Fix it now
ESET PROTECT Entry is the cheapest way into ESET’s managed range. What you buy is the console plus endpoint and file server protection: ESET documents PROTECT as managing ESET applications on workstations and servers, up to 50,000 devices, and its published tier table puts endpoint security for Windows, macOS and Linux, ESET Server Security for Windows Server and Linux, device control and anti-phishing in Entry.
- Buy it if you have anything from a handful to a few dozen machines and currently no central view of any of them. That view is the product.
- Buy it if you need to show, on demand, that every device is protected and current. Consumer licences cannot produce that and business licensing is not optional.
- Buy it if you have file servers. ESET’s tier table puts ESET Server Security for Windows Server and for Linux in Entry rather than in an upsell.
- Skip it if what you actually need is encryption, patch management or mail protection. ESET Full Disk Encryption starts at PROTECT Advanced, and Vulnerability and Patch Management, mail security and ESET Inspect start at PROTECT Complete.
- Skip it if nobody will ever log in. A console that nobody opens is a more expensive way to buy an unmanaged estate.
- Skip it if you have five devices, no server and no reporting obligation. ESET Small Business Security is the smaller-shaped product and it is managed through ESET HOME.
ESET publishes the tier matrix on its support site, so the component split is checkable rather than a matter of trust. What it does not publish is any minimum seat count or term, so those still belong on the quote.
If a central console is the thing you are missing, that is the decision made. Below is what the console actually does, what the rollout looks like, and what has changed in ESET’s licence administration.
Why it happens
The question a small business should ask about the bottom of a managed range is not whether the detection is any good. It is how much of the management story survives the price cut. With ESET the answer is straightforward, because the console is not tiered: ESET documents ESET PROTECT as a platform for managing ESET applications on workstations and servers in a networked environment with up to 50,000 devices from one central location. That is the same console regardless of which subscription you hold. What the subscription decides is which protection components your licence permits, not whether you can manage them.
What the console does is also documented rather than inferred. ESET describes the web console as turning extensive information into clear dashboards and reports, applying security policies across managed devices, carrying out tasks on agents and applications, and tracking system health on remote computers. An Active Directory Scanner is one of the platform’s components, which is the piece that keeps your machine list aligned with a directory you already maintain rather than a second list you have to remember to update.
The tier matrix is published, on ESET’s own support site, and it is worth reading before anyone quotes you. Entry covers ESET Endpoint Security and ESET Antivirus Security for Windows, ESET Endpoint Security for macOS, ESET Endpoint Antivirus for Linux, ESET Server Security for Windows Server and for Linux, device control and anti-phishing. It does not cover ESET Full Disk Encryption, which starts at Advanced alongside ESET LiveGuard Advanced and ransomware remediation, and it does not cover Vulnerability and Patch Management, ESET Inspect, mail security or ESET Cloud Office Security, which start at Complete. Tier contents in this market do move between product generations, so check that table against the version of it you are quoted from rather than against a comparison chart on somebody else’s site.
You have machines and no idea what is on them
You have this one if Antivirus was installed one machine at a time by whoever set each one up, and nobody could say today which are current.
- This is the problem the console solves, and it solves it at the bottom tier as well as the top.
- Dynamic grouping, policy application and scheduled reporting are console functions, not subscription features.
- Set the scheduled report to arrive by email for the person who will never log in. That single habit is most of the value.
Somebody has started asking for evidence
You have this one if A client questionnaire, an insurer or a contract now asks how your endpoints are managed and whether they are current.
- A console report is evidence. A per-machine screenshot is not, and neither is a promise.
- Confirm on the quote that the reporting you need is in the tier you are buying, because reporting is a console function but the data it reports on depends on which components are licensed.
- Build the answer before the deadline, not during it.
You are running consumer licences in a business
You have this one if Five or ten office machines with home antivirus on them because it was cheaper and nobody wanted to learn a console.
- The licensing problem is the first and sufficient reason to change, ahead of any technical argument.
- If the estate is genuinely tiny and static, ESET Small Business Security is the smaller-shaped answer and is managed through ESET HOME.
- If anyone will ever ask for proof, or the estate is growing, go straight to PROTECT and spend the afternoon on the console.
The honest cost of this product is the console’s depth. Policies, inheritance and task triggers are genuinely capable and they are also more concepts than a small business expects to meet in order to switch on antivirus. Budget an afternoon on policies and inheritance specifically, because a policy applied at the wrong level is the most common reason a setting appears not to take effect and the hardest thing to diagnose from the machine’s end.
Full reference
What the console does, from ESET’s own description
| Capability | What ESET documents |
|---|---|
| Scope | Manages ESET applications on workstations and servers in a networked environment, up to 50,000 devices, from one central location |
| Visibility | Converts extensive information into clear dashboards and reports |
| Policy | Applies security policies across managed devices |
| Tasks | Carries out commands on agents and applications |
| Monitoring | Tracks system health on remote computers |
| Directory | An Active Directory Scanner is a component of the platform |
Two practical points follow from that list. The first is that hosted and on-premises are a decision about where the data lives and who patches the server, not about what the console can do. The second is that the 50,000-device ceiling tells you something useful even at ten machines: nothing about this platform is going to run out of room, so the reasons to move to a different product later will be about components, not about scale.
Licence administration has moved
If you have used ESET business licensing before, one thing has changed and it is worth knowing before you go looking for a portal that is no longer the one to use. ESET states that ESET Business Account is being phased out and that all licence management moves to its successor, ESET PROTECT Hub, with customers notified roughly two weeks before their own transition. In practice that means a description of the licence portal written a year ago will not match what you sign in to, and any instruction that starts by telling you to go to ESET Business Account should be checked before you follow it.
The capability that matters for a business with more than one site is still there: seats from one subscription can be shared among sites, which is how a branch office or a managed service provider sees only its own devices. Confirm which portal you will actually be administering on, because that is the thing that has moved.
A realistic first week
- Create the console, secure the administrator account, and add a second administrator so one lost phone does not lock you out of your own estate.
- Take a pilot group of three or four machines that between them run every important application you have.
- Deploy the agent to the pilot and watch what happens to the incumbent security product. A clean removal makes this a day; a stubborn one adds a scripted removal to every machine.
- Run the pilot on real work for a few days and write down every block that turned out to be legitimate.
- Apply the exclusions, then roll out in batches, confirming each batch reports in before starting the next.
- Add servers deliberately rather than assuming they were included, and set a scheduled report to email whoever will not log in.
The window in which the old product has been removed and the new agent has not yet started is the only genuinely dangerous part of this project. Migrate in batches, make sure the reboot happens promptly, and never uninstall the incumbent product across the whole estate in advance.
Counting what you are licensing
Seats are devices, not people. A user with a desktop, a laptop and a company phone is three of them, and a file server is another. Build the number from an inventory rather than a headcount, and put the servers on the list before you ask for a price rather than after. No minimum seat count or term length is published on any ESET page reachable for this review, so if a minimum applies to you it will come from the quote, which is the right place for it to come from.
What happens if the subscription lapses
On the Windows side this is documented by Microsoft rather than by ESET, and it is worth knowing. Microsoft Defender Antivirus automatically re-enables itself when a third-party antivirus expires, is uninstalled, or stops providing real-time protection. So a lapsed estate does not go bare, but it does quietly stop being a managed estate: the console keeps showing you machines it can no longer report accurately on, and the policies you built are no longer the thing deciding what happens. Diary the expiry and renew before it rather than after.
Who should be buying something else
- You need managed disk encryption: that is PROTECT Advanced, where ESET Full Disk Encryption and ESET LiveGuard Advanced first appear. Buying Entry and adding it later is the expensive version of this decision.
- You need vulnerability and patch management, mail security or EDR: that is PROTECT Complete, where Vulnerability and Patch Management, ESET Mail Security, ESET Cloud Office Security and ESET Inspect first appear.
- You have five machines, no server and nobody asking for evidence: ESET Small Business Security is the smaller product, managed through ESET HOME.
- You have a Windows server and want it covered specifically: ESET sells ESET Safe Server for that, so name every server on the quote.
- Nobody will read anything the console produces: buy through a provider who will, or accept that you are paying for visibility you are not using.
When a licence is the actual fix
ESET PROTECT Entry is the licence that turns separately installed copies of an antivirus into an estate you can see, and the console is the same product at every tier – ESET documents it as managing up to 50,000 devices from one place. Arco supplies ESET PROTECT licences, will size the seat count from your actual device list including servers, and will put the component list for the tier on the order rather than leaving you to match ESET’s published tier table against a comparison chart. If encryption or patch management is the real reason you are shopping, we will quote PROTECT Advanced or PROTECT Complete respectively rather than selling you the cheapest tier and a migration in six months. And if your estate is five machines with no server and nobody asking for evidence, we will quote ESET Small Business Security instead.
Questions people ask about this
Can a business just buy consumer licences for each PC?
It is cheaper per device and wrong twice over. Consumer licensing is not business licensing, which is the first and sufficient reason. And it leaves you with no central policy, no reporting and no way to demonstrate that a machine is protected – which is the entire product here. ESET documents the PROTECT console as the thing that manages applications on workstations and servers from one location, and that is what you are paying for.
Does Entry include patch management or disk encryption?
Neither. ESET’s published protection tier table puts ESET Full Disk Encryption at PROTECT Advanced and Vulnerability and Patch Management at PROTECT Complete, along with ESET Inspect, ESET Mail Security and ESET Cloud Office Security. What Entry does carry is endpoint protection for Windows, macOS and Linux, ESET Server Security for Windows Server and Linux, device control and anti-phishing. If encryption or patching is why you are shopping, price the tier that contains it rather than the cheapest one.
Cloud console or on-premises?
For almost every small business, hosted: there is no server for you to build, patch or back up, and remote machines report without a VPN. Choose on-premises when data residency rules or an isolated network make it necessary, and accept that you now own a server. ESET documents the same console capabilities either way, so this is a question about where the data lives, not about what you can do.
Where do I administer the licence now?
Check before you follow an old instruction. ESET states that ESET Business Account is being phased out and that all licence management moves to ESET PROTECT Hub, with about two weeks’ notice before your own account transitions. The capability that matters for a multi-site business survives the move: ESET documents sharing licence seats among sites, which is what a branch office needs.
What happens when the licence expires?
On Windows, Microsoft documents that Defender Antivirus automatically re-enables when a third-party antivirus expires, is uninstalled or stops providing real-time protection. So the machines are not bare – but they are no longer running the product your policies describe, and your console reports become fiction. Diary the renewal date.
