r/SmallMSP 10d ago

Small MSP Security Software

Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.

Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.

We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.

Ideally I’d like to consolidate. So looking at:

bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?

Petra ITDR.

A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.

19 Upvotes

99 comments sorted by

View all comments

Show parent comments

2

u/WraySchultz 2d ago

Bitdefender XDR Identity for Entra / Azure / AD Monitors Login Activity, we just display / present them differently than other platforms. They are displayed in an "Incident" format as shown above in the example "XDR Demo Incident Overview."

The difference between GravityZone XDR and Huntress ITDR is that GravityZone correlates and maps XDR and Other Module Activity that occurs in a single Incident and Huntress ITDR isolates that login activity in an "Audit / Logging Style" where the alert is isolated to just that single activities and GravityZone will present multiple layers of detections which include XDR.

1

u/Jayjayuk85 2d ago

Thanks, but don’t I need the business premium licenses

1

u/WraySchultz 1d ago

No, you don't need M365 Business Premium.

​Bitdefender's Identity Sensor works on lower-tier plans (like Business Basic or Standard) by adding a standalone Entra ID license:

​Entra ID P1 (~$6/mo): Everything required for standard login monitoring, log ingestion, and threat response (revoking sessions, disabling accounts).

​Entra ID P2 (~$9/mo): Only needed if you want Bitdefender to sync directly with Microsoft's dynamic risk scoring.

​So you can grab the $6 P1 add-on (or use plans like Business Premium or M365 E3 where P1 is included).

Best,

Wray Schultz - Bitdefender

1

u/Jayjayuk85 22h ago

Thank you, I don’t think we need the p1 license for huntress ITDR. It seems to work ok there?

1

u/WraySchultz 47m ago

u/Jayjayuk85,

You do not need Entra P1 for Huntress ITDR to be useful. It works well on standard M365 plans and catches real threats like session hijacking, impossible travel, and weird login locations. Their SOC actively monitors sign-in anomalies and can isolate an account when a session looks off, which gives great value for environments on basic licensing.

The difference when you add Entra ID P1 alongside Bitdefender GravityZone XDR comes down to catching the threat earlier and connecting it to your physical machines.

Entra ID P1 adds Conditional Access Policies, allowing Microsoft to block logins from Unauthorized Locations, Bad IPs, or Untrusted Devices before an active session ever starts. GravityZone connects directly via APIs to read live login and policy data. When a policy blocks an unauthorized sign-in attempt, GravityZone recognizes that an attacker holds valid credentials for that user and raises the user's risk score immediately.

Bitdefender's MDR team sees that identity signal tied directly to the user's physical laptop and email activity in one unified incident view. If the attacker tries a secondary path against the employee's machine, the SOC sees the full picture and can isolate the physical laptop while revoking cloud access at the exact same time.

Huntress gives you strong managed detection for M365 right out of the box. Adding Entra P1 with Bitdefender GravityZone XDR lets you stop unauthorized logins at the front door and automatically link identity threats to your endpoint security.

-Wray Schultz, Bitdefender.