What is our primary use case?
The use cases for
McAfee ePolicy Orchestrator involve deploying multiple customers for endpoint solutions, EPP solutions, and creating credential dumping in the customer environment. We find Trellix blocks credential dumping. We have to download and create the .icar file in the customer environment, and there are malware phones we address. We are blocking suspicious URLs from web control and controlling applications through application control, as well as blocking removal drives from device controls, and utilizing
Trellix DLP.
What is most valuable?
The advantages of
McAfee ePolicy Orchestrator include being a centralized management console, which we possess when managing multiple solutions in
Trellix DLP and EPP through the EPO solution.
Automated responses, such as XDR, have significantly impacted our security posture. XDR detects from the telemetry data from the agents, correlates threats, and provides us with detections and threat insights through XDR, allowing us to create playbooks for the response.
What needs improvement?
Some drawbacks include difficulty in supporting improvements because we don't get proper response from Trellix support, so there is a need to improve the support.
In using McAfee ePolicy Orchestrator as an on-premise solution, we face challenges such as login issues and stopped services, where Trellix does not provide prompt responses. They request time for logs for analysis, and after about 10 to 11 days, this ticket was finally closed.
For how long have I used the solution?
I have been working with McAfee ePolicy Orchestrator for around seven years.
What was my experience with deployment of the solution?
Regarding installation, we have multiple types of deployment of the agent, both manually and remotely, where we receive URLs for downloading the agent and installing it from the McAfee ePolicy Orchestrator solution.
What do I think about the stability of the solution?
McAfee ePolicy Orchestrator is stable without latency; however, we are experiencing slowness issues on the user end after using the EPP solution.
When we enable all modules of EPP, such as Endpoint Security, application control, and web control, we encounter slowness. If we only install components such as Endpoint Security or web control, there isn't a slowness issue. We observe that enabling application control leads to slowness.
What do I think about the scalability of the solution?
We are not facing any limitations with the scalability of McAfee ePolicy Orchestrator.
How are customer service and support?
I would rate the quality of support from Trellix as eight points.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have used solutions similar to McAfee ePolicy Orchestrator, including deploying Trend Micro solutions and using CrowdStrike.
How was the initial setup?
There isn't much maintenance required. We continuously upgrade the version of McAfee ePolicy Orchestrator for the latest one, and there is no maintenance mode we need to go into. We back up existing versions, download from the portal, and install during the upgrade process.
Which other solutions did I evaluate?
In comparison to Trend Micro and CrowdStrike, I believe CrowdStrike is the number one solution from Trellix, while Trellix is above Trend Micro.
CrowdStrike is overall better due to its lightweight agent, which does not cause slowness issues, and it offers a signature-less solution.
What other advice do I have?
The only deployment model I am using is on-premises; I don't have a cloud solution.
I am not sure if the solution is affordable or a bit expensive since I am a technical person and don't directly handle pricing.
I have not seen any AI integrations into McAfee ePolicy Orchestrator.
I would rate McAfee ePolicy Orchestrator as eight points; it is a good solution, considering my seven years of experience with Trellix, although we do face some challenges such as user-end slowness issues. Otherwise, I am not facing any major issues with the EPO.
Which deployment model are you using for this solution?
On-premises