Bitdefender GravityZone Quickstart Guide

Introduction

This article covers initial setup of the Bitdefender GravityZone console, including understanding your network and company structure, managing users, configuring policy, installing agents, and getting familiar with core reporting and investigation tools.

Splashtop x Bitdefender Integration is coming soon. Current Splashtop capabilities can be found here: Bitdefender GravityZone Availability

gzOverview_en-us.PNG

An active Bitdefender GravityZone account is required to access the console referenced in this article.

1. Network & Companies

Path: Network / Companies

gzNetwork_en-us.png

The Network page is where all entities in an environment can be viewed and managed - this includes computers, virtual machines, Security Servers, and any companies set up under the account.

GravityZone organizes customers into Companies - each company account represents a distinct customer environment. Every Splashtop account provisioned in GravityZone can be set up as one of two company types:

  • Partner - used when an account manages child companies, e.g., an MSP with multiple clients under management.
  • Customer - used when an account only manages its own network. This is more common for something like an internal IT team.

Partner accounts will see their own endpoints listed directly under Network, and managed clients listed under Companies, each with independent license allocation and usage tracking. Customer accounts will see their own endpoints listed directly under Network.

An MSP can be provisioned as either type, depending on preference and use case:

  • Partner is the better fit if end clients will need their own access to the GravityZone console, since users can be added to a specific child company only, scoping their visibility to just their own devices. Separate license allocation per child company also prevents any one client from going over their allotted count.
  • Customer works fine for an MSP too, if end clients won't need console access and the MSP plans to fully manage everything themselves. In this case, clients can be organized into Groups instead of separate companies - this works as long as the MSP is comfortable tracking device/license counts on their own, since Groups don't have independent allocation or usage tracking.
gz_create_group_en-us.png

Within a company, endpoints can be organized into Groups. Unlike Companies, Groups don't have independent license allocation or usage tracking - they're for organizational purposes only (e.g., by department, device type, or location). Groups can be created from the Network view.

From the Network view, you can also select one or more endpoints to push actions, such as reconfiguring installed modules, uninstalling the agent, or isolating an endpoint.

Related documentation:

2. Add and Manage Console Users

Path: Accounts → Add Account

Additional console users can be created to give teammates or client contacts access to GravityZone.

Assign a role. Built-in roles include:

Role Access
Company Administrator For administrators of a company. Manages that company's own security and users, including child companies.
Network Administrator Administrative privileges over security agent deployment, either across the whole company or a specific group of endpoints.
Security Analyst Read-only access to security data, reports, and logs - useful for monitoring-only personnel.
Custom Build a role from individual rights if a built-in role doesn't fit.

Related documentation:

3. Review Policies

Path: Policies

Policies control agent behavior and are where most day-to-day tuning happens. Endpoints are assigned to a default policy upon installation. You can review the default or create and assign a new one. Below is a high-level overview, but check out the articles linked at the bottom of this section for more details. Key sections to review:

General

  • End-user UI notifications and what's visible to the end user
  • Auto-update settings - by default, the Bitdefender agent checks for updates every hour unless otherwise configured

Antimalware

  • Scan profiles and on-demand scan scheduling
  • Exclusions
  • Anti-tampering - prevents the agent from being disabled locally on the endpoint

Network Protection

  • Application blacklisting and web access control
  • Web traffic scanning and Network Attack Defense

Device Control

  • Allow or block specific device types (USB drives, external media, etc.) from connecting to protected endpoints

Sandbox Analyzer & EDR

  • If evaluating Advanced Threat Security (ATS) and/or EDR, enable the Sandbox Analyzer and EDR Incidents Sensor modules here

Related documentation:

4. Install the Agent

Manual Installation

  1. Log into GravityZone, click Installation Packages (under Network in the left-hand nav), and either create a new package or select an existing one.
  2. Checkbox the package and click Download.
  3. Download the package (Downloader recommended).
  4. Run the installer package on the endpoint.
  5. For macOS: authorize Full Disk Access and any other required system extension permissions for the Bitdefender agent in System Preferences/Settings.

Silent Installation

Windows

  1. Log into GravityZone, click Installation Packages (under Network in the left-hand nav), and either create a new package or select an existing one.
  2. Check the box next to the package → click Send Download Links.
  3. The URL will include something like setupdownloader_[veryLongString].exe. Copy the long string inside the brackets (not including the brackets) - this is your package ID, needed in the steps below.
  4. Download the MSI Wrapper.
  5. Run the following command via CMD or a 3rd party deployment tool. Replace {packageID} with the long string copied earlier.

    msiexec /i BEST_downloaderWrapper.msi /qn GZ_PACKAGE_ID={packageID} REBOOT_IF_NEEDED=1
  6. After installation, confirm the agent appears under Network in the GravityZone console.

macOS

  1. Log into GravityZone, click Installation Packages (under Network in the left-hand nav), and either create a new package or select an existing one.
  2. Check the box next to the package → click Send Download Links.
  3. Copy the macOS Downloader URL.
  4. Run the following shell script. Replace [your_installation_package_url] with the macOS Downloader URL.

    #!/bin/bash
    
    BD_TEMP="/var/tmp/temp_bd"	
    mkdir -p $BD_TEMP && cd $_
    curl -L -O [your_installation_package_url]
    hdiutil attach setup_downloader.dmg
    /Volumes/Endpoint\ for\ MAC/SetupDownloader.app/Contents/MacOS/SetupDownloader --silent
    hdiutil detach /Volumes/Endpoint\ for\ MAC/
    rm -rf $BD_TEMP
  5. After installation, confirm the agent appears under Network in the GravityZone console.

Related documentation:

5. Viewing Threats

Path: Threats Xplorer

Threats Xplorer centralizes detection events from across GravityZone's protection technologies, so it's the go-to place to review what's been detected and how it was handled. The feature centralizes detection events from the following modules:

  • Antimalware
  • Network Protection
  • Storage Protection
  • Exchange Protection
  • Device Control
  • Firewall
gzThreatsXplorer_en-us.PNG
  • Events are shown in reverse-chronological order for the selected time period, with the most recent at the top.
  • Click into an event to open its detail panel - this includes threat type, action taken, detecting module, and endpoint details like risk score and assigned policy.
  • Filters can be applied by category, threat type, endpoint, and more to narrow down results.
  • Events can be exported as a CSV for reporting or further analysis elsewhere.

For full details on filtering, columns, and exporting, refer to Bitdefender's documentation below.

Related documentation:

6. Show Quarantine

Path: Reports → Quarantine

  • Quarantined items can be restored, retrieved, or permanently deleted (emptied) from this view.

Related documentation:

7. Reports

Path: Reports

  • Reports cover Usage & Licensing, Threats, and Quarantine, among other areas, and can be scheduled or exported for regular review.

Related documentation:

8. Incidents (EDR)

Path: Incidents

gz_incident_en-us.png

If EDR or XDR is enabled, incidents can be reviewed to investigate and respond to correlated threats. An incident aggregates related security events into a single view, rather than requiring each event to be reviewed individually.

  • The Endpoint Incidents tab lists incidents detected at the endpoint level that haven't yet been actioned. Selecting an incident opens its detail panel for a quick look at the key attack indicators.
  • Opening an incident's Graph shows the full sequence of events that led to it, highlighting the critical path and the specific event that triggered the incident.
  • The graph's Node Details panel breaks down incident info (ID, status, timestamp, involved artifacts) as well as a Remediation section showing actions already taken automatically by GravityZone, along with recommended next steps.
  • The Events tab shows a filterable, chronological list of the underlying system events and alerts that were correlated into the incident.

Additional Bitdefender Resources

Beyond this article, Bitdefender provides additional resources for deeper learning and reference.

GravityZone Documentation

Bitdefender's full GravityZone documentation and help center can be accessed from within the console, or directly through Bitdefender's support site.

Demo Zone: Guided Interactive Tours

Bitdefender's demo zone offers interactive, guided tours of GravityZone features, including EDR incident investigation, which can be a useful supplement to hands-on exploration in your own console.

0 out of 0 found this helpful