<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Trend Micro Apex One On-Prem?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>On-premises web console</strong> – Apex One server manages policies, updates and reports on your hardware.<br /><strong>Anti-malware with smart scan</strong> – Offloads signature lookups to Smart Protection Sources, reducing endpoint load.<br /><strong>Ransomware protection</strong> – Blocks typical ransomware processes and backs up files being encrypted.<br /><strong>Behaviour monitoring</strong> – Flags unusual changes to the operating system and installed software.<br /><strong>Firewall and Web Reputation</strong> – Stateful firewall rules plus blocking of malicious and dangerous websites.<br /><strong>Important</strong> – EDR, application control, virtual patching and DLP are separately licensed modules.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Trend Micro Apex One On-Prem?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Trend Micro Apex One On-Prem is the successor to OfficeScan and protects Windows clients and Windows servers with a single Security Agent; since March 2026, Trend Micro's enterprise business has operated under the name TrendAI. It is managed centrally from a web console that runs on your own server, so the console, policies and detection logs stay on infrastructure you control.<br /><br /><strong>Group-based policies</strong> – Set and lock security settings for single desktops or entire groups.<br /><strong>Location-aware device rules</strong> – Applies stricter USB storage rules when notebooks leave the company network.<br /><strong>Outbreak prevention</strong> – Closes infection paths before a matching pattern file is available.<br /><strong>Automatic damage cleanup</strong> – Kills Trojan processes, repairs system files and deletes dropped files.<br /><strong>Modular upgrade path</strong> – Adds EDR, application control or virtual patching through Apex Central.<br /><strong>SIEM log export</strong> – Forwards security logs in CEF format to your syslog receiver.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Where the protection built into Windows reaches its limits against targeted attacks and ransomware.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Trend Micro Apex One On-Prem suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Apex One On-Prem suits organisations that already operate Windows servers and have staff who maintain them, because installing, updating and securing the console and its SQL Server database is your responsibility. Medium-sized and large companies that want management data kept in-house, or whose networks have restricted internet access, gain the most from this model. A small business without IT staff will usually find the effort of running and patching its own console greater than the benefit.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<thead>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
</thead>
<tbody>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Possible</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Common</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Common</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Staff to run and patch an on-premises console</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Trend Micro Apex One On-Prem meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Since 1 April 2025, the revised Information Security Act has required operators of critical infrastructure in Switzerland, such as energy suppliers, hospitals, transport companies and public authorities, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Apex One On-Prem supports this obligation by detecting malware and ransomware activity on Windows endpoints, storing the detection logs centrally and sending event notifications, which gives you the first facts for a report. Together with Apex Central, these logs can be forwarded to a SIEM, so the time of detection is documented outside the endpoint. The product does not submit reports, does not provide an incident response process and, without the separately licensed Endpoint Sensor, cannot reconstruct how an attacker gained access. This information does not constitute legal advice; clarify your specific obligations with a qualified specialist.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Trend Micro Apex One On-Prem meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes a company compliant with the NIS 2 Directive, because the directive requires risk management measures that management must organise and oversee. These measures include incident handling, business continuity with backup management, supply chain security, vulnerability handling, cryptography and encryption, access control and multi-factor authentication. Apex One On-Prem contributes to incident handling through central detection logs and outbreak prevention, and to basic data protection through USB storage control. Vulnerability handling is only covered with the separately licensed Vulnerability Protection module, and the product offers no patch management, encryption, backup or multi-factor authentication. NIS 2 also requires an early warning for significant incidents within 24 hours; the product supplies the detection data but not the reporting workflow.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Trend Micro Apex One On-Prem help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for the endpoint section of a typical questionnaire, but not for the whole document. With Apex One On-Prem you can confirm centrally managed malware protection, ransomware protection, a host firewall, blocking of malicious websites, USB storage control and centrally stored detection logs with reports. You cannot confirm endpoint detection and response, application allow-listing, patch or vulnerability management, disk encryption, backup, multi-factor authentication, or protection of Linux servers and mobile devices with this product alone. The most economical way to close the EDR, allow-listing and virtual patching gaps is usually the matching Apex One modules managed through Apex Central, because they run in the same Security Agent; encryption, backup and multi-factor authentication require separate products in any case.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">You operate the console yourself, including the patches Trend Micro releases twice a year; in August 2025 the vendor fixed two actively exploited vulnerabilities in the on-premises management console, while the cloud variant was protected centrally, and it advises restricting network access to the console. The Security Agent protects Windows clients and Windows servers, Mac endpoints need the separate Apex One (Mac) plug-in with its own activation code, and Linux servers and mobile devices are not covered. The ransomware file backup only saves files smaller than 10 MB and does not replace a real backup. The most common follow-up purchases are Endpoint Sensor for EDR, Application Control and Vulnerability Protection, which all require Apex Central, and the Data Protection module for DLP and extended device control.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Why a working backup strategy decides how long a business stays offline after data loss.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Trend Micro Apex One On-Prem</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is Apex One On-Prem still sold now that Apex One as a Service has reached end of sale?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. As of September 2026, TrendAI's product lifecycle list shows the on-premises Apex One as a supported product without an end-of-sale date, whereas Apex One as a Service reached end of sale on 31 December 2025 and reaches end of life on 31 December 2027.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the cloud-managed counterpart to Apex One On-Prem?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">TrendAI's cloud-managed endpoint protection is TrendAI Vision One Endpoint Security – Standard Endpoint Protection, which the vendor lists together with Apex One in its Windows support matrix. It suits organisations that do not want to operate and patch their own management server.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-endpoint,sec-console,compliance-supplier" data-audience="b2b" data-count="3"> </div>