Skip to main content

XDR installation

The following requirements need to be met for XDR to work on an endpoint, correlate endpoint events, and generate incidents:

  • The BEST agent needs to be installed on the endpoint with the EDR Sensor module enabled.

    If your endpoints already have the BEST agent deployed, you can use a Reconfigure agent task to add the module to the endpoint. For more information, refer to Reconfigure client.

    If no agent is installed, you will need to use an installation package to deploy BEST on your endpoints along with all required modules. For more information, refer to Install security agents - standard procedure.

  • A policy needs to be applied to the endpoint that has the feature enabled in the Incident Sensors page.

    For information on how to enable the feature for a specific policy, refer to Incidents sensor.

  • Each Sensor needs to be integrated with your GravityZone account for data to be received.

  • A license that includes the XDR feature. On it's own, the XDR feature provides endpoint-to-endpoint correlation, and gathers data from endpoint nodes.

    You require licenses for integrating additional sensors. They are grouped by the type of data they process: network, identity providers, cloud workloads, and productivity apps, or are included in specific product licenses.

    Depending on your licensing type, you can get access to sensors either through a yearly license, or enabling a specific add-on for your monthly subscription:

    Sensor name

    Yearly license

    Monthly subscription add-on

    Active Directory

    Bitdefender XDR Sensor - Identity

    eXtended Detection and Response > Identity Providers

    Azure AD (Entra ID)

    Microsoft Intune

    Office 365 sensors (Email and Management Audit)

    Bitdefender XDR Sensor - Productivity

    eXtended Detection and Response > Productivity apps

    Google Workspace

    Network

    Bitdefender XDR Sensor - Network

    eXtended Detection and Response > Network

    AWS

    Bitdefender XDR Sensor - Cloud

    eXtended Detection and Response > Cloud workloads

    Azure Cloud

    Google Cloud Platform

    Security for Mobile

    Bitdefender GravityZone Security for Mobile

    Mobile Security

    CSPM+

    Bitdefender GravityZone Cloud Security

    N/A

    AWS

    Azure Cloud

    Google Cloud Platform

    You can find a list of compatible licenses under Features by product

Tip

If this is your first time using XDR, we recommend checking out our XDR onboarding guide.