Skip to main content

Illumio Administration Guide 26.x

New and Enhanced in Segmentation

Explore new features and learn about significant enhancements to existing features in Illumio Segmentation.

New and Enhanced, August 2026

First published on August 29, 2026

Feature

Summary

Policy Advisor for the Platform

See Introducing the Policy Advisor.

AI Agent Detection and Enforcement for VEN and PCE

Insights detects AI agent processes and surfaces them alongside your other workloads so security teams can see which agents are running, what they're reaching out to, and how their traffic moves through the environment. That turns a fast-growing blind spot into something you can investigate and understand the exposure before it becomes an incident.

See AI Agent Detection and Enforcement for VEN and PCE.

Illumio Segmentation / Insights – NDR Integration

Zeek runs on a sensor instance receiving a mirrored copy of a monitored workload’s traffic via AWS VPC Traffic Mirroring. When Zeek’s scan-detection logic raises a notice, a policy hook invokes a script that calls the Illumio PCE REST API, assigns a Quarantine label to the scanned workload and moves it to Full enforcement. The workload’s VEN applies the policy within seconds. Quarantine persists until explicitly released, via CLI, an operator console, or the Illumio UI.

See Illumio and Zeek NDR: Automated Workload Quarantine.

VEN on IoT Gateway – Visibility

VEN-on-IoT-Gateway extends Illumio Zero Trust Segmentation to IoT and other unmanaged devices that cannot host a software agent. Traditional IoT security approaches often separate device identification from policy enforcement, requiring organizations to use one platform to discover and classify devices and another to control communications. VEN-on-IoT-Gateway brings these functions together by using Illumio visibility and enforcement points already present in the environment to identify device types, associate them with meaningful classifications, and apply segmentation policy based on application and role labels rather than IP address alone.

See Illumio VEN on IoT Gateway Setup and Admin Guide.

ZTNA Coexistence

On domain-joined Windows endpoints, Illumio can apply different policy depending on whether the host is on the corporate network or on an external network. That distinction relies on Windows Network Location Awareness (NLA) classification of the host's interfaces.Introducing a modern Zero Trust Network Access (ZTNA) client, such as Netskope Private Access, into a domain-joined Windows environment makes standard NLA classification ineffective. PCE-based interface classification (PCE NLA) resolves this so that ingress enforcement remains correct in ZTNA client environments.

See Illumio PCE-based interface classification (PCE NLA) for endpoints in ZTNA client environments.

Illumio VEN on DPU

Learn about running the Illumio VEN on the NVIDIA BlueField-3 DPU for hardware-accelerated, agentless workload discovery. Running an Illumio VEN on an NVIDIA BlueField-3 DPU enables performance and security benefits.

See Overview of VEN on DPU.

Host Agent Hardening

The Illumio VEN reduces the attack surface on each host it protects and helps you detect and contain malware that is built to evade traditional endpoint tools. This includes passive back doors such as BPFDoor and malware that is generated or adapted with AI to slip past signature and behavior-based detection.Illumio works at the network and enforcement layer. It does not depend on inspecting file payloads or matching malware signatures, so its protection does not weaken when an attacker mutates a payload or produces a never-before-seen variant. What malware cannot avoid is making network connections on a host whose enforcement point reports on its own integrity.

See Host hardening and malware resilience with Illumio VEN.