Apex One as a Service enables support for TLS 1.0/1.1/1.2 protocols. This is to maintain agent to server communication for older Windows platforms (that does not natively support TLS 1.2) such as:
- Windows 7
- Windows 2008 R2
Users should have Microsoft OS ESU installed since Microsoft ended support for Windows 7 and Windows Server 2008 R2. For more information, refer to the KB article: Matrix of supported Windows OS and support dates for Apex One/OfficeScan.
For additional information, refer to this MS article: Solving the TLS 1.0 Problem, 2nd Edition.
We recommended using TLS 1.2 when possible, with TLS 1.1 as a fallback. TLS 1.0 should only be used when TLS 1.1 and 1.2 are absolutely not available. For more information, refer to the KB article: PCI Data Security Standard (DSS) 3.1 compatibility with OfficeScan/Apex One.
If users no longer need Apex One as a Service to manage these OS, you can file a case with Trend Micro Technical Support to disable TLS 1.0 & 1.1 on the Apex One as a Service server.