Views:

Rebranding Applies to the Following TrendAI Vision One™ Endpoint Security Agents

Deep Security Agent (build 20.0.3.14910 or later) deployed under:

  • Cloud One – Endpoint and Workload Security
  • Deep Security
  • Server and Workload Protection

Apex One Security Agent (Build 14.0.20842 or later) deployed under:

  • Apex One as a Service
  • Vision One Standard Endpoint Protection

Rebranding Rollout

The TrendAI™ branding update for TrendAI Vision One™ Endpoint Security agents is being introduced progressively:

  • The agent console UI began reflecting the updated TrendAI™ branding with the March 2026 rollout. Additional agent component updates are scheduled to be deployed starting June 2026.
  • As updates are applied over time, endpoints may display different branding states during the transition period.
  • Deep Security Agent (DSA): The display name change from "Trend Micro Deep Security Agent" to "TrendAI™ Deep Security Agent" was introduced in build 20.0.3.14910 (June 2026). Customers on earlier DSA builds will not see the updated branding until they upgrade.

Expected Behavior During Rollout

During the phased rollout, variations in branding may be observed across endpoints. For example:

  • Endpoints within the same environment may display different branding depending on their current update status. Updated branding will appear gradually as additional agent updates are applied over time.
  • These variations are expected during the rollout period and do not indicate an issue with the agent.

For DSA-based products (C1WS / DS / SWP): A known display-only defect exists in DSA build 20.0.3.14910 where the trademark symbol ™ (Unicode U+2122) in the new product name renders as the literal string "2122" in the Notifier tray application (showing "TrendAI2122 Deep Security2122"). This is cosmetic only and does not affect agent protection or functionality. A fix will be delivered in a future DSA build.

What You Need to Do

Endpoint agents will automatically reflect the updated branding as updates are applied. However, if your environment uses third-party network access control (NAC), VPN, or endpoint posture solutions, additional action may be required to prevent endpoints from being flagged as non-compliant.

Take the action that corresponds to your posture solution:

Cisco ISE: Update your ISE posture policy to recognize "Apex One Security Agent" as the display name and/or the updated agent service name. Retaining the previous entry ("Trend Micro Apex One Security Agent") alongside the new one ensures coverage for endpoints on either build during the transition period.

Palo Alto Networks GlobalProtect (via OPSWAT): Apply the latest OPSWAT definition file on the GlobalProtect side. The updated file maps the new "Apex One" product name and restores compliant detection.

F5 BIG-IP Edge Client (via OPSWAT): Apply the OPSWAT definition file dated June 15, 2026, or later on F5 BIG-IP. This version has been confirmed to resolve the AV-compliance check failure.

TrendAI™ Zero Trust Secure Access (ZTSA): Upgrade ZTSA to v2.35.1036 or later. This release restores correct recognition of the Security Agent.

Controlling the timing of agent upgrades (optional): Apex One as a Service agents upgrade to the latest maintenance build automatically by default. If you wish to control upgrade timing, you can pin or freeze the agent version using the Program Update policy setting. Refer to knowledge article KA-0014555 for step-by-step instructions. Note that the Apex One SaaS agent does not support one-click rollback; managing upgrade timing via policy is the recommended approach.

 
Note: OPSWAT catalog updates to recognize the new TrendAI™ Deep Security Agent product name are currently in progress. The target completion is within three weeks of this publication. Once released, the updated catalog files will be distributed to downstream technology partners through the standard OPSWAT distribution process.

Take the action that corresponds to your posture solution:

Cisco ISE: Update your ISE posture policy to recognize "TrendAI Deep Security Agent" as the display name and/or the updated agent service name. Retaining the previous entry ("Trend Micro Deep Security Agent") alongside the new one ensures coverage for endpoints on either build during the transition period.

Palo Alto Networks GlobalProtect (via OPSWAT): Apply the updated OPSWAT definition file on the GlobalProtect side once it is available (catalog update in progress; see note above). In the interim, you can restore VPN access by modifying your GlobalProtect HIP match object to use a process-based check — for example, verify that ds_agent.exe is running — instead of a product-name string match. This interim change does not reduce security posture because the agent is still running and protecting the endpoint.

F5 BIG-IP Edge Client (via OPSWAT): Apply the updated OPSWAT definition file on F5 BIG-IP once it is available (see note above for timeline).

TrendAI™ Zero Trust Secure Access (ZTSA): Upgrade ZTSA to v2.35.1036 or later. This release restores correct recognition of the Deep Security Agent.

Controlling the timing of agent upgrades (optional): Cloud One Workload Security (C1WS) and Vision One Server and Workload Protection (V1ES/SWP) agents can be managed through their respective update policy settings. If you wish to defer the 20.0.3.14910 build while awaiting the OPSWAT catalog update, configure the update policy in the console accordingly. Note that this agent line is designed for forward-only upgrades; version pinning via policy is the recommended approach.

If you are not using any of the above solutions and have not observed VPN or network access issues, no action is required.

Comments (0)