LUCIDTextjet - Print logo

Trend Micro Apex One On-Prem

Short Description

Open HTML

What are the core benefits of Trend Micro Apex One On-Prem?
Central console – Managed from a web console on your own server.
Ransomware defence – Blocks encryption processes and restores affected files automatically.
Behaviour monitoring – Detects unusual changes to the operating system and software.
Web reputation – Blocks malicious websites inside and outside the company network.
Host firewall – Filters connections by application, IP address, port or protocol.
Important note – EDR, virtual patching and DLP require separate licences.

Long Description

Open HTML

What is included in Trend Micro Apex One On-Prem?

On-premises web console – Apex One server manages policies, updates and reports on your hardware.
Anti-malware with smart scan – Offloads signature lookups to Smart Protection Sources, reducing endpoint load.
Ransomware protection – Blocks typical ransomware processes and backs up files being encrypted.
Behaviour monitoring – Flags unusual changes to the operating system and installed software.
Firewall and Web Reputation – Stateful firewall rules plus blocking of malicious and dangerous websites.
Important – EDR, application control, virtual patching and DLP are separately licensed modules.

What are the main benefits of Trend Micro Apex One On-Prem?

Trend Micro Apex One On-Prem is the successor to OfficeScan and protects Windows clients and Windows servers with a single Security Agent; since March 2026, Trend Micro's enterprise business has operated under the name TrendAI. It is managed centrally from a web console that runs on your own server, so the console, policies and detection logs stay on infrastructure you control.

Group-based policies – Set and lock security settings for single desktops or entire groups.
Location-aware device rules – Applies stricter USB storage rules when notebooks leave the company network.
Outbreak prevention – Closes infection paths before a matching pattern file is available.
Automatic damage cleanup – Kills Trojan processes, repairs system files and deletes dropped files.
Modular upgrade path – Adds EDR, application control or virtual patching through Apex Central.
SIEM log export – Forwards security logs in CEF format to your syslog receiver.

Best antivirus? Why Windows Defender alone is not enough
Where the protection built into Windows reaches its limits against targeted attacks and ransomware.

Which company size is Trend Micro Apex One On-Prem suitable for?

Apex One On-Prem suits organisations that already operate Windows servers and have staff who maintain them, because installing, updating and securing the console and its SQL Server database is your responsibility. Medium-sized and large companies that want management data kept in-house, or whose networks have restricted internet access, gain the most from this model. A small business without IT staff will usually find the effort of running and patching its own console greater than the benefit.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland By sector By sector By sector
NIS 2 in the European Union Rarely By sector By sector
Security questionnaire from large customers Possible Common Common
Staff to run and patch an on-premises console ✕ Usually ✓
This product fits Limited ✓ ✓

Does Trend Micro Apex One On-Prem meet the requirements of Swiss cybersecurity legislation?

Since 1 April 2025, the revised Information Security Act has required operators of critical infrastructure in Switzerland, such as energy suppliers, hospitals, transport companies and public authorities, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Apex One On-Prem supports this obligation by detecting malware and ransomware activity on Windows endpoints, storing the detection logs centrally and sending event notifications, which gives you the first facts for a report. Together with Apex Central, these logs can be forwarded to a SIEM, so the time of detection is documented outside the endpoint. The product does not submit reports, does not provide an incident response process and, without the separately licensed Endpoint Sensor, cannot reconstruct how an attacker gained access. This information does not constitute legal advice; clarify your specific obligations with a qualified specialist.

Does Trend Micro Apex One On-Prem meet the requirements of European cybersecurity legislation?

No software product makes a company compliant with the NIS 2 Directive, because the directive requires risk management measures that management must organise and oversee. These measures include incident handling, business continuity with backup management, supply chain security, vulnerability handling, cryptography and encryption, access control and multi-factor authentication. Apex One On-Prem contributes to incident handling through central detection logs and outbreak prevention, and to basic data protection through USB storage control. Vulnerability handling is only covered with the separately licensed Vulnerability Protection module, and the product offers no patch management, encryption, backup or multi-factor authentication. NIS 2 also requires an early warning for significant incidents within 24 hours; the product supplies the detection data but not the reporting workflow.

Does Trend Micro Apex One On-Prem help with security questionnaires from large customers?

Yes, for the endpoint section of a typical questionnaire, but not for the whole document. With Apex One On-Prem you can confirm centrally managed malware protection, ransomware protection, a host firewall, blocking of malicious websites, USB storage control and centrally stored detection logs with reports. You cannot confirm endpoint detection and response, application allow-listing, patch or vulnerability management, disk encryption, backup, multi-factor authentication, or protection of Linux servers and mobile devices with this product alone. The most economical way to close the EDR, allow-listing and virtual patching gaps is usually the matching Apex One modules managed through Apex Central, because they run in the same Security Agent; encryption, backup and multi-factor authentication require separate products in any case.

Which limitations should you know before buying?

You operate the console yourself, including the patches Trend Micro releases twice a year; in August 2025 the vendor fixed two actively exploited vulnerabilities in the on-premises management console, while the cloud variant was protected centrally, and it advises restricting network access to the console. The Security Agent protects Windows clients and Windows servers, Mac endpoints need the separate Apex One (Mac) plug-in with its own activation code, and Linux servers and mobile devices are not covered. The ransomware file backup only saves files smaller than 10 MB and does not replace a real backup. The most common follow-up purchases are Endpoint Sensor for EDR, Application Control and Vulnerability Protection, which all require Apex Central, and the Data Protection module for DLP and extended device control.

Data loss is expensive: How backups help you avoid outages
Why a working backup strategy decides how long a business stays offline after data loss.

Frequently asked questions about Trend Micro Apex One On-Prem

Is Apex One On-Prem still sold now that Apex One as a Service has reached end of sale?

Yes. As of September 2026, TrendAI's product lifecycle list shows the on-premises Apex One as a supported product without an end-of-sale date, whereas Apex One as a Service reached end of sale on 31 December 2025 and reaches end of life on 31 December 2027.

What is the cloud-managed counterpart to Apex One On-Prem?

TrendAI's cloud-managed endpoint protection is TrendAI Vision One Endpoint Security – Standard Endpoint Protection, which the vendor lists together with Apex One in its Windows support matrix. It suits organisations that do not want to operate and patch their own management server.

 

Meta Description

Endpoint protection for Windows clients and servers, managed from your own on-premises console. Successor to OfficeScan, for in-house IT teams.

Keywords

Trend Micro Apex One On-Prem, Trend Micro, TrendAI, Apex One, OfficeScan, endpoint protection, on-premises management console, ransomware protection, behaviour monitoring, device control

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree