Views:

This section shows the Operating system compatibility depending on the TMEE product installed on the endpoints.

Full Disk Encryption

  • Version 6.0.0.3204: Windows 10 21H2
  • Version 6.0.0.3153: Windows 10 1909/19H2
  • Version 6.0.0.3051: Windows 10 1903/19H1
  • Version 6.0.0.2056: Windows 10 1709 RS3
  • Version 6.0.0.1514: Windows 10 1709 RS3

File Encryption

  • Version 6.0.0.3066: Windows 10 21H2
  • Version 6.0.0.3027: Windows 10 20H2
  • Version 6.0.0.2018 (6.0 L10n): Windows 10 1709 RS3
  • Version 6.0.0.1070: Windows 10 1709 RS3

Encryption Management for Microsoft Bitlocker

  • Version 6.0.0.3072: Windows 10 22H2 and Windows 11 22H2/23H2
  • Version 6.0.0.3036: Windows 10 22H2 and Windows 11 22H2/23H2
  • Version 6.0.0.3018: Windows 10 22H2 and Windows 11 22H2
  • Version 6.0.0.3013: Windows 10 1903 19H1
  • Version 6.0.0.2020 (6.0 L10n): Windows 10 1709 RS3
  • Version 6.0.0.1042: Windows 10 1709 RS3

Encryption Management for Apple Filevault

  • Version 6.0.0.3253: MacOS 10.11 ~ 11.0, Support T2 chip
  • Version 6.0.0.3240: MacOS 10.11 ~ 10.15, Support T2 chip
  • Version 6.0.0.3010: MacOS 10.8 ~ 10.14, Support T2 chip
  • Version 6.0.0.3009: MacOS 10.8 ~ 10.13
  • Version 6.0.0.2018 (6.0 L10n): MacOS 10.8 ~ 10.12
  • Version 6.0.0.1033: MacOS 10.8 ~ 10.12
Operating System
Endpoint EncryptionWindows
Server 2008
Windows
Server 2008 R2
Windows
Server 2012
Windows
Server 2012 R2
Windows
Server 2016
Windows
Server 2019
Windows
Server 2022
Windows XPWindows 7Windows 8Windows 8.1Windows 10Windows 11Mac OSX
Policy Server
PolicyServerMMC
Full Disk Encryption
File Encryption
Encryption Management for Microsoft Bitlocker
Encryption Management for Apple Filevault

Windows 10 Compatibility

  • Version 1607 (Anniversary Update)
  • Version 1703 (Creators Update)
  • Version 1709 (Fall Creators Update)
  • Version 1803 (April 2018 Update)
  • Version 1809 (October 2018 Update)
  • Version 1903 (May 2019 Update)
  • Version 1909 (November 2019 Update)
  • Version 2004 (May 2020 Update)
  • Version 20H2 (October 2020 Update)
  • Version 21H1 (May 2021 Update)
  • Version 21H2 (November 2021 Update)

Mac OSX Compatibility

  • OS X™ "Big Sur" - TBA
  • OS X™ "Catalina"
  • OS X™ "Mojave"
  • OS X™ "High Sierra"
  • OS X™ "Sierra"
  • OS X™ "El Capitan"

Hardware and Scaling Requirements

The following shows deployment and scaling requirements in several different-sized environments. In smaller network environments, PolicyServer SQL databases can be installed on the same server. For PolicyServer deployments in environments greater than 1500 devices, Trend Micro recommends having at least two dedicated servers:

  1. A dedicated server for the PolicyServer services, also known as the "front-end server"
  2. A dedicated server for the database, or add the database to an existing SQL cluster

The following table displays the requirements for the PolicyServer SQL database for the basic requirements at the specified scale:

DevicesPolicy Server Front-end RequirementsPolicy Server SQL Database Requirements
1,000
  • One front-end and SQL database multi-role server with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 120 GB hard drive
Installed on PolicyServer front-end server
4,000
  • One front-end and SQL database multi-role server with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 150 GB hard drive
Installed on PolicyServer front-end server
8,000
  • Two front-end servers each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • One SQL database server with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 150 GB hard drive
20,000
  • Four front-end servers each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL database servers (one for the policy database and one for the log database) each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 180 GB RAID 5 hard drive
40,000
  • Eight front-end servers each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL database servers (one for the policy database and one for the log database) each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 16 GB RAM
  • 350 GB shared SAN RAID 5 hard drive
 
  • Virtual hardware is supported under VMware Virtual Infrastructure.
  • Microsoft or VMware on virtual hardware does not support Microsoft Cluster Service.
  • Baseline testing was performed on an endpoint with an Intel Xeon CPU E5-2650 v4 2.20 GHz, 2200 Mhz.
 

Redundancy Requirements

With larger environments, Trend Micro recommends adding additional servers to avoid having single points of failure. The following table displays the requirements for the PolicyServer SQL database for an environment with increased redundancy.

DevicesPolicy Server Front-end RequirementsPolicy Server SQL Database
With Zero Points of Failure
8,000
  • Four front-end servers each with one Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • One SQL server cluster of two nodes, with Intel Xeon quad-core 2.2 GHz processors or above
  • 8 GB RAM
  • 60 GB RAID 5 hard drive
  • 150 GB shared SAN RAID 5 hard drive
20,000
  • Six front-end servers each with Intel Xeon quad-core 2.2 Ghz processors or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL server clusters of two nodes , with Intel Xeon quad-core 2.2 Ghz processors or above
  • 8 GB RAM
  • 60 GB RAID 5 hard drive
  • 180 GB shared SAN RAID 5 hard drive
40,000
  • Twelve front-end servers each with Intel Xeon quad-core 2.2 GHz processors or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL server clusters of two nodes , with Intel Xeon quad-core 2.2 Ghz processors or above
  • 16 GB RAM
  • 60 GB RAID 5 hard drive
  • 350 GB shared SAN RAID 5 hard drive

Software Requirements

SpecificationRequirements
Database server
  • Microsoft SQL Server 2008 / 2008 R2 / 2012 / 2012 R2 / 2014 / 2016 / 2017 / 2019
  • Microsoft SQL Server Express 2008 / 2012 / 2014 / 2016 / 2017 / 2019
  • Mixed Mode Authentication (SA password) installed
  • Reporting services installed
  • Note: For Windows Server 2008 R2, you must install SQL Server 2008 SP1.
Application server

PolicyServer 6.0 Patch 1 requires Microsoft Internet Information Services (IIS) with the following roles installed and enabled:

  • Application Development
    • ASP.NET
    • ASP
    • ISAPI Extensions
    • ISAPI Filters
  • Management Tools
    • IIS Management Console
    • IIS Management Scripts and Tools
    • Management Service
    • IIS 6 Management Compatibility
    • IIS 6 Metabase Compatibility

For Windows Server 2008 and 2008 R2 you must install the "Application server" role and the "Web server" role. Additionally, you must add SMTP and Microsoft IIS Support features.

Legacy Endpoint Encryption environments (version 3.1.3 and earlier) require Client Web Service. If you install Client Web Service on a remote endpoint, install Microsoft IIS on that endpoint.

Other software
  • Both Microsoft .NET Framework 2.0 SP2 (or 3.5) and 4.0
  • Windows Installer 4.5 (SQL Express)
 
  • For SQL Server:
    • Mixed Mode Authentication (SA password) installed and Reporting services installed
  • For Application Server:
    • On Windows Server 2008 and 2008 R2 you must install the "Application server" role and the "Web server" role. Additionally, you must add SMTP and Microsoft IIS Support features.
    • Legacy Endpoint Encryption environments (version 3.1.3 and earlier) require Client Web Service. If you install Client Web Service on a remote endpoint, install Microsoft IIS on that endpoint.
 

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
RAM1 GB
Disk space
  • 30 GB
  • 20% free disk space
  • 256 MB contiguous free space
Network connectivityCommunication with PolicyServer required for managed agents
Operating system
  • Windows™ Embedded POSReady 7 (32-bit/64-bit)
  • Windows™ 10 (32-bit/64-bit)
     
    Older builds of Windows 10 installed on endpoints where UEFI is enabled may encounter issues if secure boot is turned on. To prevent this issue, install all service packs, hotfixes and security patches for Windows 10 before proceeding with the installation.
     
  • Windows™ 8.1 (32-bit/64-bit)
  • Windows™ 8 (32-bit/64-bit)
  • Windows™ 7 (32-bit/64-bit)
Windows 10 Version Compatibility
  • Version 1607 (Anniversary Update)
  • Version 1703 (Creators Update)
  • Version 1709 (Fall Creators Update)
  • Version 1803 (April 2018 Update)
  • Version 1809 (October 2018 Update)
  • Version 1903 (May 2019 Update)
  • Version 1909 (November 2019 Update)
  • Version 2004 (May 2020 Update)
  • Version 20H2 (October 2020 Update)
  • Version 21H1 (May 2021 Update)
  • Version 21H2 (November 2021 Update)
Hard disk

Full Disk Encryption uses software-based encryption for all standard drives (drives without self-encryption).

Full Disk Encryption uses hardware-based encryption for the following self-encrypting drives (SEDs):

  • Seagate OPAL and OPAL 2 drives
  • SanDisk self-encrypting (OPAL2) solid-state drives
  • Toshiba self-encrypting (OPAL2) solid-state drives (SATA and NVMe)
  • Intel self-encrypting (OPAL2) solid-state drives (SATA and NVMe)

Full Disk Encryption has the following limitations:

  • Full Disk Encryption does not support RAID and SCSI drives.
  • Full Disk Encryption does not support eDrive drives for Windows 8 or later environments.
Hard disk controllers
  • Software encryption: ATA, AHCI, or IRRT hard disk controller
  • Hardware encryption: AHCI hard disk controller
Other softwareMicrosoft .NET Framework 3.5 SP1(Windows 7 and later operating systems)
 
Full Disk Encryption is not compatible with other versions of the Microsoft .NET Framework.
 

Trend Micro recommends checking if the endpoint is compatible. For the Pre-Install checklist, you may refer to this article:
https://success.trendmicro.com/solution/KA-0007514

For the list of compatible SED, you may refer to this article:
https://success.trendmicro.com/solution/KA-0006199

For the list of compatible Network Cards, you may refer to this link:
https://success.trendmicro.com/solution/KA-0006309

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
RAM1 GB
Disk space
  • 30 GB
  • 20% free disk space
Network connectivityCommunication with PolicyServer required for managed agents
Operating system
  • Windows™ 10 (32-bit/64-bit)
  • Windows™ 8.1 (32-bit/64-bit)
  • Windows™ 8 (32-bit/64-bit)
  • Windows™ 7 (32-bit/64-bit)
Other software
  • Microsoft .NET Framework 3.5 SP1 (Windows 7 and later operating systems)
  • Microsoft Windows Installer 3.1

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
Memory
  • 512 MB minimum
  • 2 GB recommended
Disk space400 MB minimum
Network connectivityConnectivity with PolicyServer
Operating system
  • OS X™ "Big Sur"
  • OS X™ "Catalina"
  • OS X™ "Mojave"
  • OS X™ "High Sierra"
  • OS X™ "Sierra"
  • OS X™ "El Capitan"
Other software
  • Mono runtime environment (MRE)
  • Apple FileVault is disabled
Hardware considerations
  • Mac OS local accounts or mobile accounts are able to initiate encryption on Mac OS X Mountain Lion or later. Other Mac OS user account types will be unable to initiate encryption.
    To create a mobile account for Active Directory on your Mac, see Creating a Mobile Account for Active Directory on Mac OS.
  • Encryption Management for Apple FileVault supports Apple Fusion Drives on Mac OS X Mountain Lion or later (starting with Mac OS build 10.8.2).

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
RAMRequirements are the based on Windows system requirements:
  • 64-bit systems: 2 GB
  • 32-bit systems: 1 GB
Disk space
  • 30 GB
  • 20% free disk space
Hard diskStandard drives supported by Windows
 

Encryption Management for Microsoft BitLocker installation is only supported on endpoints with 1 physical hard disk drive (multiple partitions are supported).

Encryption Management for Microsoft BitLocker can’t support when the system partition is not the first partition of the disk.

 
Network connectivityConnectivity with PolicyServer
Operating System
  • Windows™ 11 Enterprise and Professional editions (64-bit)
  • Windows™ Embedded POSReady 7 (32-bit/64-bit)
  • Windows™ 10 Enterprise and Professional editions (32-bit/64-bit)
  • Windows™ 8.1 Enterprise and Professional editions (32-bit/64-bit)
  • Windows™ 8 Enterprise and Professional editions (32-bit/64-bit)
  • Windows™ 7 Enterprise and Professional editions (32-bit/64-bit)
Other software
  • Trusted Platform Module (TPM) 1.2 or higher
  • Full Disk Encryption is not installed
  • Microsoft .NET Framework 3.5
 
Full Disk Encryption is unable to install on SED disks attached to devices using UEFI if these disks were previously managed by Windows Bitlocker. To install Full Disk Encryption on these disks, perform one of the following:
  • Configure Full Disk Encryption to use software-based encryption by adding the FORCESOFTWARE parameter during installation.
    >For details, see the "Installing the Full Disk Encryption Agent" section in the Endpoint Encryption Installation Guide.
  • Restore the SED disk back to its factory setting. This procedure removes all existing data from the SED disk. After the disk has been restored, try running the installer again.