It serves as a comprehensive solution for antivirus scanning across all endpoints. It facilitates the deployment of the application portal within the access center, ensuring device control for vulnerability protection which enables the implementation of device-blocking measures to enhance security.
Technical Manager at a tech services company with 1,001-5,000 employees
Robust and scalable endpoint security with efficient threat detection, rapid deployment and user-friendly administration
Pros and Cons
- "The graphical user interface is simple, making it easy to navigate without the need for additional training or complex documentation."
- "There is room for improvement in the reporting aspect"
What is our primary use case?
How has it helped my organization?
It safeguards endpoints by detecting threats like malware or malicious scripts, employing features such as behavior monitoring and machine learning. This includes detecting zero-day attacks and analyzing application behaviors for enhanced security. It delivers excellent products for effectively safeguarding endpoints, utilizing advanced features that enhance protection and mitigate various threats. It is equipped with advanced ransomware detection capabilities through real-time machine learning.
This detection is not solely reliant on signatures; instead, it incorporates built-in features for proactive identification of ransomware threats, offering an advanced and pre-emptive approach to detection. A single console facilitates cross-layer detection, and access to the central console is necessary for on-premises solutions. In the SaaS-based model, the EDR console serves as the unified interface.
This single console allows for threat hunting, investigations, incident management, playbook creation, and incident response. It is essential as it provides end-to-end visibility into the entire IT security environment, especially in EDR. However, challenges may arise when dealing with endpoints that contain files lacking signatures or behavior detection capabilities. To address this, a sandboxing solution becomes crucial to analyze and understand the behavior of such files.
It offers the capability to swiftly deploy updates to endpoints, allowing for the immediate deployment of patches or signature files in response to incidents or attacks. In scenarios with no existing signatures, the support team from the OEM can provide the necessary signatures, and these can be promptly pushed to the Apex One Center.
Timely updates are crucial for us as they help us maintain security.
Since transitioning to Apex One, we have observed a notable decrease in viruses and malware.
Our product now detects threats much faster, leading people to express confidence in the effectiveness of our custom machine-learning capabilities, evident in the significant reduction in detection times. Utilizing an independent cloud has significantly reduced the workload for our staff by eliminating the need to manage hardware, operating systems, and applications.
Daily tasks such as console endpoint restarts, application protection, and agent communications compliance become more straightforward. The ease of managing these aspects is a notable advantage.
Moreover, the SaaS solution proves particularly beneficial when customers are unable to provide on-premises infrastructure for applications. Users can effortlessly log in, deploy agents, and manage tasks without the complexities associated with on-premises solutions, which depend on factors like hardware, databases, operating systems, networks, proxies, and other variables.
What is most valuable?
The standout and highly valuable feature of Apex One is its XDR capability.
Featuring advanced protection capabilities that dynamically adapt to defend against evolving and emerging threats, Apex One stands out. Detecting ransomware and utilizing machine learning capabilities are crucial features, especially for safeguarding customer environments.
It stands out as a pioneer in incorporating these features within its antivirus solution. Trend Micro was the first to integrate behavior-based analysis, signatures, and reputation-based detection to enhance protection against ransomware and other threats.
The learning curve for Apex One is minimal, as it is a straightforward and user-friendly product. The graphical user interface is simple, making it easy to navigate without the need for additional training or complex documentation.
The terminology and features are presented in a common and basic language, ensuring that anyone can comprehend and work with the product easily.
Administering it is also a straightforward process. It offers virtual patching capabilities to safeguard against significant vulnerabilities. This involves an active signature-based approach to virtual patching.
The added value that managed XDR brings to our Apex One deployment is significant.
What needs improvement?
There is room for improvement in the reporting aspect. Custom-level reporting is crucial for in-depth analysis and its significance is evident in the effectiveness of managing and prospecting products.
Buyer's Guide
TrendAI Vision One – Endpoint Security
September 2026
Learn what your peers think about TrendAI Vision One – Endpoint Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,197 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with it for fifteen years.
What do I think about the stability of the solution?
In terms of stability, Apex has proven to be a reliable product with no reported downtime requirements. In my experience, I haven't encountered any significant challenges. The only instances of the console being down were typically related to database issues, such as log saturation or routine database maintenance.
What do I think about the scalability of the solution?
It's a scalable solution with good performance.
How are customer service and support?
The support has been challenging, particularly when utilizing bots during customer calls, as it often results in ineffective solutions. The primary issue revolves around prolonged resolution times. Even with ongoing follow-ups, cases remain unresolved within the anticipated timeline. The consistent request for logs implies that multiple submissions may be necessary for a potential solution or resolution. Enhancements in specific areas are required to improve the overall support process. I would rate it seven out of ten.
How was the initial setup?
Deploying the on-premises solution is a seamless process, especially when dealing with the application components. Apex One or Apex Central is the management console, with Apex One managing antivirus consoles, groups, and parts. Policies can be efficiently pushed through Apex Central. The agent itself is equipped with XDR capabilities for on-premises solutions. Conversely, an additional service installation on endpoints is necessary for cloud-based implementations. The deployment process is relatively quick, typically taking around half an hour
What's my experience with pricing, setup cost, and licensing?
Opting for cloud solutions can provide a more cost-effective and efficient alternative, with fewer dependencies on physical setups and unexpected costs associated with on-premises tasks.
What other advice do I have?
Integration capabilities exist for Trend Micro with its own suite of security products, allowing seamless collaboration. However, integration with Apex One may not be supported regarding other security products from different vendors or OEMs, such as Central One, CrowdStrike, or Palo Alto. Overall, I rate it nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Product Manager at a tech services company with 11-50 employees
Integrates well with other security products but has limited intelligence
Pros and Cons
- "Its database is better than most of the endpoint protection solutions."
- "It is weak in terms of intelligence. By implementing Trend Micro Apex One, I wanted to see real-life scenarios. I deployed it on 50 clients to check if I could do lateral moments and zero-day exploits. I wanted to check how the zero-day protection works with Trend Micro. It fails with most of them because it is signature-based. They are not looking at the MITRE ATT&CK framework, so with zero-day attacks, it mostly fails."
What is our primary use case?
I create real-life scenarios with products and work with products such as Trend Micro, CrowdStrike, SentinelOne, Palo Alto, etc. Trend Micro is not my focus item or brand. My focus is more on CrowdStrike, but I am using Trend Micro in my lab environments to check the real-life situation. I am not okay with what vendors share on their websites, so I give my customers and partners real-life scenarios.
How has it helped my organization?
I offer Trend Micro Apex One to our customers just because they want a secondary signature-based solution.
Apex One did not work as per my expectations. I am doing zero-day attacks by myself, and for fileless attacks, it does not work at all.
With the current architecture, Apex One does not have advanced protection capabilities that adapt to protect against unknown and stealthy new threats. It might have these capabilities in the future if they change the architecture. For instance, McAfee merged with FireEye and created a new brand Trellix. They changed the overall architecture. If Trend Micro considers shifting its architecture, it can get this kind of protection.
Apex One is okay for detecting ransomware with runtime machine-learning capabilities. It has some signature-based protection against ransomware, but it may miss the ransomware, which has been a huge threat at least for the last seven or eight years. It is the foundation of zero-day protection, and that is why I am looking for a more capable solution besides Trend Micro.
Apex One integrates with other security products. As part of this integration, when a threat is detected in the network sandbox, it deploys rapid updates to endpoints, which has huge importance because if you can respond to events in a short time, you get the least damage from attacks. It is of huge importance.
Apex One provides us with virtual patching to protect against vulnerabilities even before a patch is available for the source of the issue, but it is a problem in itself because it consumes too many resources on an endpoint. It is a good feature, but it is a problematic feature because it consumes lots of the system resources. If you use signature-less architecture, you do not have to deal with virtual patching because all attack types are already addressed with some framework, such as the MITRE ATT&CK framework. You do not have to deal with virtual patching at all.
There has been no reduction in viruses and malware since moving to Apex One because my customers are using it as a secondary solution. They have primary products, and there are not many things left for Apex One. My customers are using it as a secondary solution just because of their habits of using signature-based. Some of my customers could not understand the concept of signature-less protection. Antiviruses have been there for 40 years or so, and their habits are a little bit hard to change. That is the reason why I am offering this product.
What is most valuable?
I offer this solution only if a customer is looking for a signature-based protection solution. Its database is better than most of the endpoint protection solutions.
What needs improvement?
It is weak in terms of intelligence. By implementing Trend Micro Apex One, I wanted to see real-life scenarios. I deployed it on 50 clients to check if I could do lateral moments and zero-day exploits. I wanted to check how the zero-day protection works with Trend Micro. It fails with most of them because it is signature-based. They are not looking at the MITRE ATT&CK framework, so with zero-day attacks, it mostly fails. Instead of signature-based, Trend Micro may want to change the architecture to use more behavior analysis. Behavior analysis is included with Trend Micro, but it is not a complete set, so it needs enhancement.
Apex One does not provide a single console for cross-layer detection, threat hunting, and investigation. Managing it is a little bit hard. You have to use different consoles for Apex One, Deep Security, and Trend Micro endpoint protection, so managing it is a little bit tricky.
In terms of the learning curve, Apex One is easy for me, but regular users may have some issues. The management of Trend Micro products is a little bit tricky. Apex One does not include every protection in itself, so you have to use endpoint protection, and you have to use Deep Security. If three of them come together, at some point, it will be competitive with next-generation antiviruses or EPPs such as SentinelOne, Microsoft, CrowdStrike, etc.
Its implementation takes too much time. With CrowdStrike, I do not have to restart any operating system, but with Trend Micro, I have to.
Its administration is also a little bit tricky. It is easier when you have background knowledge.
For how long have I used the solution?
I have been using this product for a year.
What do I think about the stability of the solution?
Its stability is quite good. I cannot complain about the stability.
It sometimes also depends on luck. The product can sometimes conflict with other products, but to this day, I never encountered any issue like that.
What do I think about the scalability of the solution?
It is a little bit hard to scale as compared to CrowdStrike. I am using on-prem solutions most of the time. With on-prem solutions, it is a little bit hard to maintain, deploy, or scale a product, but cloud products are easier to scale.
I have a centralized customer, and I also have customers who have distributed locations all over Turkey, so I have both types of customers.
How are customer service and support?
It takes a little bit of time, and it can be improved. Sometimes, I get a response in two days, and at other times, I get a response in two hours. It depends. More consistency would be great, but I have already gotten used to this kind of issue, so I cannot complain at all. I would rate them a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I am using other server protections and intelligence products. I still have CrowdStrike in my portfolio. I have clients for that, and I am okay with CrowdStrike.
How was the initial setup?
Its deployment takes time. If I have to deploy it in a huge company with over 10,000 clients, it takes a little bit of time. If I am using CrowdStrike, it would take only two or three days, whereas Trend Micro takes more time. I have not measured the exact time difference, but it takes more time compared to other solutions or the next-gen antiviruses. It also depends on the environment because organizational units are not available all the time.
I deployed it on the cloud and on-premises. It depends on the end-user scenarios and topology. In Turkey, customers mostly prefer on-prem solutions, but this is changing day by day. Customers in Turkey tend to have their information on-premises. If a customer wants an on-prem solution, then I offer them the Trend Micro product or Trellix product. It also depends on their budget.
Its deployment is not too complex in my experience, but from the customer perspective, it is a little bit tricky. It takes a little bit of time. They have to have a little bit of background knowledge.
The implementation strategy varies. Sometimes, I use third-party solutions, and sometimes, I am just pushing from the central management console. It depends on the customer's topology.
In terms of maintenance, it does require maintenance. It depends on the company budget because some of my customers have a few locations in Turkey, and sometimes, they have only one IT specialist. They send that one person everywhere in Turkey or to multiple locations. If they have more than one IT guy and if they are also distributed, they do not have to send those guys to other places. It depends on the customer's budget.
What about the implementation team?
If I deploy the product, then one person is enough, but if I have to leave it to my customers, they need two or three people. They are usually IT specialists, but they are not so knowledgeable.
What was our ROI?
It takes time, but it is better than some of the other products such as Symantec. Symantec takes more time compared to Trend Micro.
What's my experience with pricing, setup cost, and licensing?
It is okay. Compared to Sophos, it is a little bit expensive, but it is a good product and it is better than Sophos, for instance. It is equivalent to Trellix.
Its cost depends on the country. I am in Turkey, and Trend Micro is not so affordable in Turkey. SMB companies are looking for cheaper products. In Turkey, enterprise customers tend to use Trend Micro, and if they have more money, then they use next-generation antivirus or EPP products such as SentinelOne, CrowdStrike, or Microsoft E5 package.
Which other solutions did I evaluate?
I evaluate most of the popular brands such as Trellix, Sophos, and Kaspersky.
What other advice do I have?
Trend Micro Apex One has some good benefits, and CrowdStrike also has some benefits. I would recommend Apex One depending on the scenario. I have to check it with my customer first. I have to identify their basic needs and what they want to do. Sometimes, it just matches the requirements, and sometimes, it does not, so it depends.
If you are looking for the productivity of employees, go for a signatureless solution.
For an SMB, I would rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
TrendAI Vision One – Endpoint Security
September 2026
Learn what your peers think about TrendAI Vision One – Endpoint Security. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,197 professionals have used our research since 2012.
Systems Engineer at a consultancy with 1,001-5,000 employees
Offers great integration, has valuable ransomware protection, and behavior monitoring
Pros and Cons
- "The ransomware protection and behavior monitoring features of Trend Micro Apex One are actually good."
- "One of Trend Micro's weaknesses is its high resource utilization."
What is our primary use case?
Many clients come to us after they have been attacked by ransomware. They often ask us to immediately remediate the situation, but this is not possible once a system has been compromised. However, we can usually install Trend Micro Apex One or a Cloud One product right away. This is our standard response to these situations.
Most of the clients I work with are hospitals. They have been using a different endpoint security solution, but they were attacked by ransomware and reached out to us for a different solution.
In one of the use cases we worked on, we simply installed an endpoint security solution. During the proof of concept, the hospital actually encountered a ransomware attack. There were two systems that were attacked: our test PC running Apex One and the other that was using the existing endpoint security solution. The Trend Micro-installed PC was able to navigate the attack, but the files on the other PC were corrupted.
We also simulate other attacks, such as ransomware or simple malware, using the Intelligent Content Analysis and Response tool. We then check the Device Control feature. Apex One also has data loss prevention and application control features. The DLP feature is not as comprehensive as a full-blown DLP solution, but it can be used to leverage regular expressions, specific keywords, and specific attributes. We also test the application control feature.
Our most recent testing has been with the new Vision One product. This is an extended detection and response platform that can be integrated with not only Trend Micro's other solutions, but also with other security solutions from different vendors, such as SIEM, firewalls, NDR, and vulnerability management systems.
When we test the integration of Apex One and Vision One, we focus on automation, remediation, and cost analysis. We can see how an attack was carried out, down to the file level, hostname, and user. If Vision One is integrated with Active Directory, we can also see who the user was at the time of the attack.
This is the scope of the usual use cases we perform during proof of concepts for Trend Micro Apex One.
How has it helped my organization?
I would rate Apex One nine out of ten for its ability to defend endpoints against malware, ransomware, and malicious scripts.
Apex One can defend against zero-day attacks and stealthy attacks. This is important because in-house applications can have many vulnerabilities, such as coding errors and misconfigurations, which attackers can exploit. Having Apex One as an advantage would give clients a head start in defending against unknown threats.
It uses runtime machine learning to detect ransomware. Machine learning allows us to monitor activities and suspicious behaviors running in our system, not only at the file transfer level but also at the library and registry level. This is important because it allows us to identify potential threats. Runtime machine learning can see any entry points that ransomware might use to infect a system.
Trend Micro has announced that they will be migrating the Apex One platform to Vision One, which can be integrated with an XDR.
Our clients have integrated Apex One with a vulnerability management firewall, SIEM, MFA solutions integrated with Azure AD, and the native security of Microsoft 365.
Apex One is user-friendly. For those familiar with an endpoint security solution, it will not be difficult to learn Trend Micro Apex One. However, for those who are new to the solution, they will need to take some time to learn the ropes.
Administering Apex One is straightforward, especially for the SaaS solution compared to the on-premises solution. This is because we only need to download the installer. The installer is large, around 400 MB. Once we install it on the system, we can communicate with the management console, which is the same for both solutions. We just need to make sure that all required communication ports, FQDNs, IP addresses, and ports are allowed on the firewall. We usually take into consideration the clients when we are doing POCs, and we need to work with the infrastructure team to check on this.
Apex One provides our clients with virtual patching to protect against vulnerabilities. From the perspective of an impending threat, if a client is able to patch the vulnerability in the meantime, Apex One can see the potential threat and take action to protect the client. This is done by identifying the signatures of the vulnerability and creating a virtual patch. It is important to make sure that clients understand that this is not an official patch, but rather a temporary measure that can be used while the official patch is being developed and applied.
Before using Trend Micro, many of our larger clients, which are hospitals, were constantly attacked by malware. However, after adopting Apex One, the viruses and malware have been significantly reduced or eliminated altogether. This is why they continue to renew their subscriptions to Trend Micro.
Most of the time, we recommend the SaaS version of Apex One because the on-premises solution from Trend Micro requires significant resources from the client. If they do not have the necessary monetary resources, they will need to take this into account. This is because when we build an on-premises Apex One, we need two servers: one for Apex One on-premises and one for Apex in Cloud. Additionally, if we leverage the entire SPE package, we will also need a server for mobile security and file and drive encryption.
The endpoint deployment in the cloud has helped our clients reduce their staff workload, especially on the maintenance side.
Apex One has helped reduce our client's administrative overhead.
Some of our clients use Trend Micro's managed XDR service and they love it because the automation makes things easier for them.
What is most valuable?
The ransomware protection and behavior monitoring features of Trend Micro Apex One are actually good. All endpoint security solutions are in the market to defend against and remediate threats. However, Trend Micro is particularly quick to identify suspicious activities. Any malicious virus or malware that can be extracted from the system is something that they can leverage and work on. One way they do this is through virtual patching. Most of the time, vulnerabilities come from legacy operating systems. These operating systems cannot always be updated, such as Windows 7. If Microsoft announces that it will no longer update a specific operating system, there is nothing that can be done about it. However, Trend Micro can anticipate specific vulnerabilities that can be exploited due to the lack of updates. They can then leverage these vulnerabilities to create a virtual patch that can be applied to the specific system. I believe this is one of the many highlights of Trend Micro Apex One.
What needs improvement?
One of Trend Micro's weaknesses is its high resource utilization. Many of our clients have complained about this, and it is a valid concern. However, we assure our clients that the level of security that Trend Micro provides is worth the high resource utilization. Trend Micro is very fast at detecting and protecting against threats. For example, they were able to identify suspicious signatures for a ransomware attack that was happening worldwide months before the attack actually occurred. We believe that this level of threat intelligence is a major strength of Trend Micro. Of course, no security solution is perfect. There are always ups and downs. However, we believe that Trend Micro's strengths outweigh its weaknesses. However, we do not only offer Trend Micro for this reason.
For how long have I used the solution?
I have been using Trend Micro Apex One for four years.
What do I think about the stability of the solution?
Trend Micro has consistently been in Gartner's Leaders Program year after year. Apex One is stable.
What do I think about the scalability of the solution?
Apex One is scalable.
How was the initial setup?
The initial setup is straightforward. We usually plan and gather data before implementing. We ensure that there are no residual old endpoints installed in the system. We then set expectations with the client and proceed with setting up the management console. We install the system step-by-step and then work on the policies. We also integrate with other systems and transfer knowledge and troubleshooting skills.
I usually complete the deployments on my own, but for our larger clients with over 2,000 endpoints in different locations, we need to be on-site. For a three-month deployment of those 2,000 endpoints, we allocated three engineers. There was also one time when we had to allocate a lot of engineers for a government agency with eight thousand employees.
What's my experience with pricing, setup cost, and licensing?
The pricing for Apex One is midrange, and worth the costs.
What other advice do I have?
I would rate Trend Micro Apex One an eight out of ten.
All security solutions require maintenance. But with SaaS deployment and SaaS security solutions, most of the maintenance is actually covered by the principal itself.
Apex One can be resource-intensive and have high utilization, but it does a great job protecting our clients' endpoints.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Principal Consultant at Jilit
Great for defending endpoints, reduces threats, and is easy to manage
Pros and Cons
- "Using the product as a service on the cloud has helped reduced employee workloads."
- "It would be better if it was easier to administer Apex One."
What is our primary use case?
We primarily use the solution for endpoint protection. We have only used the solution for six months, however, it has already improved the security posture of our organization.
How has it helped my organization?
The solution is good for monitoring endpoints and providing or removing access.
What is most valuable?
The automatic source updates are quite useful. The agent is installed on the machine and can provide updates to the clients.
It's an extremely convenient product.
It's great for defending endpoints against threats like malware, ransomware, and malicious scripts. The product provides good protection overall. It helps protect our endpoints against even unknown or stealthy threats. It adapts well against various threats.
Apex One detects ransomware with runtime machine-learning capabilities. This is very important for us. It's protected us well against ransomware.
The product provides a single console for cross-layer detection, threat hunting, and investigation. Having a single layer of control makes things easy. It provides complete end-to-end visibility to the entire IT security environment.
Using it makes the management of threat detection smoother. It's reduced our response times by 60% to 70%.
It has provided us with virtual patching to protect us against vulnerabilities even before a patch is available for the source of the issue. This is very useful. It's a pretty significant aspect of the product.
We've seen a reduction in viruses since moving to ApexOne. We've seen a 50% to 60% reduction in events.
Using the product as a service on the cloud has helped reduce employee workloads. It's also reduced administrative overhead.
What needs improvement?
We'd like to have access to more learning materials to help us understand the solution better. It would be great if the company offered some core courses.
It would be better if it was easier to administer Apex One. Right now, it is moderate.
For how long have I used the solution?
I've been using the solution for the last six months.
What do I think about the stability of the solution?
The solution is stable and has met our needs.
What do I think about the scalability of the solution?
We can increase capacity based on our needs. It is a scalable product.
How are customer service and support?
I haven't had any issues with technical support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used Symantec, among other solutions, in the past. We read about this product and found it was better at endpoint protection.
How was the initial setup?
The initial setup process was not easy or difficult. It was moderate. You do need to have some knowledge of the solution in order to deploy it effectively.
What's my experience with pricing, setup cost, and licensing?
I don't have any insights in terms of pricing.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this solution.
What other advice do I have?
I'm a customer and end-user.
We do not use the solution to integrate with other security products. We don't use any other products.
We have tried to use Trend Micro's managed XDR services in conjunction with Apex One, however, we weren't able to install an agent, so we're looking into it.
I'd rate the solution eight out of ten. I'd recommend it as a security solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Operations Section Head at Toyota Motor Philippines Corporation
Offers quick and timely updates, and the management is simple
Pros and Cons
- "The solution offers quick and timely updates."
- "We do not have much control as we have to work with regional policies and regional support."
What is our primary use case?
We use the solution for endpoint protection.
How has it helped my organization?
Prior to this solution, we used Symantec, and we managed everything locally. When we were researching this product, we liked that it was managed based on region. We had good results following incidents and observed detection capabilities.
What is most valuable?
The pricing is very good.
The solution offers quick and timely updates. We also like that the solution is managed by the region. We're in the Asia Pacific. The management is simple and our support does not need to worry as much.
We have also been able to free up time. We can allocate that time to other tasks. We began to realize the benefits of the solution within six months of implementation.
What needs improvement?
At the moment, we have no issues with the product. However, we do not have much control as we have to work with regional policies and regional support. I'm not sure if this is an HP item or a Trend Micro program issue. Nevertheless, product-wise, we have no concerns.
Trend Micro has mentioned the potential for EDR functionality. We are excited about that. It will be good not to have a separate license for ADA.
For how long have I used the solution?
I've been working with the solution for four years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution scales well.
How are customer service and support?
We don't have any interaction with Trend Micro's technical support. We do have local support, however, our interactions with them are very minimal. We might ask questions about bugs we've found, but that's it. They respond quickly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We also use Cisco.
In the past, we used Symantec, but we no longer use it. Once we evaluated Trend Micro, we decided to switch.
How was the initial setup?
The initial setup is very straightforward. There were no complexities. It only takes one or two minutes to deploy. We have the product in multiple locations and branches.
What about the implementation team?
Our support handled the product's initial setup. We didn't need any assistance.
What was our ROI?
While I cannot put the ROI into financial terms, in terms of operations it's quite good. We have fewer incidents and the response time is quick for virus-related issues. We can resolve events faster and we might have noted a 50% ROI.
What's my experience with pricing, setup cost, and licensing?
The product's price is fair. We get a regional discount. There are also regional maintenance costs that are not connected to Trend Micro directly. They are part of a service we have.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Trend Micro.
What other advice do I have?
We use the product's latest version.
I'd rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information security specialist at a energy/utilities company with 10,001+ employees
It's a good solution for large companies that need to monitor and mitigate external threats
Pros and Cons
- "I like Apex One's USB port blocking. We implement different policies for each client. For example, a client might ask us to block certain USB devices or require us to restart a desktop on the network."
- "Apex One's account security could be improved."
What is our primary use case?
I work with Trend Micro Apex One and Vision One. The solutions are also integrated with ServiceNow ITSM. When we detect issues with Apex One, we can open up tickets in ServiceNow to address them. We customize the solution for our clients. The types of policies we implement in ApexOne depend on the customer's situation.
How has it helped my organization?
Apex One has helped us mitigate a lot of threats like phishing and malware. We've seen a reduction of about 30 percent.
What is most valuable?
I like Apex One's USB port blocking. We implement different policies for each client. For example, a client might ask us to block certain USB devices or require us to restart a desktop on the network. We can track threats across the network and delete viruses on the endpoint level from a desktop or a laptop. Apex One offers cloud security for large companies that need to monitor and mitigate external threats. It's crucial to have end-to-end visibility from a central console.
What needs improvement?
Apex One's account security could be improved.
For how long have I used the solution?
I have used Trend Micro Apex One for about six months.
What do I think about the stability of the solution?
Apex One is stable.
What do I think about the scalability of the solution?
Apex One is scalable.
How are customer service and support?
I rate Trend Micro support eight out of 10. I have had no problems with Trend Micro support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used McAfee EDR. I like Apex One much better.
How was the initial setup?
Apex One isn't complex to set up. The deployment time depends on the size of the company. It could take a few weeks in some cases. A five-person team deployed the solution.
What's my experience with pricing, setup cost, and licensing?
Apex One is relatively inexpensive.
What other advice do I have?
I rate Trend Micro Apex One eight out of 10. It's an excellent solution that helps companies mitigate attacks from the internet.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior Officer Infrastructure Security at a financial services firm with 5,001-10,000 employees
Provides great protection and has good reporting and dashboard
Pros and Cons
- "Its reporting and dashboard are valuable. Its dashboard is easy to use."
- "It could be more customizable."
What is our primary use case?
Apex One is used for endpoint security. I deployed it for two major financial institutions in my previous company. I also installed it in my internal lab in the previous company.
I am currently not using it. I am currently at a banking site, but before that, I was at a managed service provider vendor site.
How has it helped my organization?
Apex One is a great solution for defending endpoints against threats such as malware, ransomware, and malicious scripts. It can detect malicious files, ransomware, and suspicious files.
I have not had any issues regarding detection. I have deployed it on two customer sites, and I have not heard of any issues from them. It provides great protection to endpoints.
We have seen a reduction in viruses and malware since moving to Apex One. It provides great protection. It detected ransomware for one customer. After you install it and sign in, it quickly detects all the viruses.
Apex One provides a single console for cross-layer detection, threat hunting, and investigation. It shows everything on the console. If you integrate it with Apex Central, then Apex Central provides a centralized dashboard of every product of Trend Micro. It provides full visibility into the environment. You get full visibility of all the products installed on the site such as DLP, encryption, XDR, and Vision One. Apex Central is the centralized management system.
Apex One integrates with other security products. I have integrated it with SIEM solutions. I have integrated it with LogRhythm and QRadar for log collection.
Apex One is an all-in-one solution. It provides application control, vulnerability management, and protection. It is also for EDR.
It is easy to administer. You have to specify the policy criteria and automate the policies.
Apex One reduces the administrative overhead. There is a 20% to 30% reduction.
What is most valuable?
Its reporting and dashboard are valuable. Its dashboard is easy to use.
What needs improvement?
It could be more customizable. Some clients' systems are slow after the installation of Apex One.
For how long have I used the solution?
I have been using it from the start. It has been more than five years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is a scalable solution. Our clients were enterprise clients.
How are customer service and support?
Their support team has been very helpful when we needed support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have not used any other solution.
How was the initial setup?
I have experience with on-premises and cloud deployments. I prefer the cloud. The cloud setup is easy.
The deployment depends on the client. If client requirements are clear, it is easy. Otherwise, it can be complex. In Pakistan, there are many problems that we are facing with the deployment process of Apex One because some clients are not pushing the agents to Active Directory or remote registry. We have to install it manually on every computer or place it on a shared server to install it on their endpoints.
The deployment duration depends on the number of endpoints. For more than 2,000 endpoints, it can take two to three months. If you are only installing the endpoint solution from a remote site without making any policies, then it does not take too much time. You just need to push the agent.
It requires maintenance. There are upgrades. They inform the customers and partners when they are having a major upgrade.
What other advice do I have?
Overall, I would rate Trend Micro Apex One an eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
Owner at a tech services company with 1-10 employees
Works well in a Microsoft environment and provides virtual patching but needs better reporting
Pros and Cons
- "The cloud-based management portal was okay."
- "The reporting can be improved. We'd like to have had broader insights as to what was happening on a machine."
What is our primary use case?
The solution is used for security management in the broadest sense. It was for antivirus and malware scanning.
How has it helped my organization?
The client already phased the product out. However, it was used as endpoint protection.
What is most valuable?
I only worked with it for a couple of months, and we phased it out due to some technical reasons.
The cloud-based management portal was okay.
It does help prevent various threats. While it's protecting in a broader sense, the issue is I can't see the results of what is happening.
ApexOne does integrate with other security products. We had a different solution from Trend Micro running. We also are running a server-based solution available from Trend Micro, although they were not necessarily integrated.
We had it installed within a Microsoft environment.
If you are an administrator who needs to access the console, it's pretty straightforward. It's easy to administer ApexOne.
The solution provides you with virtual patching to protect against vulnerabilities.
We were able to use Trend Micro's XDR services in conjunction with ApexOne. It helped give us some extra insights and additional security measurements.
What needs improvement?
In terms of protecting points against threats, it's hard to answer the question. I'd only worked for it for a couple of months. From what I'd seen, we weren't able to see well reporting-wise. For example, what it does, what it catches, and what it prevents, Defender 365 is way more advanced and transparent. The reporting can be improved. We'd like to have had broader insights as to what was happening on a machine.
As a user or as an administrator, you should be able to see what the product actually does. You would like to see what's happening. What's scanning, et cetera, and it doesn't do a good job like Defender 365 does.
We had some pretty severe issues in a VDI environment. Every time a machine reboots, it needs to fetch the latest updates. However, we had some caching issues, and Trend Micro did not update some specific components which caused VMs to fall out or some people not to be able to work on their VDI anymore. We had some support cases open with Trend Micro, however, it was not easy at all. It was pretty hard to comprehend our specific situation as it was a little in-depth.
For how long have I used the solution?
I have used the solution for less than a year.
What do I think about the stability of the solution?
We experienced instability with a few different Trend Micro products. Typically, after an update, we would have some issues.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
We had severe cases with VMs falling down. Support took too long to help define the root cause of the issue.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We implemented Microsoft Defender 365 in its place. When you look at, for example, reporting from all kinds of incidents it seems to be better than what I have seen from Trend Micro.
There was a period of time when the company paid for both Microsoft licenses and Defender and the reason for the transition was to just have the one solution already covered under 365.
How was the initial setup?
The solution was deployed on-premises. The company used Citrix Cloud, however, the machines that people worked on were local. There was no cloud-based machinery.
I was not involved with the deployment of ApexOne. I can't speak to how long it took.
Uninstalling or removing the product wasn't easy.
The solution did require maintenance. Every month we did an image update of the VDI environment. We manually had to make sure everything from ApexOne was exactly right, and the update process was very tricky.
What's my experience with pricing, setup cost, and licensing?
I was not in a position to compare the cost of licenses.
What other advice do I have?
I'm an independent freelance consultant. I used the solution within the last company I worked for and used it as an administrator and a user.
I'm not sure if I have noticed a reduction in viruses and malware since moving on to ApexOne. I worked with it for too short of a time period. We never had a real outbreak or anything.
I'd advise those considering the product to do a good proof of concept to really make sure the solution fits. Have your needs and everything in place. Get all the people who will administer the product involved and well-trained. Look at all of the reports as well.
Overall, I would rate the solution six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Consultant
Senior Manager at Gsfc Ltd
A user-friendly solution that provides virtual patching to protect systems with old operating systems from attacks
Pros and Cons
- "The most valuable feature of Trend Vision One Endpoint Security is the virtual patching it provides."
- "The solution can be improved to utilize fewer system resources, like memory and hard disk, during scanning."
What is our primary use case?
We use Trend Vision One Endpoint Security for securing end-user systems, desktops, and laptops. We also use it to secure the data in the user system, which we officially provide to employees. It also supports backward compatibility by providing virtual patching to operating systems like Windows 8, whose end-of-life was declared by Microsoft.
How has it helped my organization?
Normally, all organizations have their own domain services. Employees who log in to the local LAN network are given unique login credentials to log in to the system and access applications. Without the solution, DDoS attacks could happen in the network, and unknown traffic could be generated from the endpoints. Sometimes, the malware uses up all the resources, generates traffic, and destabilizes the server or network connectivity.
Services like Trend Vision One Endpoint Security and endpoints security identify malware or viruses infecting the systems. We can disconnect them from the network and limit unknown traffic. The official work which needs to be done gets faster. Otherwise, it slows the network and affects the other systems by overloading the services and applications.
Since we have installed the solution in the system, malware attacks get quarantined, and we get notifications on our dashboard. We get a notification on the solution's centralized dashboard, and then we take the needful action on that.
Trend Vision One Endpoint SecurityOne has advanced protection capabilities that adapt to protect against unknown and new threats.
The solution detects ransomware with run-time machine learning capabilities.
The solution's ransomware detection ability is very important to us.
The dashboard provides us with a single console for cross-layer detection, threat hunting, and investigation. It is very important to have a single console for cross-layer detection.
The solution does not provide end-to-end visibility into the entire IT security environment. It only provides visibility for the desktop part. There is a separate solution for the server part. However, the solution provides complete visibility for the end user part.
The solution integrates with other security products. As part of integrating with other security products, when a threat is detected in the network sandbox, the solution deploys rapid updates to the endpoint. We have scheduled updates. On the server, it gets automatically updated, but on the end user part, we have defined the schedule for when it should get updated.
Trend Vision One Endpoint Security is easy to learn because it's a web-based application. It gives a dashboard on the web, making it easy to identify the affected endpoint or port. So it's easy, and any technical person can use it in a simple way.
Administering it is just a one-time setup; if you have done it, you won't face any issues.
Trend Vision One Endpoint Security has reduced administrative overhead for us. Earlier, we used a different endpoint solution. So the administrative people involved with the old solution are also involved in the new solution.
We are using Trend Micro's managed XDR services in conjunction with Trend Vision One Endpoint Security, which has been quite useful for our Trend Vision One Endpoint Security deployment. It's an additional benefit to the Trend Vision Service.
Users can evaluate the product, and they can use it. We have been using it for the last six to seven years, and it's a stable solution. We haven't faced many issues. The functions we set are normal, and if the end-user faces any issue, we can easily rectify it.Trend Vision One Endpoint Security is a user-friendly solution that can be used by all organizations.
What is most valuable?
The most valuable feature of Trend Vision One Endpoint Security is the virtual patching it provides. If no patches are available for any operating system we use, the system becomes vulnerable to attacks. Trend Vision One Endpoint Security provides virtual patching services, which protect the system from any attack.
The virtual patching feature of Trend Vision One Endpoint Security is quite significant. While Microsoft has released new operating systems like Windows 10 and Windows 11, older operating systems like Windows 8 and Windows 7 are being used for specific purposes. It's not possible to immediately upgrade to a new operating system once it is released. In such a case, we can use the virtual patching feature, which helps limit any attacks on that system, and we can use it till we go for any replacement or upgrade of that machine.
What needs improvement?
The resources used by Trend Vision One Endpoint Security during scanning could be improved. Once the endpoint scanning starts, it may run up to two to three hours; and other applications slow down during that time. The solution can be improved to utilize fewer system resources, like memory and hard disk, during scanning.
For how long have I used the solution?
I have been using Trend Vision One Endpoint Security for the last six years.
What do I think about the stability of the solution?
Trend Vision One Endpoint Security is a stable solution.
I rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
Trend Vision One Endpoint Security is a scalable solution.
I rate it an eight out of ten for scalability.
Which solution did I use previously and why did I switch?
We previously used McAfee. McAfee had some business changes as some other company took over, and there was no future roadmap for the next releases. I was unclear if I would get any updates or if the solution would introduce new versions or releases in the coming years.
How was the initial setup?
The solution's initial setup is straightforward. We have installed the solution on two virtual servers with high availability mode.
What about the implementation team?
We had support from Trend Micro, and a partner was also involved in the solution's deployment. So around four people were involved during the solution's one-time installation.
All the departments use Trend Vision One Endpoint Security in our organization. We have a separate contract for the maintenance of the solution on an on-call basis. If we face any maintenance issues, we open a ticket.
What was our ROI?
We have seen a return on investment with Trend Vision One Endpoint Security. We have seen a significant reduction of around 60 to 70% in viruses and malware since we started using Trend Vision One Endpoint Security.
What's my experience with pricing, setup cost, and licensing?
The subscription model is definitely on the expensive side. Earlier, we used to pay a one-time license fee and yearly support charges. However, with the subscription model, we have to pay more for the complete cost every year.
What other advice do I have?
Overall, I rate Trend Trend Vision One Endpoint Security an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT analyst at a tech services company with 5,001-10,000 employees
Fairly priced with good detection capabilities but needs better integrations
Pros and Cons
- "We've been able to integrate the solution with other security products."
- "They need to integrate the DLP with the EDR."
What is our primary use case?
There are many use cases. For example, it would depend on the user's requirements. It's mostly for security.
How has it helped my organization?
The detection of viruses has been good. The ability to automate has been useful.
What is most valuable?
The security is very good. It's helpful for catching viruses.
We are satisfied with the protection it provides. It protects endpoints against malware, ransomware, and malicious scripts.
It helps us find new stealthy threats. It can find new viruses and the latest threats before they can do damage. They can update sometimes twice a day, depending on the virus or malicious activity that is happening.
The product can detect ransomware and has runtime machine-learning capabilities.
It provides a single console for detection, threat hunting, and investigations. It's very handy and helps us optimize.
We get end-to-end visibility for our entire security environment. We've been able to reduce our response time thanks to this capability. We've reduced response time by about 30%.
We've been able to integrate the solution with other security products.
When we've had detection in the sandbox, we're able to deploy rapid updates to endpoints.
It's an easy solution to learn. It's also very easy to administer.
The service's endpoint deployment in the cloud helped reduce our staff workload by 20%.
What needs improvement?
There needs to be more integration with third parties. They need to integrate the DLP with the EDR.
For how long have I used the solution?
I've been using the solution for four years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have about 6,000 or more users using the product in our organization.
The solution can scale.
How are customer service and support?
We have sent requests for support. They are okay. They need to improve the response time.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used CrowdStrike. CrowdStrike is EDR/XDR. CrowdStrike has a very good interface. Trend Micro has two different consoles for XDR and EDR, whereas, with CrowdStrike, it's all one console.
How was the initial setup?
The initial deployment was straightforward. It took about two months to deploy.
We have the solution deployed in multiple areas.
It does not require any maintenance. You just need to make sure it is up to date.
What was our ROI?
We have witnessed an ROI. It's difficult to define, however. It may be around 30%.
What's my experience with pricing, setup cost, and licensing?
It is a fairly priced product.
What other advice do I have?
We're a customer.
We use ApexOne as a service.
I'd rate the solution seven out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free TrendAI Vision One – Endpoint Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Endpoint Protection Platform (EPP) Endpoint Compliance Endpoint Detection and Response (EDR)Popular Comparisons
Cortex XDR by Palo Alto Networks
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Endpoint
IBM Security QRadar
Elastic Security
Huntress Managed EDR
TrendAI Vision One
Trellix Endpoint Security Platform
WatchGuard Firebox
HP Wolf Security
Symantec Endpoint Security
Microsoft Defender XDR
Buyer's Guide
Download our free TrendAI Vision One – Endpoint Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the biggest differences between BitDefender and Trend Micro?
- What's the difference between Trend Micro Deep Security and Trend Micro Apex One?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Which ransomware is the biggest threat in 2020?


















