Views:

Understand the full requirements and limitations for updating to TrendAI Vision One™ Endpoint Security agents with Standard Endpoint Protection.

What are the platform requirements?
Your environment must meet the following criteria:
  • You must have the upgraded TrendAI Vision One™ for Service Providers console with the following modules:
    • Licensing Management Platform (LMP)
    • Remote Manager (RM)
  • Managed customers with an active Worry-Free Services Standard or Advanced license. Support for other license types is coming soon.
  • Managed customers have the TrendAI Vision One™ console provisioned.
  • Your TrendAI Vision One™ for Service Providers account has the Master Administrator role or a custom role with the Update Worry-Free agents permission enabled. If you do not have this permission, the function might not be visible to your account and you cannot start the update.
  • Target endpoints appear in TrendAI Vision One™ for Service Providers Endpoint Inventory and have the Worry-Free Services agent installed.
    • You cannot update Worry-Free agents from the customer's TrendAI Vision One™ console Endpoint Inventory.
    • Worry-Free Business Security On-Premises is not supported.
What are the endpoint requirements?
Your customers' endpoints must meet the following:
  • Worry-Free Services Security Agent must be online and updated to the minimum supported agent version or later. Offline agents start the update process as soon as they reconnect.
  • Migration for Windows requires the Worry-Free Services Security Agent version 6.7.4082 or later. Updating supports both desktop and server versions of Windows.
  • Migration for macOS requires the Worry-Free Services Security Agent version 3.7.2050 or later.
  • The endpoint must also have the TrendAI Vision One™ base agent program installed and appear in the TrendAI Vision One™ for Service Providers Endpoint Inventory.
  • The endpoint must meet the minimum requirements for Standard Endpoint Protection. For more information, see Standard Endpoint Protection system requirements.
Do I need to reconfigure the security settings and permissions for the updated agent on macOS endpoints?
Security settings and permissions for the security agent and extensions are retained during the update. You do not need to configure permissions for any feature that is enabled before updating, including Endpoint Sensor to XDR for Endpoints (EDR). If Endpoint Sensor is disabled before the update, and you enable XDR for Endpoints (EDR) afterward, you will need to configure permissions in that scenario.
Which policies are migrated from Worry-Free to Standard Endpoint Protection?
If you choose to migrate policy settings, only the Device (Default) groups for both Windows and Mac policies are migrated. Custom policy groups are not migrated. Some settings are migrated into Policy Resources. The migration is not one-to-one due to feature differences. For more information, see:
What are some limitations to updating?
The following limitations apply:
  • You can only update endpoints for one customer at a time.
  • You can select a maximum of 200 endpoints to update at a time.
  • Logs collected by Worry-Free Services are not transferred to Standard Endpoint Protection.
Can I revert or rollback the update after starting the process?
No, it is a Permanent Update: Once the update begins, the process cannot be paused or reversed. The Worry-Free agent will be automatically removed and replaced with the new TrendAI Vision One™ Endpoint Security agent.
What happens to the Worry-Free license after updating?
Updated agents no longer use the Worry-Free license and instead use TrendAI Vision One™ credits for billing. Certain feature configurations might affect your credit requirement and agent configuration based on which feature licenses are active.
  • If Endpoint Sensor is ON and you have an active IES License that is not expired, then XDR for Endpoints (EDR) is automatically enabled. The credit requirement for your agents is based on which feature package you are using.
  • If Sample Submission is ON and you have an active SO License that is not expired, then Sandbox Analysis is automatically enabled.
How do I update Worry-Free Services Security Agents?
How long does the update process take?
The update process might take up to 30 minutes to complete. The length of the process depends on factors such as the number of endpoints in your customer's environment, connectivity, and system health.
What if an endpoint is offline or not connected during the update?
The update request is a persistent command with no timeout. When the agent reconnects, it will start the update process.
What does the update process and flow look like?
The update flow for the agent uses the following steps:
  1. Update command received
  2. CID matched
  3. Task started
  4. API returned 200
  5. Download completed
  6. Unzip completed
  7. Uninstall Endpoint Sensor
  8. Install agent program (basecamp)
    1. Unregister Worry-Free agent
    2. Install Endpoint Sensor
    3. Uninstall Worry-Free agent
    4. Install Standard Endpoint Protection features
  9. Unregister from Worry-Free completed
  10. Block communication with Worry-Free server
How do I confirm if the update is successful?
There are two ways to confirm a successful update:
  • In Endpoint Inventory, the agent's protection manager shows the Standard Endpoint Protection instance selected to manage the endpoint during the update process.
  • On the endpoint, the Worry-Free Services Security Agent console is replaced by the TrendAI Vision One™ Endpoint Security agent interface.