Skip to main content

Bitdefender Management

Overview

The Bitdefender Management static job allows IT administrators to deploy Bitdefender Endpoint Security Tools (BEST) packages directly to Windows devices from the SureMDM Console. This job is used for silently onboarding enrolled endpoints into Bitdefender GravityZone and configuring initial security modules.

note

This feature is supported on Windows devices running SureMDM Agent version 6.32.0 or later and requires a SureRMM or higher-tier subscription.

To Create a Bitdefender Management Job

  1. On the SureMDM Console, navigate to Jobs > New Job > Windows.
  2. Select Bitdefender Management from the list of available job types.
  3. In the Bitdefender Management prompt, enter a Job Name.
  4. Choose a package deployment method under Deploy Package:

Option A: Use Existing Package

Use this option to deploy a pre-existing package fetched directly from your Bitdefender GravityZone account.

  1. Select Use Existing Package from the drop-down menu.
  2. Select an existing package from the Select Package list.
  3. Review the package details (Package Name, Type, Language, and Description) displayed on the screen for confirmation.

Option B: Create Custom Package

Use this option to configure and build a custom Bitdefender deployment package directly within SureMDM.

  1. Select Create Custom Package from the drop-down menu.
  2. Configure the following parameters:
  • General: Specify the Package Name, Description, and Language.
  • Security Modules and Roles:
    • Operation Mode: Set to Detection and Prevention by default (read-only).
    • Modules: Enable the required security modules:
      • Antimalware
      • Advanced Threat Controls
      • Advanced Anti-Exploit
      • Firewall
      • Network Protection (Content Control, Anti-phishing, Web Traffic Scan, Network Attack Defense)
      • Device Control
      • Power User
    • Roles: Configure roles such as Relay.
  • Additional Settings: Enable Remove Competitors to automatically uninstall conflicting third-party security software prior to installation.
danger

Skipping competitor removal before installation is not recommended. Running multiple security solutions on the same endpoint may cause performance degradation or software incompatibility issues.

  • Scan Modes: Choose between Automatic or Custom.
    • Custom Mode: Configure specific scan types (Hybrid, Local, or Central Scan) for Computers, Virtual Machines, and EC2 Instances.
  • Settings:
    • Use Custom Installation Path: Specify a custom destination path on the target machine.

      note

      Supported only on Windows and Windows Server devices.

    • Set Uninstall Password: Enforce a password requirement to authorize the uninstallation of BEST on the device.

    • Use Custom Folder: Select the target deployment folder.

  • Deployer: Configure network proxy settings (Server, Port, Username, and Password) if target endpoints connect through a network proxy.
note
  • The Bitdefender Management static job is intended specifically for onboarding devices to Bitdefender GravityZone. If an endpoint already has a Bitdefender package installed, deploying another package will not replace or overwrite the existing installation.
  • SureMDM automatically detects the presence of an existing Bitdefender client on an endpoint to fetch and update device properties accordingly.
  1. Once done, click Save to save the changes. The newly created job will be listed in the Jobs List section.
  2. Click Apply to launch the Apply Job/Profile To Device prompt.
  3. In the Apply Job/Profile To Device prompt, select the job and click Apply.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.