Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Trend Micro Endpoint Encryption 6.0 Patch 1 Requirements and Compatibility Matrix

    • Updated:
    • 19 Jan 2021
    • Product/Version:
    • Endpoint Encryption 6.0
    • Platform:
    • N/A
Summary

This article covers the compatibility matrix and the system requirements for the following Trend Micro Endpoint Encryption Products.

  • PolicyServer
  • Full Disk Encryption
  • File Encryption
  • Encryption Management for Microsoft Bitlocker
  • Encryption Management for Apple Filevault
Details
Public
Operating System
Endpoint EncryptionWindows
Server 2008
Windows
Server 2008 R2
Windows
Server 2012
Windows
Server 2012 R2
Windows
Server 2016
Windows
Server 2019
Windows XPWindows 7Windows 8Windows 8.1Windows 10Mac OSX
Policy Server
PolicyServerMMC
Full Disk Encryption
File Encryption
Encryption Management for Microsoft Bitlocker
Encryption Management for Apple Filevault

Windows Compatibility

  • Version 1607 (Anniversary Update)
  • Version 1703 (Creators Update)
  • Version 1709 (Fall Creators Update)
  • Version 1803 (April 2018 Update)
  • Version 1809 (October 2018 Update)
  • Version 1903 (May 2019 Update)
  • Version 1909 (November 2019 Update)
  • Version 2004 (May 2020 Update)
  • Version 20H2 (October 2020 Update)

Mac OSX Compatibility

  • OS X™ "Big Sur" - TBA
  • OS X™ "Catalina"
  • OS X™ "Mojave"
  • OS X™ "High Sierra"
  • OS X™ "Sierra"
  • OS X™ "El Capitan"

Hardware and Scaling Requirements

The following shows deployment and scaling requirements in several different-sized environments. In smaller network environments, PolicyServer SQL databases can be installed on the same server. For PolicyServer deployments in environments greater than 1500 devices, Trend Micro recommends having at least two dedicated servers:

  1. A dedicated server for the PolicyServer services, also known as the "front-end server"
  2. A dedicated server for the database, or add the database to an existing SQL cluster

The following table displays the requirements for the PolicyServer SQL database for the basic requirements at the specified scale:

DevicesPolicy Server Front-end RequirementsPolicy Server SQL Database Requirements
1,000
  • One front-end and SQL database multi-role server with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 120 GB hard drive
Installed on PolicyServer front-end server
4,000
  • One front-end and SQL database multi-role server with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 150 GB hard drive
Installed on PolicyServer front-end server
8,000
  • Two front-end servers each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • One SQL database server with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 150 GB hard drive
20,000
  • Four front-end servers each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL database servers (one for the policy database and one for the log database) each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 8 GB RAM
  • 180 GB RAID 5 hard drive
40,000
  • Eight front-end servers each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL database servers (one for the policy database and one for the log database) each with an Intel Xeon quad-core 2.2 GHz processor or above
  • 16 GB RAM
  • 350 GB shared SAN RAID 5 hard drive
 
  • Virtual hardware is supported under VMware Virtual Infrastructure.
  • Microsoft or VMware on virtual hardware does not support Microsoft Cluster Service.
  • Baseline testing was performed on an endpoint with an Intel Xeon CPU E5-2650 v4 2.20 GHz, 2200 Mhz.
 

Redundancy Requirements

With larger environments, Trend Micro recommends adding additional servers to avoid having single points of failure. The following table displays the requirements for the PolicyServer SQL database for an environment with increased redundancy.

DevicesPolicy Server Front-end RequirementsPolicy Server SQL Database
With Zero Points of Failure
8,000
  • Four front-end servers each with one Intel Xeon quad-core 2.2 GHz processor or above
  • 4 GB RAM
  • 40 GB hard drive
  • One SQL server cluster of two nodes, with Intel Xeon quad-core 2.2 GHz processors or above
  • 8 GB RAM
  • 60 GB RAID 5 hard drive
  • 150 GB shared SAN RAID 5 hard drive
20,000
  • Six front-end servers each with Intel Xeon quad-core 2.2 Ghz processors or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL server clusters of two nodes , with Intel Xeon quad-core 2.2 Ghz processors or above
  • 8 GB RAM
  • 60 GB RAID 5 hard drive
  • 180 GB shared SAN RAID 5 hard drive
40,000
  • Twelve front-end servers each with Intel Xeon quad-core 2.2 GHz processors or above
  • 4 GB RAM
  • 40 GB hard drive
  • Two SQL server clusters of two nodes , with Intel Xeon quad-core 2.2 Ghz processors or above
  • 16 GB RAM
  • 60 GB RAID 5 hard drive
  • 350 GB shared SAN RAID 5 hard drive

Software Requirements

SpecificationRequirements
Database server
  • Microsoft SQL Server 2008 / 2008 R2 / 2012 / 2012 R2 / 2014 / 2016 / 2017 / 2019
  • Microsoft SQL Server Express 2008 / 2012 / 2014 / 2016 / 2017 / 2019
  • Mixed Mode Authentication (SA password) installed
  • Reporting services installed
  • Note: For Windows Server 2008 R2, you must install SQL Server 2008 SP1.
Application server

PolicyServer 6.0 Patch 1 requires Microsoft Internet Information Services (IIS) with the following roles installed and enabled:

  • Application Development
    • ASP.NET
    • ASP
    • ISAPI Extensions
    • ISAPI Filters
  • Management Tools
    • IIS Management Console
    • IIS Management Scripts and Tools
    • Management Service
    • IIS 6 Management Compatibility
    • IIS 6 Metabase Compatibility

For Windows Server 2008 and 2008 R2 you must install the "Application server" role and the "Web server" role. Additionally, you must add SMTP and Microsoft IIS Support features.

Legacy Endpoint Encryption environments (version 3.1.3 and earlier) require Client Web Service. If you install Client Web Service on a remote endpoint, install Microsoft IIS on that endpoint.

Other software
  • Both Microsoft .NET Framework 2.0 SP2 (or 3.5) and 4.0
  • Windows Installer 4.5 (SQL Express)
 
  • For SQL Server:
    • Mixed Mode Authentication (SA password) installed and Reporting services installed
  • For Application Server:
    • On Windows Server 2008 and 2008 R2 you must install the "Application server" role and the "Web server" role. Additionally, you must add SMTP and Microsoft IIS Support features.
    • Legacy Endpoint Encryption environments (version 3.1.3 and earlier) require Client Web Service. If you install Client Web Service on a remote endpoint, install Microsoft IIS on that endpoint.
 

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
RAM1 GB
Disk space
  • 30 GB
  • 20% free disk space
  • 256 MB contiguous free space
Network connectivityCommunication with PolicyServer required for managed agents
Operating system
  • Windows™ Embedded POSReady 7 (32-bit/64-bit)
  • Windows™ 10 (32-bit/64-bit)
     
    Older builds of Windows 10 installed on endpoints where UEFI is enabled may encounter issues if secure boot is turned on. To prevent this issue, install all service packs, hotfixes and security patches for Windows 10 before proceeding with the installation.
     
  • Windows™ 8.1 (32-bit/64-bit)
  • Windows™ 8 (32-bit/64-bit)
  • Windows™ 7 (32-bit/64-bit)
Windows 10 Version Compatibility
  • Version 1607 (Anniversary Update)
  • Version 1703 (Creators Update)
  • Version 1709 (Fall Creators Update)
  • Version 1803 (April 2018 Update)
  • Version 1809 (October 2018 Update)
  • Version 1903 (May 2019 Update)
  • Version 1909 (November 2019 Update)
  • Version 2004 (May 2020 Update)
  • Version 20H2 (October 2020 Update)
Hard disk

Full Disk Encryption uses software-based encryption for all standard drives (drives without self-encryption).

Full Disk Encryption uses hardware-based encryption for the following self-encrypting drives (SEDs):

  • Seagate OPAL and OPAL 2 drives
  • SanDisk self-encrypting (OPAL2) solid-state drives
  • Toshiba self-encrypting (OPAL2) solid-state drives (SATA and NVMe)
  • Intel self-encrypting (OPAL2) solid-state drives (SATA and NVMe)

Full Disk Encryption has the following limitations:

  • Full Disk Encryption does not support RAID and SCSI drives.
  • Full Disk Encryption does not support eDrive drives for Windows 8 or later environments.
Hard disk controllers
  • Software encryption: ATA, AHCI, or IRRT hard disk controller
  • Hardware encryption: AHCI hard disk controller
Other softwareMicrosoft .NET Framework 3.5 SP1(Windows 7 and later operating systems)
 
Full Disk Encryption is not compatible with other versions of the Microsoft .NET Framework.
 

Trend Micro recommends checking if the endpoint is compatible. For the Pre-Install checklist, you may refer to this article:
https://success.trendmicro.com/solution/1117125-windows-pre-install-checklist-for-full-disk-encryption-fde-6-0#

For the list of compatible SED, you may refer to this article:
https://success.trendmicro.com/solution/1113630-self-encrypting-drive-compatibility-list-for-endpoint-encryption

For the list of compatible Network Cards, you may refer to this link:
https://success.trendmicro.com/solution/1113984-supported-network-card-list-in-endpoint-encryption

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
RAM1 GB
Disk space
  • 30 GB
  • 20% free disk space
Network connectivityCommunication with PolicyServer required for managed agents
Operating system
  • Windows™ 10 (32-bit/64-bit)
  • Windows™ 8.1 (32-bit/64-bit)
  • Windows™ 8 (32-bit/64-bit)
  • Windows™ 7 (32-bit/64-bit)
Other software
  • Microsoft .NET Framework 3.5 SP1 (Windows 7 and later operating systems)
  • Microsoft Windows Installer 3.1

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
Memory
  • 512 MB minimum
  • 2 GB recommended
Disk space400 MB minimum
Network connectivityConnectivity with PolicyServer
Operating system
  • OS X™ "Big Sur"
  • OS X™ "Catalina"
  • OS X™ "Mojave"
  • OS X™ "High Sierra"
  • OS X™ "Sierra"
  • OS X™ "El Capitan"
Other software
  • Mono runtime environment (MRE)
  • Apple FileVault is disabled
Hardware considerations
  • Mac OS local accounts or mobile accounts are able to initiate encryption on Mac OS X Mountain Lion or later. Other Mac OS user account types will be unable to initiate encryption.
    To create a mobile account for Active Directory on your Mac, see Creating a Mobile Account for Active Directory on Mac OS.
  • Encryption Management for Apple FileVault supports Apple Fusion Drives on Mac OS X Mountain Lion or later (starting with Mac OS build 10.8.2).

Software Requirements

SpecificationRequirements
ProcessorIntel Core 2 Duo 2.0 GHz processor or equivalent
RAMRequirements are the based on Windows system requirements:
  • 64-bit systems: 2 GB
  • 32-bit systems: 1 GB
Disk space
  • 30 GB
  • 20% free disk space
Hard diskStandard drives supported by Windows
 

Encryption Management for Microsoft BitLocker installation is only supported on endpoints with 1 physical hard disk drive (multiple partitions are supported).

Encryption Management for Microsoft BitLocker can’t support when the system partition is not the first partition of the disk.

 
Network connectivityConnectivity with PolicyServer
Operating
  • Windows™ Embedded POSReady 7 (32-bit/64-bit)
  • Windows™ 10 Enterprise and Professional editions (32-bit/64-bit)
  • Windows™ 8.1 Enterprise and Professional editions (32-bit/64-bit)
  • Windows™ 8 Enterprise and Professional editions (32-bit/64-bit)
  • Windows™ 7 Enterprise and Professional editions (32-bit/64-bit)
Other software
  • Trusted Platform Module (TPM) 1.2 or higher
  • Full Disk Encryption is not installed
  • Microsoft .NET Framework 3.5
 
Full Disk Encryption is unable to install on SED disks attached to devices using UEFI if these disks were previously managed by Windows Bitlocker. To install Full Disk Encryption on these disks, perform one of the following:
  • Configure Full Disk Encryption to use software-based encryption by adding the FORCESOFTWARE parameter during installation.
    >For details, see the "Installing the Full Disk Encryption Agent" section in the Endpoint Encryption Installation Guide.
  • Restore the SED disk back to its factory setting. This procedure removes all existing data from the SED disk. After the disk has been restored, try running the installer again.
 
Premium
Internal
Partner
Rating:
Category:
Deploy
Solution Id:
000283534
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.