong>No extra agent</strong> – The sensor connects directly to your tenant.<br /> <strong>Evidence for audits</strong> – After-action and monthly reports document what analysts did.<br /> <strong>One console</strong> – Sensor status and alerts sit beside endpoint data.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why the protection built into a platform covers less than most administrators assume, and where the detection gaps sit.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Company size matters less here than two other facts: whether your business runs Microsoft 365 or Google Workspace, and whether you already pay for Bitdefender MDR. Without the base service there is no analyst team to receive the alerts this sensor produces, which is why the smallest companies rarely reach it.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Microsoft 365 or Google Workspace in daily use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Only with MDR</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: since April 2025 the revised Information Security Act has required them to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and sanctions for failing to report have been in force since October 2025. The practical difficulty with a 24-hour clock is that a compromised Microsoft 365 account often leaves no trace on any endpoint, so without this sensor the mailbox rule change, the mass file access and the unusual administrative activity never reach an analyst at all. Where it helps concretely is speed and documentation: for critical and high-severity incidents the MDR team contacts your designated people within 30 minutes, and the later after-action report gives you a written timeline of what was detected and what was done. Where it does not help is the reporting itself, because the sensor neither decides whether an incident is reportable nor files anything with BACS, and it sees only Microsoft 365 and Google Workspace, so endpoint, identity and network evidence has to come from other components. This text describes product capabilities and is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses essential and important entities as organisations and holds their management accountable for the measures taken. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, access control and multi-factor authentication, cryptography, basic cyber hygiene and training, and a way to assess whether the measures actually work. This sensor contributes to one of those categories: incident handling, specifically the detection, analysis and containment of account and email compromise inside cloud productivity suites, with analysts reviewing the alerts outside office hours. It contributes nothing to business continuity or backup, nothing to supply chain and supplier risk assessment, nothing to access control or multi-factor authentication, and nothing to cryptography. It also produces no policies and no staff training, which entities are expected to maintain themselves.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a narrow but frequently asked block of questions. It lets you answer that cloud email and collaboration platforms are monitored for account compromise, that this monitoring is staffed around the clock rather than during office hours, that a malicious message can be removed from all mailboxes in the tenant, and that written incident records exist, since the MDR service produces after-action reports per incident and a monthly report. It does not answer questions about email filtering and anti-spam, data loss prevention, backup and restore of Microsoft 365 content, enforcement of multi-factor authentication, device or disk encryption, patch levels, or the management of your own suppliers and subcontractors. Where a questionnaire fails you on those points, adding the matching Bitdefender component is usually cheaper and less disruptive than introducing a second vendor: Security for Email for filtering, the Identity Sensor for Active Directory and Entra ID, and the Network Sensor for lateral movement, all managed from the same console.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between the XDR Sensor for MDR and the GravityZone XDR Productivity Applications Sensor?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is not what the sensor collects but who looks at the results. Both variants gather the same Microsoft 365 and Google Workspace telemetry and offer the same response actions. The MDR variant attaches to the managed service, so Bitdefender analysts triage the alerts and act on pre-approved response actions; the self-managed variant attaches to GravityZone Business Security Enterprise and hands the alerts to your own administrators. Choose the MDR variant if nobody in your company is on call at three in the morning.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">XDR Sensor for MDR</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">GravityZone XDR sensor</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Base product required</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">MDR or MDR PLUS</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Business Security Enterprise</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Microsoft 365 and Google Workspace</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Alerts reviewed by Bitdefender analysts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Response carried out by</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">SOC, pre-approved</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Your administrators</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Written incident reports from analysts</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is a detection and response sensor, not an email security product: it does not filter, quarantine or block incoming messages before delivery, so phishing still lands in the mailbox and is removed afterwards rather than stopped at the gateway. It also stores nothing, so it is no substitute for a backup of mailbox, SharePoint or OneDrive content. One response action, marking a user as compromised, is only available to customers holding a Microsoft E5 licence, and visibility into Active Directory, network traffic or cloud workloads requires the corresponding Identity, Network and Cloud sensors, each licensed separately. Bitdefender publishes no country restriction for this sensor, but the service around it is delivered follow-the-sun from security operations centres in the United States, Romania and Singapore, while the GravityZone console itself is available as an EU-hosted option; Swiss and European buyers with data residency requirements should raise both points before signing.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers why detection and response tools do not replace a backup, and what an outage actually costs a business.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender XDR Sensor for MDR (Add-On) Productivity Apps</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the sensor need software installed on our servers or mailboxes?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. The Office 365 and Google Workspace sensors use a direct connection between GravityZone and the platform, set up under Configuration and Sensors Management in the console. Nothing is deployed into the tenant itself.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How fast does Bitdefender react to a serious incident?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">For incidents classified as critical or high, the MDR team sends an email to your designated contacts within 30 minutes to arrange a call, and telephones again when the investigation starts. Containment through pre-approved actions can begin without waiting for your reply, if you have authorised those actions in advance.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does this replace the Identity Sensor for Active Directory?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. This licence covers the Office 365 and Google Workspace sensors only. Detection of Kerberos attacks, stolen tickets and rogue domain controllers comes from the Identity Sensor, which is a separate add-on.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens to the sensor if the MDR subscription ends?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The sensor has no standalone function. It exists to feed telemetry to the managed service, so without an active Bitdefender MDR or MDR PLUS subscription there is no analyst team receiving its alerts.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,sec-email" data-audience="b2b" data-count="3"> </div>