Sora Yazılım
Network security, server and software solutions from Türkiye

Apex One Migration Plan: Moving to Trend Vision One Endpoint Security

In short: Apex One migration is not a one-click upgrade. For on-premises Apex One, you export policies with the Apex One Settings Export Tool, import them into a Standard Endpoint Protection instance in Trend Vision One Endpoint Security and move agents in waves. Apex One as a Service is updated from the console, irreversibly.

What is the official Apex One migration path?

It depends on your Apex One model: on-premises endpoints and settings are moved manually, while Apex One as a Service is updated from the Trend Vision One console. Trend Vision One is Trend Micro's XDR platform; since the enterprise business began operating as TrendAI on 23 March 2026, the documentation calls it "TrendAI Vision One".

The target is Trend Vision One Endpoint Security, which has two protection managers: Standard Endpoint Protection (SEP) for end-user devices and Server & Workload Protection for servers, plus a sensor-only deployment. According to Trend, the Product Instance app currently does not support updating on-premises Apex One to SEP. For the wider platform, see our guide to Trend Vision One's XDR and risk management components.

Current setupDocumented pathWay backWatch out for
On-premises Apex OnePolicy export with the Settings Export Tool; agent move via the Apex One console or IPXferIPXfer onlyA provisioned SEP instance is required; agents take the target's settings
Apex One as a ServiceProduct Instance → Update Solution → Connect and TransferNone; cannot be stopped once startedOff-hours recommended; Endpoint Sensor agents are re-associated by support
Evaluate first"Evaluate Standard Endpoint Protection"Via IPXferApex One as a Service June 2023 maintenance or Apex Central Patch 5 and later; up to five SEP instances

Has Trend announced an Apex One end of life date?

Yes for Apex One as a Service; for on-premises Apex One, Trend's lifecycle list showed no date as of 7 October 2026. The list marks Apex One as a Service as "End-of-Sale", with end of sale and renewal on 31 December 2025 and end of life on 31 December 2027.

No date does not make the version irrelevant: under Trend's support policy, each program build is supported for 18 months from its release month, and on-premises Apex One gets two patch releases a year (Q1 and Q3).

Why keep the old server patched during migration?

Version 2026.10.04 of CISA's Known Exploited Vulnerabilities (KEV) catalogue has 10 entries naming Apex One. The two newest concern the on-premises server:

  • CVE-2025-54948 (added 18 August 2025): command injection in the on-premises management console. Trend bulletin KA-0020652 lists SP1 CP B14081 as the permanent fix and advises source restrictions for externally exposed consoles.
  • CVE-2026-34926 (added 21 May 2026): directory traversal in the on-premises server. Bulletin KA-0023430 lists SP1 CP Build 18012 for existing SP1 users and SP1 Build 17079 for new installs.

Until it is retired, the old server stays in your attack surface: patch it, restrict console access to the management network and keep the parallel period short.

What should you inventory before migrating?

You need a written list of agents, policies, exceptions and integrations, because settings do not travel with the agent; they are reattached on the target. Fill in this checklist from your Apex One deployment console.

  • Agents: name, OS version, agent version, managing server, online/offline status.
  • Hardware: SEP needs 2.5 GB RAM dedicated to the agent and at least 4.5 GB disk on Windows 10 and Windows Server; flag older devices.
  • Policies: Security Agent and DLP policies and the groups they are assigned to.
  • Exceptions: scan exclusions, trusted program list, application control criteria, device control allowed devices, intrusion prevention rules.
  • Unload passwords: the IPXfer command asks for this password on every endpoint.
  • Integrations: syslog, Active Directory, Automation API, SIEM/SOAR feeds, scheduled reports.
  • Network: proxy settings, firewall rules, regional Vision One exceptions, Service Gateway.
  • Special cases: VDI golden images, macOS, Linux, servers, Endpoint Sensor (EDR) groups.

Which device should go to which Vision One component?

End-user Windows and macOS devices go to Standard Endpoint Protection, Linux servers to Server & Workload Protection or sensor-only; for Windows servers it depends on the features you need. Based on Trend's feature mapping by platform:

Device / roleTargetBasis in the documentation
Windows desktops and laptopsStandard Endpoint ProtectionAll Apex One Security Agent policy features are supported
macOSStandard Endpoint ProtectionApex One (Mac) policy settings apply; Server & Workload Protection features cannot be deployed to macOS
Windows serversSEP or Server & Workload ProtectionSEP requirements list Windows Server 2012–2025; Integrity Monitoring and Log Inspection exist only in Server & Workload Protection
Linux serversServer & Workload Protection or sensor-onlySEP features cannot be deployed to Linux
Devices without a Trend protection agentSensor-onlyDeployment that works without a protection manager

For integrity monitoring and log inspection on servers, also assess the server and workload protection line. Trend flags the new "Endpoint Security Policies" model as pre-release (agent 202507 or later), so protection manager policies are the more predictable start. Small businesses with a lean IT team may prefer our guide to choosing between Worry-Free and Vision One.

How do you move Apex One policies and exclusions?

Policies are exported with the Apex One Settings Export Tool and imported into the target SEP instance; they are not applied to moved agents automatically. Trend's console migration steps:

  1. In the Apex One server console, download the tool from Administration → Settings → Server Migration; it also sits under PCCSRV\Admin\Utility\PolicyExportTool in the installation folder.
  2. Run ApexOneSettingsExportTool.exe from an elevated prompt; it produces ApexOne_Agent_Policies.zip and ApexOne_Agent_DLP_Policies.zip.
  3. In Vision One, open Endpoint Security → Standard Endpoint Protection → Policies → Policy Management, select "Apex One Security Agent" and import the first archive, then "Apex One Data Loss Prevention" for the second.
  4. Imported policies have no targets; assign the target groups yourself.
  5. After the agents move, apply the policies to them.

Agents inherit the target's settings; with IPXfer they take the parent group's settings, not their source settings. Preparing the target group and policy before each wave shortens the time on defaults. Proxy settings do not move either: Vision One uses policy-based Runtime Proxy Settings, which Trend has been moving to Connection Policies since 28 April 2026.

How do you run the pilot and migration waves?

Trend recommends batches or phases rather than all at once: every endpoint reporting to Vision One downloads and installs a new agent package, and insufficient bandwidth can cause outages. Traffic uses HTTPS with TLS on port 4343, plus region-specific firewall exceptions; Trend recommends a Service Gateway with the Forward Proxy service to manage bandwidth.

The pilot should represent every OS, policy type, remote device and critical application user. The console moves many agents at once but only online ones; IPXfer also handles offline devices, one at a time with local admin rights. Each wave:

  1. Prepare the group and policy in the target SEP instance.
  2. Copy the target server FQDN from Directories → Product Servers, without port or path.
  3. In the Apex One console, select agents under Agents → Agent Management, choose Manage Agent Tree → Move Agent and enter the FQDN for "Move selected agent(s) to another Apex One server".
  4. Confirm the agents report to the SEP instance and install the new package.
  5. Apply policies; collect false-positive and performance feedback.
  6. Move remaining offline agents with IPXfer.
PhaseDocumented tool / stepExit criterion
0. InventoryApex One consoleEvery device has a target
1. Target readinessProduct Instance, Service GatewayA test device connects on 4343
2. Policy transferSettings Export Tool, Import SettingsPolicies assigned to target groups
3. PilotMove Agent / IPXferOpen issues closed
4. WavesMove Agent, IPXferOnly deliberate exceptions left on the source
5. VerificationEndpoint Inventory, logsChecklist complete
6. RetirementBackup, uninstallation programServer and rules removed

Want to build the inventory and wave plan together? Ask about implementation support. Get a Quote

How do you run two consoles during the transition?

While waves run, some endpoints sit on Apex One and some on Vision One; keep this period short and recorded in one table (device, date, method). Because IPXfer is the only documented way back, the rollback plan must include the tool, unload passwords and the target server certificate.

Check other protection products too. Per Microsoft Learn, on Windows 10/11 devices not onboarded to Defender for Endpoint, Microsoft Defender Antivirus switches to disabled mode automatically when a non-Microsoft antivirus is primary; on Windows Server this must be set manually. Checking AMRunningMode in Get-MpComputerStatus during the pilot reveals overlapping real-time engines early.

How do you verify the migration is complete?

A device appearing in Vision One is not enough; you need evidence that it got the right policy, updated its components and produces logs. Trend notes that HTTPS issues can leave agents offline, not updating or not uploading logs. Checklist:

  • The Endpoint Inventory count matches your inventory; any gap is explained in writing.
  • Each group has its intended policy; exclusions and DLP rules are in place.
  • Component updates are complete; no device shows as offline.
  • A harmless test confirms detection, alerting and log flow (syslog/SIEM).
  • Endpoint Sensor status is confirmed for groups using EDR.
  • Apex One as a Service: post-update tasks done (IdP, user roles, groups and policies, Endpoint Sensor re-association via support).

XDR and correlation features come next; see our Trend Vision One solution page.

How do you retire the old Apex One console?

Retire the old server only after every agent has moved. Trend's installation guide advises moving the agents and backing up the database and configuration files before uninstalling. The order:

  1. Confirm no managed agents remain, or that any remainder is deliberately out of scope.
  2. Export the logs and reports you must keep; organisations in Türkiye can use our KVKK technical measures checklist for retention needs.
  3. Back up the database and configuration files.
  4. On the server, use Start → Programs → Trend Micro Apex One Server → Uninstall Apex One or Control Panel; the program asks for the administrator password.
  5. Remove firewall rules, DNS records, service accounts and console access; document the change.

FAQ

Can an on-premises Apex One server be updated to Vision One automatically?

No. Trend's "Before You Migrate" page states that the Product Instance app currently does not support updating on-premises Apex One to a Standard Endpoint Protection Manager. Policies move via the Settings Export Tool and agents via the Apex One console or IPXfer to a provisioned SEP instance.

Can moved agents be returned to Apex One?

Not from the Vision One console. Trend's documentation says agents moved to SEP can only go back to an Apex One server with the IPXfer tool. It moves one agent at a time and needs local admin rights plus the unload password, so test the rollback on one device before the pilot.

Do you need to uninstall the Apex One agent before moving it?

Not in the documented path. According to Trend, an endpoint that starts reporting to Vision One Endpoint Security downloads and installs a new agent package by itself. Package size varies with pattern and binary updates, so Trend suggests downloading an installer from Endpoint Inventory to check the current size.

Can the Apex One as a Service update be stopped halfway?

No. Trend calls the update permanent: once started, it cannot be undone or stopped. Duration depends on how many agents the instance manages, and console sessions end when it begins. Trend recommends off-hours and asks customers with PCI compliance concerns to contact a sales representative first.

What must the network be ready for?

Agents use HTTPS with TLS on port 4343, and your region's firewall exceptions must be open. Trend recommends a Service Gateway with Forward Proxy for bandwidth and testing proxy settings before migrating. For a network and wave plan tailored to your environment, contact us.

Conclusion

  • On-premises Apex One migrates manually: policy transfer, target assignment, agent waves.
  • The Apex One as a Service update is permanent; plan it off-hours.
  • Pick each device's target per the documentation: SEP, Server & Workload Protection or sensor-only.
  • Keep the old server patched and access-restricted until it is retired.

Sora Yazılım provides selection, procurement, deployment and support for Trend Micro products and can plan the migration with you, from inventory to retirement.

Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com

Sources

  1. Before You Migrate — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  2. Migrating Agents with the Apex One Server Console — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  3. Migrating Agents with the IPXfer Tool — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  4. Updating Apex One as a Service from the Vision One console — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  5. Evaluate TrendAI Vision One Endpoint Security — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  6. Evaluate Standard Endpoint Protection — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  7. Move agents with the Apex One server console — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  8. Setting up Endpoint Security for new customers — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  9. Protection feature support mapping by platform — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  10. Standard Endpoint Protection system requirements — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  11. Runtime Proxy Settings — TrendAI. docs.trendmicro.com (accessed 7 October 2026)
  12. Before Uninstalling the Apex One Server — Apex One SP1 Patch 4 Install Guide. docs.trendmicro.com (accessed 7 October 2026)
  13. Uninstalling the Apex One Server Using the Uninstallation Program — Apex One SP1 Install Guide. docs.trendmicro.com (accessed 7 October 2026)
  14. Supported and End-of-Life Products and Services (KA-0004690) — TrendAI. success.trendmicro.com (accessed 7 October 2026)
  15. Apex One Support Policy (KA-0013579) — Trend Micro. success.trendmicro.com (accessed 7 October 2026)
  16. Security bulletin KA-0020652 (CVE-2025-54948) — Trend Micro, 2025. success.trendmicro.com (accessed 7 October 2026)
  17. Security bulletin KA-0023430 (CVE-2026-34926) — TrendAI, May 2026. success.trendmicro.com (accessed 7 October 2026)
  18. Known Exploited Vulnerabilities Catalog, version 2026.10.04 — CISA (data file). github.com/cisagov (accessed 7 October 2026)
  19. Microsoft Defender Antivirus compatibility — Microsoft Learn. learn.microsoft.com (accessed 7 October 2026)
  20. Trend Micro's Enterprise Business is now TrendAI — Trend Micro Newsroom, 23 March 2026. newsroom.trendmicro.com (accessed 7 October 2026)

How this article was prepared

Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical details were checked against the vendor and official sources linked in the text as of 7 October 2026.

Related articles

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support