New and Enhanced in Segmentation
Explore new features and learn about significant enhancements to existing features in Illumio Segmentation.
New and Enhanced, August 2026
First published on August 29, 2026
Feature | Summary |
|---|---|
Policy Advisor for the Platform | |
AI Agent Detection and Enforcement for VEN and PCE | Insights detects AI agent processes and surfaces them alongside your other workloads so security teams can see which agents are running, what they're reaching out to, and how their traffic moves through the environment. That turns a fast-growing blind spot into something you can investigate and understand the exposure before it becomes an incident. |
Illumio Segmentation / Insights – NDR Integration | Zeek runs on a sensor instance receiving a mirrored copy of a monitored workload’s traffic via AWS VPC Traffic Mirroring. When Zeek’s scan-detection logic raises a notice, a policy hook invokes a script that calls the Illumio PCE REST API, assigns a Quarantine label to the scanned workload and moves it to Full enforcement. The workload’s VEN applies the policy within seconds. Quarantine persists until explicitly released, via CLI, an operator console, or the Illumio UI. |
VEN on IoT Gateway – Visibility | VEN-on-IoT-Gateway extends Illumio Zero Trust Segmentation to IoT and other unmanaged devices that cannot host a software agent. Traditional IoT security approaches often separate device identification from policy enforcement, requiring organizations to use one platform to discover and classify devices and another to control communications. VEN-on-IoT-Gateway brings these functions together by using Illumio visibility and enforcement points already present in the environment to identify device types, associate them with meaningful classifications, and apply segmentation policy based on application and role labels rather than IP address alone. |
ZTNA Coexistence | On domain-joined Windows endpoints, Illumio can apply different policy depending on whether the host is on the corporate network or on an external network. That distinction relies on Windows Network Location Awareness (NLA) classification of the host's interfaces.Introducing a modern Zero Trust Network Access (ZTNA) client, such as Netskope Private Access, into a domain-joined Windows environment makes standard NLA classification ineffective. PCE-based interface classification (PCE NLA) resolves this so that ingress enforcement remains correct in ZTNA client environments. See Illumio PCE-based interface classification (PCE NLA) for endpoints in ZTNA client environments. |
Illumio VEN on DPU | Learn about running the Illumio VEN on the NVIDIA BlueField-3 DPU for hardware-accelerated, agentless workload discovery. Running an Illumio VEN on an NVIDIA BlueField-3 DPU enables performance and security benefits. |
Host Agent Hardening | The Illumio VEN reduces the attack surface on each host it protects and helps you detect and contain malware that is built to evade traditional endpoint tools. This includes passive back doors such as BPFDoor and malware that is generated or adapted with AI to slip past signature and behavior-based detection.Illumio works at the network and enforcement layer. It does not depend on inspecting file payloads or matching malware signatures, so its protection does not weaken when an attacker mutates a payload or produces a never-before-seen variant. What malware cannot avoid is making network connections on a host whose enforcement point reports on its own integrity. |