Appearance
Bitdefender GravityZone Setup
Connect Bitdefender GravityZone to let Junto inspect endpoint protection, investigate incidents, review quarantined files, and check policies and monthly license usage. The agent can also request endpoint scans and isolate or reconnect devices with approval.
Junto supports one GravityZone configuration per organization. Connect your partner account once, then map GravityZone companies to Junto companies so the agent can retrieve each customer's data.
Prerequisites
- A Junto Admin or Owner account
- A GravityZone partner administrator account with access to the customer companies you want to connect
- A GravityZone API key with the services needed for your workflows enabled
- Your regional GravityZone Access URL
- Customer companies in Junto, imported from your PSA, to map to GravityZone
Step 1: Create a GravityZone API Key
Sign in to GravityZone Control Center and open My Account from the user menu.
Under API keys, click Add and enter a description such as
Junto.Enable the API services Junto uses:
API service Used for Network Company discovery, endpoint information, scans, and scan task history Incidents Incident investigation, blocklist lookups, and endpoint isolation or restoration Quarantine Quarantined files on computers and virtual machines Policies Policies available to a customer company Licensing Monthly Endpoint Security license usage Click Generate and copy the key before closing the window. Store it securely; GravityZone does not show it again.
On My Account, find Control Center API and copy the Access URL for your instance.
For account permission requirements and key creation details, see Bitdefender's Public API guide.
Step 2: Configure in Junto
Go to Settings > Integrations > Bitdefender GravityZone.
Click Add configuration.
Complete the form:
Field What to enter Access URL The regional HTTPS URL copied from GravityZone, such as https://cloud.gravityzone.bitdefender.com/apiAPI key The key from Step 1, preserving its capitalization Active Leave enabled to make the integration available Click Create configuration, then Done after the save succeeds. Junto encrypts the API key when stored.
Click Test connection on the configuration card and confirm Connection verified appears.
Use your instance's Access URL, including /api. Do not append a service path such as /v1.0/jsonrpc/network. Saving the configuration does not test the credentials; run Test connection separately. A successful test confirms access to API key details, but individual features still depend on the key's enabled services and account permissions.
Step 3: Map Companies
- Click Manage company mappings on the active configuration.
- For each Junto company, select its GravityZone company.
- Click Save mappings.
You can also click Auto-map companies. Exact name matches are applied automatically; similar names are presented for review. Save any manual selections before running auto-map.
Each Junto company can map to one GravityZone company, and each GravityZone company can be selected only once. To remove a mapping, select Not mapped and save. An unmapped customer cannot use the customer-specific Bitdefender tools.
If a saved selection is marked unavailable, check the API key's company access and select a current GravityZone company. If the list is empty, confirm that the partner account can see the intended customers and that the Network API is enabled.
What the Agent Can Do
| Capability | What Junto can do | Risk level |
|---|---|---|
| Endpoint information | Find managed endpoints by name or FQDN; inspect protection, OS, agent details, assigned policy, last successful scan, and isolation state | Low |
| Incident investigation | List incidents by last-update date range, status, or priority and retrieve details for a specific incident | Low |
| Blocklist | Read a customer's blocked items | Low |
| Quarantine | Inspect quarantined computer and virtual-machine files for a company or a specific endpoint | Low |
| Policies | List policies available to a company, including policies shared by a parent company | Low |
| License usage | Read monthly Endpoint Security usage for a specified billing month | Low |
| Scan task history | List scan tasks visible to the API key from an organization-wide Explore chat | Low |
| Scan endpoint | Request a quick, full disk, or memory scan on one endpoint | Medium |
| Endpoint isolation | Isolate one endpoint from the network or restore its network connectivity | High |
Read tools do not require approval by default. Scans always require approval. Isolation and restoration require internal approval because they change the endpoint's network access.
Scope and Reporting
- Customer context: All tools except scan task history operate on one mapped customer at a time. Scan task history is available only in an organization-wide chat because GravityZone does not provide the company ownership needed to filter it safely. For a customer-specific scan check, ask for the endpoint's last successful scan.
- Incidents: Date filters use the incident's last update, not its creation date. Results cover the mapped company and exclude its child companies. Incident access also depends on the customer's GravityZone license.
- Result limits: Lists may return a limited selection of records. Ask for a narrower search or more results when needed, and use GravityZone when you need an exhaustive review.
- Policies: An available policy may belong to a parent company. Check endpoint details to confirm which policy is assigned to a particular device.
- License usage: Specify a billing month, such as
09/2026. Results cover monthly Endpoint Security usage, not allocated seats or invoices. A company without a monthly license is reported as such; that does not mean it has zero protected endpoints. Standalone EDR and PHASR usage are outside this lookup. - Read-only areas: The integration can inspect blocklists, quarantine, and policies. It does not modify blocklist entries, restore or delete quarantined files, or change policy assignments. Quarantine lookups do not include Exchange quarantine.
Scans and Isolation
An accepted action returns queued task IDs, not a completed result. After a scan, check endpoint details for its last successful scan. After isolation or restoration, ask Junto to check the endpoint's isolation state.
If an action times out or its outcome is unclear, check GravityZone before requesting it again. If the connection, company mapping, or endpoint isolation state changes after approval, refresh the endpoint information and request fresh approval.
Example requests:
- "Check the Bitdefender protection status of Acme's endpoints."
- "Show Acme's high-priority GravityZone incidents updated in the last seven days."
- "Review quarantined files on Acme's laptop ACME-042."
- "Check Acme's monthly Endpoint Security usage for September 2026."
- "Request a quick scan of ACME-042, then check whether it completed."
- "Request network isolation for ACME-042 and verify its isolation state."
Managing the Connection
- Update credentials: Click Edit, enter the replacement key, and click Save changes. Leave API key blank to keep the stored key. Test the connection after updating it.
- Change accounts or regions: Update the key and Access URL, test the connection, and review every company mapping against the new account's company list.
- Pause the integration: Click Edit, turn off Active, and save. The configuration and mappings remain saved.
- Remove the integration: Click Delete configuration, then Delete permanently. This removes the stored API key and all Bitdefender company mappings from Junto.
Troubleshooting
- Connection fails: Recheck the regional Access URL and API key. Keys are case-sensitive. Confirm the key has not been deleted and the account still has the required access.
- Save fails: Use an HTTPS Access URL ending in
/api, without a query string or fragment. Re-enter the API key before retrying; Junto clears that field after a save attempt. - Connection passes, but a feature fails: Check that feature's API service is enabled and the account has the necessary permissions and GravityZone entitlement. An unavailable feature is not evidence that the customer has no threats.
- Company or endpoint missing: Confirm the configuration is active, the mapping is saved, and the API key can access the mapped company. Endpoint inventory includes managed endpoints.
- Mapping cannot be saved: Check that each GravityZone company is selected only once. If companies are no longer available, close and reopen the mapping dialog to refresh the list.
- Scan task history unavailable in a customer chat: Use an organization-wide Explore chat, or inspect the customer's endpoint details for its last successful scan.
- Scan or isolation still pending: Check task progress in GravityZone and reread endpoint details or isolation state before treating the action as complete.