Bitdefender Management
SureMDM integrates seamlessly with Bitdefender GravityZone to unify endpoint management and endpoint security within a single console. By bridging unified endpoint management (UEM) with Bitdefender's Endpoint Protection Platform (EPP), IT teams can eliminate context-switching between separate management portals and maintain complete control over device health and security posture.
Key Integration Benefits
- Unified Management: Oversee device management and Bitdefender security status from a single, centralized SureMDM dashboard.
- Automated & Silent Deployment: Silently push Bitdefender Endpoint Security Tools (BEST) packages across enrolled endpoints, enabling automated security onboarding without user intervention.
- Real-Time Telemetry Visibility: Monitor live security status, active policy enforcement, and endpoint health directly within the SureMDM device grid.
- Instant Remote Remediation: Trigger immediate threat responses-such as executing on-demand malware scans, terminating malicious processes, or assigning security policies directly from the SureMDM console.
Prerequisites
- Supported Tier: SureRMM, Premium, and Enterprise.
- Supported OS: Windows and Windows Server devices.
- Agent Version: SureMDM Agent version 6.32.0 or later.
- Bitdefender Credentials: Bitdefender Endpoint URL and a valid API Key.
Step 1: Configure Bitdefender Integration in SureMDM
To establish communication between SureMDM and Bitdefender GravityZone:
- In the SureMDM Console, navigate to Account Settings > Enterprise Integrations > Bitdefender.
- Select Enable Bitdefender Integration.
- Enter the required parameters:
| Field | Description |
|---|---|
| Bitdefender Endpoint | Enter your Bitdefender cloud instance URL (e.g., https://cloud.gravityzone.bitdefender.com/) |
| API Key | Enter the generated Bitdefender API key |
- Click Test Connection.
- Upon successful validation, the status changes to Connected, and the List of Enabled Bitdefender APIs (e.g., Companies, Licensing, Packages, Network, Policies, Incidents, PatchManagement) is displayed.
- Click Save.
Step 2: Create a Bitdefender Management Job
You can deploy existing Bitdefender installation packages or create a custom security package to push to enrolled Windows devices.
- Go to Jobs > Create Job > Windows / Windows Server.
- Select Bitdefender Management.
- Enter a Job Name.
- Choose the Deploy Package option:
Option A: Use Existing Package
- Select Use Existing Package from the drop-down menu.
- Choose an existing Bitdefender package from the Select Package list.
- Package details (Package Name, Type, Language, Description) will be displayed for confirmation.
Option B: Create Custom Package
Select Create Custom Package and configure the following parameters:
- General: Define Package Name, Description, and Language.
- Security Modules and Roles: The Operation Mode is set to Detection and Prevention by default and is greyed out (read-only). Enable the following required modules:
- Antimalware
- Advanced Threat Controls
- Advanced Anti-Exploit
- Firewall
- Network Protection (Content Control, Anti-phishing, Web Traffic Scan, Network Attack Defense)
- Device Control
- Power User
- Roles (Relay)
- Additional Settings: Option to Remove Competitors (automatically uninstalls existing third-party security software).
Skipping competitor removal before installation is not recommended. Running multiple security solutions on the same machine may lead to performance or incompatibility issues.
- Scan Modes: Choose between Automatic or Custom.
- Custom Mode: Configure specific scan types (Hybrid, Local, or Central Scan) for Computers, Virtual Machines, and EC2 Instances.
- Settings:
- Use Custom Installation Path: Specify a custom destination path on the target machine. (Supported only on Windows & Windows Server)
- Set Uninstall Password: Require a password to authorize uninstallation of BEST on the device.
- Use Custom Folder: Select target deployment folder.
- Deployer: Configure proxy communication settings (Server, Port, Username, Password) if endpoints connect through a network proxy.
- Click Save.
- The Bitdefender Management job is intended specifically for onboarding devices to Bitdefender. If a device already has a Bitdefender package installed, deploying another package will not replace the existing installation.
- BEST will automatically uninstall conflicting security software on target endpoints when Remove Competitors is enabled.
Step 3: Manage Endpoints via Dynamic Job
Once deployed, administrators can view device security status and run management commands directly from the device grid using the Bitdefender Management dynamic job.
Endpoint Details Tab
Displays real-time telemetry reported by the Bitdefender agent, including device, agent, policy, security, and management information.
The tab includes 40+ parameters, such as:
- General: Device ID, Name, Company ID, Operating System, IP Address, Machine Type, Last Seen, State, Label, Move State, and Managed With BEST status.
- Policy: Currently enforced Bitdefender policy ID and Policy Name.
- MalwareStatus: Current malware protection status reported by the agent.
- Agent: Bitdefender agent information and status
- Group: Group associated with the endpoint
- Modules: Status and information for Bitdefender security modules
- RiskScore: Security risk score associated with the endpoint
The Endpoint Details tab contains additional parameters beyond those listed above. The available information may vary based on the Bitdefender agent version and the endpoint configuration.
Actions Tab
Allows administrators to execute remote operations on the endpoint:
| Action | Description |
|---|---|
| Set Endpoint Label | Assigns custom administrative tags to the endpoint. |
| Kill Process | Remotely terminates running processes on the device. |
| Assign Policy | Enforces a specific Bitdefender security policy on the endpoint. |
| Move Endpoint to a Custom Group | Reassigns the device to a specified group in Bitdefender GravityZone. |
| Malware Scan | Triggers an immediate on-demand malware scan on the device. The scan can be performed using either Quick Scan or Full Scan, depending on the required scan scope. |