Bitdefender GravityZone is one of the best-scoring endpoint protection platforms in independent tests, but getting it properly deployed and tuned is where most organisations leave protection gaps on the table. This guide walks through a complete GravityZone deployment for an Indian business environment — from console setup to policy configuration to integration with email security.
GravityZone Deployment Options
Before starting, decide which deployment model suits your environment:
GravityZone Cloud (Recommended for most Indian businesses)
- Management console hosted by Bitdefender
- No on-premise infrastructure to manage
- Agents connect to Bitdefender cloud for updates and policy
- Best for: businesses without a dedicated IT server, remote/hybrid workforces
- Setup time: 2–4 hours
GravityZone On-Premise (Virtual Appliance)
- Management console runs in your data centre as a virtual machine (VMware ESXi or Hyper-V)
- All management traffic stays within your network
- Required for: BFSI entities with strict data localisation requirements, air-gapped environments
- Setup time: 4–8 hours including VM provisioning
GravityZone Cloud MSP / Multi-Tenant
- For Cloudfy managed deployments — a single console manages multiple customer environments
- Available through Cloudfy's MSP programme
Phase 1: GravityZone Cloud Console Setup
Step 1: Activate Your GravityZone Console
- You will receive a GravityZone activation email from Bitdefender (or from Cloudfy if purchasing through us)
- Set your console password and configure your company profile
- Console URL format:
https://[your-company].gravityzone.bitdefender.com - Default time zone: Configure to Asia/Kolkata (IST) immediately — all logs and alerts use the console time zone
Step 2: Configure SMTP for Alerts
- Go to My Account > Notifications
- Configure email notifications for: New incident detected, Malware blocked, Agent offline, Licence expiry
- Use your organisation's SMTP relay or any business SMTP service
- Set alert recipient to your IT team distribution list
Step 3: Configure Network — Relay (If Applicable)
For environments where endpoints cannot reach the Bitdefender cloud directly (common in Indian manufacturing plants or secure environments):
- Designate one Windows server as the Communication Server (Relay)
- Install the GravityZone Communication Server role on this server
- Endpoints communicate with the relay; relay communicates with the cloud
- Configure firewall rules: allow the relay server outbound HTTPS (443) to
*.bitdefender.com
Phase 2: Organising Your Network
Step 4: Configure Network Inventory
- Go to Network > Network Inventory
- GravityZone automatically discovers Windows devices in your AD domain
- For non-domain devices (home PCs, personal laptops used for work): use the manual installation package
- Organise devices into groups matching your business structure:
- Finance Team
- HR
- IT
- Servers
- Remote Employees
- BYOD Devices
Groups allow you to apply different policies per department — finance team may need stricter web filtering; IT team needs AV exclusions for management tools.
Step 5: Add Custom Groups for Indian Business Contexts
Consider these group structures for typical Indian deployments:
Manufacturing / Industrial:
- Production Floor PCs (stricter application control)
- Engineering Workstations (allow CAD software, specific exceptions)
- Office PCs (standard policy)
- ERP/SAP Server (server policy with no AV scanning during business hours)
BFSI (Banks/NBFCs):
- Customer-Facing Terminals (locked down, no USB, no personal browsing)
- Back Office (standard + USB blocked)
- Treasury/Trading Terminals (maximum security, application whitelist)
- Servers (server-specific scanning schedule)
Phase 3: Policy Configuration
This is the most important phase — the default GravityZone policy is permissive. Harden it before deploying agents.
Step 6: Create Your Base Policy
- Go to Policies > Add Policy
- Start from the default Bitdefender policy as a base
- Name it clearly: "Cloudfy Standard Policy — [Company] — [Date]"
Step 7: Antimalware Settings
On-Access Scanning:
- Enable: All file types
- Scan Archives: Yes
- Scan Boot Sectors: Yes
- Action for detected malware: Move to Quarantine (safer than Delete for false positive recovery)
On-Demand Scanning:
- Schedule: Weekly, Sunday 2am
- Scan network shares: Yes (important for file servers)
Advanced Anti-Exploit:
- Enable: Yes
- This is Bitdefender's protection against memory exploitation (buffer overflows, ROP chains) — particularly relevant for Indian businesses running older Windows applications
Step 8: Anti-Ransomware (Critical for India)
- Enable Ransomware Mitigation in the policy
- Enable Automatic Restore: Bitdefender creates shadow copies before suspicious file operations and can restore encrypted files if ransomware runs
- Enable Network Share Scanning: ransomware often spreads to shared folders — this detects the pattern at the network share level
For Indian businesses, ransomware is the #1 endpoint security threat. This section deserves more attention than any other policy setting. Ensure Ransomware Mitigation + Automatic Restore is explicitly enabled — it is not on by default.
Step 9: Firewall (Host-Based)
Bitdefender GravityZone includes a host-based firewall (replaces Windows Firewall on managed endpoints):
- Enable: Yes
- Mode: Alert initially (log all blocked connections for 2 weeks before switching to Enforce)
- Generic Rules: Block inbound connections on all ports except required services (RDP if needed, specific application ports)
- Stealth Mode: Enable — makes the endpoint invisible to port scans
Note for Indian environments: If your business uses Zoho, Google Workspace, or any SaaS tool, ensure the firewall rules allow HTTPS outbound (port 443) broadly — these services use a wide range of IP ranges.
Step 10: Device Control (USB Protection)
- In the policy, go to Device Control
- Enable Device Control
- Default Device Type Rules:
- USB Storage: Blocked (recommended) or Read-Only
- CD/DVD: Blocked (most Indian offices no longer use optical media)
- Bluetooth: Allow but log
- Printers: Allow
For exceptions (IT staff who need USB access, specific authorised drives):
- Create a separate policy or add a Device Control exception with the specific device serial number
Step 11: Web Protection
- Enable Web Protection
- Configure Web Filtering categories to block:
- Adult/Mature content
- Gambling
- P2P/Torrent
- Anonymisers/Proxy bypass (important for Indian call centres)
- Malware hosting (always block)
- Allow with alert (log but permit):
- Social media (consider your business needs — block during work hours if productivity is a concern)
- Personal cloud storage (Dropbox personal, WeTransfer)
Scheduled web filtering (for school or BPO environments): Configure stricter categories 9am–6pm, relaxed policy after hours.
Step 12: Content Control (Application Access)
For businesses needing application-level control:
- Block specific applications by name (e.g., BitTorrent clients, game clients, screen recording apps)
- Block browser extensions by category (useful for preventing data exfiltration via browser extensions)
Phase 4: Agent Deployment
Step 13: Deploy Agents to Windows Endpoints
Method A: Remote Push (recommended for domain-joined machines)
- In Network Inventory, select all devices in a group
- Right-click > Install Protection
- Select your policy
- GravityZone pushes the agent silently via WMI/Remote Registry
Method B: Installation Package (for non-domain or remote devices)
- Go to Network > Packages
- Create a new package with your policy pre-assigned
- Download the
.exeinstaller - Distribute via email, Teams/Slack, or MDM (Intune/Jamf)
- Users install themselves — no admin rights needed if package is signed
Method C: Group Policy / Login Script (for phased rollout) Create a GPO that runs the GravityZone installer silently on all domain machines. Useful for deploying during off-hours to avoid business disruption.
Step 14: Verify Agent Health
After deployment (allow 30 minutes for agents to appear):
- Go to Network > Network Inventory
- Look for devices showing Managed status
- Devices showing Unmanaged failed deployment — investigate per device
- Check for Protected vs Unprotected status (protected = agent running, policy applied, AV up to date)
Common deployment issues in Indian environments:
- Windows Firewall blocking WMI: Ensure the GravityZone server's IP is allowed inbound on the Windows Firewall of target machines
- AV conflict: Older Kaspersky or McAfee installations must be uninstalled before Bitdefender deploys
- Group Policy conflict: Existing GPO antivirus exclusions can interfere — review and clean up
Phase 5: GravityZone Email Security Integration (If Applicable)
GravityZone Business Security Premium and higher include email security. If your organisation uses Microsoft 365 or Google Workspace:
Microsoft 365 Integration
- In GravityZone console, go to Email Security > Microsoft 365
- Authorise via Microsoft OAuth
- Configure inbound scanning policy: block malware, scan links, hold suspicious attachments for sandbox analysis
- Configure outbound scanning (optional — for compliance/DLP)
Google Workspace Integration
- Go to Email Security > Google Workspace
- Authorise via Google OAuth
- Configure inbound scanning with similar parameters
Phase 6: Dashboard and Reporting Setup
Step 15: Configure Your Dashboard
Customise the GravityZone dashboard for your operational needs:
- Add widget: Security Status (overall protection posture at a glance)
- Add widget: Malware Activity (detections over the last 30 days)
- Add widget: Update Status (endpoints with outdated definitions — flag for remediation)
- Add widget: Top Infected Machines (for incident response prioritisation)
Step 16: Schedule Compliance Reports
- Go to Reports > Add Report
- Create a monthly Security Audit Report — emailed to IT manager and CISO
- Create a monthly Device Status Report — all managed endpoints, protection status, last seen
For ISO 27001 or SOC 2 evidence collection, schedule a Malware Activity Report monthly and archive PDFs for the audit period.
Common Issues in Indian Deployments
Issue: Agent not updating definitions
Cause: Endpoint cannot reach update.bitdefender.com through the corporate proxy.
Fix: Add Bitdefender update servers to the proxy whitelist, or configure the GravityZone Communication Server as a local update relay.
Issue: Too many false positives in quarantine
Cause: Custom or locally-developed software being flagged. Fix: Add the software path or hash to the Antimalware Exclusions list in the policy. Do not globally exclude entire directories — exclude specific files/hashes.
Issue: High CPU during business hours
Cause: On-demand scan scheduled during work hours, or on-access scanning of large shared drives. Fix: Reschedule full scans to off-hours (Sunday 2am). Add shared drive paths to exclusions for on-access scanning (on-demand scan covers them on schedule).
Issue: Device control blocking legitimate hardware
Cause: Default "Block All USB Storage" policy blocking authorised peripherals. Fix: Add the specific device serial number to the Device Control exception list in the policy.
Post-Deployment Checklist
- All endpoints showing Protected status in GravityZone console
- Ransomware Mitigation enabled on all endpoint policies
- USB device control active
- Web filtering blocking test URL in blocked category
- Monthly security report scheduled and delivered to IT manager
- Alert notifications active for: new detections, offline agents, licence expiry
- AV definitions current (< 24 hours old) on all endpoints
- No devices in Unmanaged state (investigate any exceptions)
Cloudfy Systems is an authorised Bitdefender partner in India. We provide GravityZone licensing, deployment, policy configuration and ongoing managed endpoint support with INR pricing and GST invoice.
Contact us: +91 97600 50555 · connect@cloudfysystems.com
See also: Bitdefender GravityZone pricing for India
Frequently Asked Questions
How long does a 50-endpoint GravityZone deployment take?
With GravityZone Cloud, a 50-endpoint deployment using remote push (domain-joined machines) typically completes in 2–4 hours. Non-domain devices requiring manual installation packages take longer depending on user availability. Cloudfy handles the full deployment as part of our standard package.
Does GravityZone require a dedicated server?
GravityZone Cloud requires no on-premise infrastructure. The management console is hosted by Bitdefender. You only need a Communication Server relay if your endpoints cannot directly reach the Bitdefender cloud — relevant for secure or air-gapped environments.
Can GravityZone manage both office and remote/WFH endpoints?
Yes. GravityZone Cloud manages all endpoints regardless of location as long as they have Internet access. Remote endpoints receive policy updates and submit threat reports via the cloud console.
Is Bitdefender GravityZone compatible with Zoho, Tally and Indian business software?
Yes. GravityZone is compatible with all major Indian business applications. Initial deployment may require adding Tally.ERP or custom application paths to the exclusions list if they trigger false positives. Cloudfy configures these exclusions as part of deployment.
What happens when a GravityZone agent detects ransomware?
With Ransomware Mitigation enabled: the agent detects the encryption pattern, halts the ransomware process, and if Automatic Restore is enabled, rolls back the affected files from the pre-attack shadow copies. The incident is logged in the console and an alert email is sent to the IT team.
