Overview

McAfee was founded in 1987, headquartered in San Jose, California, and is one of the earliest security companies in the world. McAfee is widely known for its consumer anti-virus software, but its enterprise portfolio is far broader — covering endpoint security (MVISION), data loss prevention (DLP), cloud access security broker (CASB), web security, and threat intelligence. In 2021, McAfee sold its enterprise business to a consortium led by Symphony Technology Group, subsequently splitting into two independent brands: Trellix (endpoint security, XDR, threat intelligence) and Skyhigh Security (cloud security, CASB, DLP).

Despite the brand restructuring, McAfee (now operating as Trellix + Skyhigh for enterprise) still maintains over 40 million endpoint licenses and 200,000+ enterprise customers globally, with a strong foothold in compliance-driven sectors such as finance, government, and healthcare. McAfee Global Threat Intelligence (GTI) processes over 30 million samples daily, providing the data foundation for protection rules.

Key Strengths

  • Single-agent endpoint security: MVISION uses a single-agent architecture integrating anti-virus, EDR, web control, and email protection, reducing multi-agent conflicts and system resource overhead. A single agent covers detection across 200+ techniques in the MITRE ATT&CK framework.
  • Comprehensive DLP coverage: McAfee DLP supports content inspection across five channels — endpoint, network, cloud storage, email, and web — with 1,000+ pre-built compliance policy templates (PII, PCI, HIPAA, GDPR) that significantly reduce policy configuration effort.
  • Cloud Access Security Broker (CASB): Skyhigh Security CASB covers 200+ SaaS and IaaS applications, providing shadow IT discovery, data classification, DLP policy orchestration, and anomaly behavior detection to mitigate data leakage risks from cloud application shadow usage.
  • Global threat intelligence network: McAfee GTI covers IP reputation, URL classification, file hashes, and behavioral indicators, processing 30M+ samples daily for real-time threat blocking in web gateway and email security scenarios.

Product Ecosystem

MVISION Unified Endpoint Security

MVISION is McAfee's (now Trellix) enterprise endpoint security platform, integrating anti-virus, endpoint detection and response (EDR), web control, email protection, and device control. MVISION uses a single-agent architecture with both cloud-based and on-premises management console options. The EDR module provides threat hunting capabilities based on the MITRE ATT&CK framework with automated incident response, supporting log aggregation and cross-layer correlation analysis with the Trellix XDR platform.

McAfee DLP (Data Loss Prevention)

McAfee DLP is one of the most comprehensive data leakage prevention solutions on the market, covering five transmission channels: endpoint, network, cloud storage (Office 365, Box, Google Drive, Salesforce), email, and web. It supports document fingerprinting, exact data matching (EDM), and regex-based multi-level content inspection. DLP events can be integrated with SIEM platforms such as Splunk and IBM QRadar through standard connectors.

Skyhigh Security (CASB + SSE)

Skyhigh Security delivers Cloud Access Security Broker (CASB) and Security Service Edge (SSE) capabilities across 200+ SaaS and IaaS applications. Core features include shadow IT discovery, sensitive data classification, DLP policy orchestration, anomaly behavior detection, and zero-trust network access (ZTNA). Skyhigh is particularly well-suited for enterprises with heavy investments in Salesforce, Office 365, ServiceNow, and AWS.

Trellix XDR

Trellix Extended Detection and Response (XDR) aggregates telemetry from endpoints, email, network, and cloud workloads to deliver cross-layer threat detection, automated incident response, and expert threat hunting services. Trellix XDR supports API integration with Splunk, ServiceNow, and Jira, making it suitable for security teams needing a unified SOC operations view.

Web and Email Security

McAfee Web Gateway provides URL filtering, malware blocking, SSL decryption, and application control. McAfee Email Gateway delivers anti-spam, anti-phishing, email DLP, and sandbox analysis. Both can integrate with MVISION and Trellix XDR platforms for end-to-end security protection.

Limitations

  • Brand restructuring uncertainty: The split into Trellix and Skyhigh has caused product roadmap disruption, with customers facing hidden costs of brand migration and learning new consoles. Some large accounts have migrated to CrowdStrike and Microsoft.
  • Consumer bundle bloat: The consumer edition includes trial promotion components with a complex uninstall process, generating widespread complaints. Enterprise edition installation is cleaner, but the brand image is still affected by the consumer product experience.
  • Cloud security market share gap: Skyhigh Security faces intense competition from Netskope and Microsoft Defender for Cloud Apps in the CASB market, with a lower positioning in the Gartner SSE Magic Quadrant compared to Netskope and Zscaler.
  • Endpoint protection competitive position: McAfee was a long-time Gartner MQ Leader for Endpoint Protection Platforms but was overtaken by CrowdStrike and Microsoft Defender for Endpoint after 2022, with a noticeable gap in innovation speed and cloud-native architecture.

Use Cases

  • Data leakage prevention compliance (★★★★★): McAfee DLP's five-channel coverage and 1,000+ compliance policy templates suit finance, government, and healthcare sectors facing PCI DSS, HIPAA, and GDPR data protection audits.
  • Cloud application security control (★★★★): Skyhigh CASB covers 200+ applications, ideal for organizations with extensive SaaS deployments needing shadow IT discovery and data classification.
  • Unified endpoint security deployment (★★★★): MVISION's single-agent architecture reduces operational complexity for organizations already in the McAfee ecosystem or upgrading from traditional anti-virus to EDR.
  • Consumer and home security (★★★): McAfee Total Protection offers multi-device coverage for households needing simple, unified protection, though bundled components during installation should be reviewed carefully.
  • XDR and threat hunting (★★★): Trellix XDR suits organizations with existing MVISION + DLP + Web/Email security investments looking to extend unified threat management. Greenfield XDR deployments should prioritize CrowdStrike or SentinelOne.

Pricing

Product Billing Model Reference Price
MVISION Endpoint Per endpoint/year $25–$60/endpoint/year (basic EDR included)
MVISION EDR Per endpoint/year $40–$90/endpoint/year
McAfee DLP Per endpoint/year $15–$40/endpoint/year
Skyhigh CASB Per user/month $5–$15/user/month
Web Gateway Per user/year $10–$30/user/year
Trellix XDR Per endpoint/year $60–$150/endpoint/year

Note: Prices above are estimated list prices. Trellix and Skyhigh are now independently priced; inquiries should be made separately. Enterprise bulk purchases typically receive 20%–40% discounts.

FAQ

  • What is the relationship between McAfee, Trellix, and Skyhigh? In 2021, McAfee sold its enterprise business. Enterprise endpoint security (MVISION), XDR, and threat intelligence are now under the Trellix brand. Cloud security (CASB, SSE) operates under Skyhigh Security. The McAfee brand is retained for consumer products. Enterprise customers are effectively using Trellix and Skyhigh products.2026 Cybersecurity Threat Landscape

  • How well does McAfee DLP integrate with Office 365? McAfee DLP supports content inspection across Office 365 email, OneDrive, SharePoint, and Teams, with DLP policy orchestration enabling automatic classification and blocking of sensitive data. However, native Microsoft Purview DLP offers deeper integration depth; a hybrid deployment approach is recommended.Data Protection and Compliance Checklist

  • Skyhigh CASB vs Netskope — which is better? Skyhigh's advantage is seamless policy orchestration with existing McAfee DLP investments, making it ideal for organizations with pre-existing McAfee data protection deployments. Netskope excels in SSE platform integration, real-time inline inspection, and a unified cloud security experience — recommended for greenfield cloud security evaluations.Cloud Server Security Configuration Guide

  • What are the benefits of MVISION's single-agent architecture? A single agent eliminates performance conflicts and resource contention caused by running separate agents for anti-virus, EDR, web control, and email protection on enterprise endpoints. MVISION's single agent covers all these functions with a measured performance impact of 3%–5%.Website Security Hardening Guide

  • Are McAfee consumer and enterprise management consoles unified? No. Consumer products are managed through the McAfee website account portal. Enterprise products use Trellix ePO (endpoint policy management) or Skyhigh cloud console. The two are not interconnected; enterprise customers should use Trellix ePO or Skyhigh console directly.Website Security Checklist