What are the essential features of Trend Micro Endpoint Encryption Full Disk Encryption and File Encryption Corporate?
Central management – Policies managed on-premises through PolicyServer and Control Manager.
Pre-boot authentication – Blocks Windows startup until the user is verified.
Disk encryption – Encrypts operating system, swap, temporary and user files.
Removable media – Encrypts files, folders, USB drives and optical media.
Self-encrypting drives – Supports Seagate DriveTrust, OPAL and OPAL2 hardware encryption.
Important note – Discontinued product: vendor support ended on 30 June 2024.
Full Disk Encryption agent – Encrypts the entire Windows drive, including system, swap and temporary files.
Pre-boot authentication – Requires user verification before the operating system is allowed to load.
File Encryption agent – Encrypts individual files, folders, USB drives and other removable media.
XTS-AES encryption – FIPS-compliant algorithm with a choice of 128-bit or 256-bit keys.
PolicyServer management – On-premises server for policies, users, devices, keys and audit data.
Important – Vendor end of life since 30 June 2024: no patches or support.
Trend Micro Endpoint Encryption Full Disk Encryption and File Encryption Corporate is a legacy bundle of two Windows encryption agents, managed on-premises through PolicyServer with optional Trend Micro Control Manager integration; Trend Micro has run its enterprise business under the name TrendAI since March 2026. The vendor removed both agents from new sales on 1 April 2023, previously sold them as Endpoint Encryption Bundle, and now uses the name Trend Micro Endpoint Encryption for a product that only manages Microsoft BitLocker and Apple FileVault.
Lost laptop protection – A stolen drive stays unreadable without passing pre-boot authentication.
Remote lock and wipe – Administrators can lock or wipe a device before Windows starts.
Policy check at login – The agent fetches current policies before allowing user authentication.
Hardware or software – Uses self-encrypting drives where present, software encryption on older disks.
Audit data upload – Connected agents send audit records to PolicyServer for later review.
Internet-capable communication – Encrypted client traffic allows a proxy in the DMZ for remote devices.
Because PolicyServer is an on-premises component administered through the Microsoft Management Console, this bundle always required an organisation able to run its own Windows server infrastructure. Since vendor support ended on 30 June 2024, it no longer suits new deployments in companies of any size. Its only remaining role is to keep existing installations working while they are moved to a supported encryption solution.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Possible | Frequent | Frequent |
| Vendor-supported encryption with central recovery | ✓ | ✓ | ✓ |
| This product fits | Migration only | Migration only | Migration only |
Under the revised Information Security Act, operators of critical infrastructure in Switzerland, such as energy suppliers, hospitals and public authorities, must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery; most other companies are not directly subject to this obligation. The bundle can support a related task: when a notebook is lost or stolen, full disk encryption with pre-boot authentication and the audit data in PolicyServer help document that the stored data was protected. It does not detect cyberattacks, collect incident evidence or support the 24-hour report itself. Because the vendor has supplied no patches since 30 June 2024, an operator would also have to justify the use of unsupported security software in its own risk assessment. This information does not constitute legal advice; whether and how the reporting obligation applies to your organisation should be clarified with a qualified specialist.
No software product makes an organisation compliant with the NIS 2 Directive, which requires essential and important entities to implement risk management measures including access control, policies on cryptography and encryption, vulnerability handling, incident handling, business continuity with backup management, and supply chain security. Full disk and file encryption with pre-boot authentication maps directly to the cryptography and access control measures. The same product works against the vulnerability handling and supply chain categories, because it has received no vendor updates since its end of life on 30 June 2024. It provides nothing for incident handling, backup and recovery or malware protection, so these measures must be covered by other tools and processes.
Only partly, and only for installations that already exist. The bundle can support answers to questions about whether notebooks are fully encrypted, whether removable media are encrypted, whether users must authenticate before the operating system starts and whether encryption policies are administered centrally. Where a questionnaire asks whether the security software in use is still supported and patched by its vendor, the accurate answer for this bundle has been no since 30 June 2024. It also answers none of the questions on malware protection, endpoint detection and response, patch management, backups, multi-factor authentication or incident response. Within the same product family, the closest route for the encryption items is the current Trend Micro Endpoint Encryption with Microsoft BitLocker management, which keeps central administration through PolicyServer; the vendor's free migration offer from Full Disk Encryption was tied to the end-of-life date, so current conditions should be confirmed with TrendAI before planning. The remaining gaps require separate endpoint protection, backup and authentication products.
The decisive difference is vendor support: the Full Disk Encryption and File Encryption agents reached end of life on 30 June 2024, while the vendor continues to support Microsoft BitLocker and Apple FileVault management. The current Trend Micro Endpoint Encryption no longer brings its own disk encryption agent and instead centrally manages the encryption built into the operating system. File, folder and removable media encryption is no longer part of the product. Apple FileVault management does not support macOS 12 or later, so Macs on current macOS versions cannot be managed with it.
| Feature | Full Disk and File Encryption bundle | Trend Micro Endpoint Encryption |
|---|---|---|
| Vendor support | Ended June 2024 | ✓ |
| Sold new by the vendor | ✕ | ✓ |
| Own disk encryption agent | ✓ | ✕ |
| File, folder and removable media encryption | ✓ | ✕ |
| Updates for new Windows versions | ✕ | ✓ |
The most important limitation is the product lifecycle: Full Disk Encryption and File Encryption reached end of life on 30 June 2024, so there are no patches, no compatibility updates for new Windows releases and no technical support. According to the vendor, the agent installers are no longer offered on the download page, and customers who bought before 1 April 2023 were referred to technical support to obtain them. The Full Disk Encryption agent cannot be installed while Microsoft BitLocker is active or another disk encryption product is present, which has to be planned for when migrating in either direction. Before File Encryption is removed, the vendor instructs that all encrypted files be decrypted first. No region-specific feature restrictions were identified in the vendor documentation.
The vendor documented a migration from Full Disk Encryption to Encryption Management for Microsoft BitLocker and offered it at no cost before the end-of-life date of 30 June 2024. Whether and on what terms this path is still available today should be confirmed directly with TrendAI before any rollout is planned.
Legacy Trend Micro bundle for Windows disk and file encryption with pre-boot authentication. Vendor support ended June 2024. For existing setups.
Trend Micro Endpoint Encryption Full Disk Encryption and File Encryption Corporate, Trend Micro, TrendAI, Trend Micro Endpoint Encryption, Endpoint Encryption Bundle, full disk encryption, file encryption, pre-boot authentication, PolicyServer
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies