Security Stack Logo
Illumio Segmentation logo

Network & Infrastructure Security

Illumio Segmentation

Host-based microsegmentation mapping dependencies to enforce least-privilege and contain breaches.

Illumio Segmentation Overview

What it does

Illumio Core is a host-based microsegmentation product that contains breaches by stopping lateral movement across data center, cloud, and endpoint workloads. Rather than relying on network firewalls or VLANs, it decouples segmentation policy from the underlying network and enforces rules directly on each workload through a lightweight agent paired with a centralized policy controller. This host-level model lets security teams write least-privilege policy based on application identity instead of IP addresses.

How it works

The Policy Compute Engine (PCE) ingests real-time traffic telemetry from a Virtual Enforcement Node (VEN) installed on each workload, builds an application dependency map of east-west flows, and computes per-workload policy. Policies are expressed through Role, Application, Environment, and Location labels, and the VEN enforces them using the operating system's native firewall on Linux and Windows hosts. Progressive enforcement modes let teams test rules before blocking traffic, while SecureConnect adds IPsec encryption between workloads. Coverage spans bare-metal servers, virtual machines, containers, and cloud instances. Named deployments include eBay, which segmented 3,000 servers, and Marriott Vacations.

Credentials and traction

Illumio has completed a SOC 2 Type II audit, holds a FedRAMP Moderate Authorization to Operate, and uses FIPS 140-2 validated cryptographic modules in its Policy Compute Engine and Virtual Enforcement Node. It was named a Leader in The Forrester Wave: Microsegmentation Solutions, Q3 2024, and a Customers' Choice in the 2026 Gartner Peer Insights Voice of the Customer for Network Security Microsegmentation, earning 4.8 of 5 across 59 reviews with 98% of reviewers willing to recommend. Deployments include federal agencies and 15 of the Fortune 100.

Key Capabilities

mapped to solution categories
Microsegmentation

Evaluates proposed segmentation policies against observed traffic to identify what legitimate connections would be blocked, enabling policy validation without a production enforcement change.

Enriches raw flow and asset records with context such as owning process, user, application, environment, cloud tags, CMDB attributes and threat intelligence, and turns that context into labels that policies reference directly, so rules are written in business terms (application, environment, role) rather than addresses and ports. Products differ in attribute breadth, process- and payload-level depth, and how much labeling is automatic rather than manual.

Discovers and classifies every workload and device that communicates on the network, including unknown and unmanaged assets missing from the CMDB, using the product's own agents, network sensors and ingested external inventories, so segmentation policy can cover assets the organization did not know it had. Products differ in fingerprinting depth (device make, model, operating system, function), agentless reach, and use of external data sources.

Enforces segmentation through the existing on-premises network infrastructure, programming switches, DPU-based switches, firewalls, NAC, application delivery controllers or an inline gateway appliance, so devices that cannot run an agent are segmented without rearchitecting the network or replacing hardware. Products differ in the range of network hardware vendors supported, whether enforcement is distributed at the access layer or backhauled to central chokepoints, and dependency on a NAC deployment.

Programs the cloud provider's own network controls (AWS security groups, Azure network security groups, GCP firewall rules, VPC and VNet constructs) from the central segmentation policy, so cloud virtual machines are governed by the same labels and rules as on-premises workloads without a host agent. Products differ in provider breadth, whether enforcement uses native controls or requires proprietary virtual appliances, and how drift between cloud rules and intended policy is reconciled.

Proposes least-privilege allow-list rules automatically from observed flows, labels and templates, and manages them through the full lifecycle of creation, testing, enforcement, tuning and retirement, so segmentation is not built by writing rules by hand. Products differ in recommendation quality, template coverage for common applications and compliance zones, and support for iterative refinement before enforcement.

Segments purpose-built and unmanaged devices such as medical devices, industrial controllers, building systems and IoT endpoints that cannot host an agent and often run very old operating systems, combining device fingerprinting and classification with network-side enforcement and policy templates tuned to clinical and industrial protocols, without disrupting device operation. Products differ in device fingerprinting depth, protocol awareness, and whether enforcement works with the legacy network equipment typical of hospitals and plants.

Enforces segmentation policy on the workload itself through a host agent or existing endpoint hooks (operating system firewall, eBPF, an EDR agent already deployed), so the policy travels with the workload across data center, cloud and endpoint locations and gives per-process visibility. Products differ in operating system coverage, resource overhead, kernel or user-mode operation, and whether an existing EDR agent can be reused instead of deploying a new one.

Contains an active breach by cutting the paths ransomware and attackers use to spread: pre-staged containment policies that block peer-to-peer SMB, RDP, WMI and other administrative protocols between endpoints and servers, a firebreak around devices that cannot run security agents, and quarantine of compromised workloads that can be triggered from the console, by a severity-level switch, or by SIEM, SOAR and EDR during an incident. Products differ in whether containment can be staged by threat level and activated with a single switch, and in how quickly a quarantine reaches every enforcement point.

Renders the discovered assets, their flows and the current policy state as an interactive map that can be viewed at data center, application, workload and connection level, showing which traffic is allowed, blocked or not yet governed, so teams can author policy and investigate incidents from the same view. Products differ in readability at scale, filtering and drill-down, and whether the map supports policy authoring directly.

Extends the same segmentation policy model into Kubernetes and container environments, enforcing at pod, namespace and service level through CNI or eBPF hooks, sidecars or native NetworkPolicy objects, so container traffic is governed by the same labels and rules as virtual machines and bare metal instead of a separate container-only tool. Products differ in whether Kubernetes support is enforcement or visibility only, distribution coverage (managed cloud Kubernetes, OpenShift, self-managed), and Layer 7 awareness.

Discovers the actual north-south and east-west communication flows between workloads and devices by observing live traffic, producing the dependency data that allow-list policy is built from instead of hand-documented application maps. Products differ in flow sources (host agent, network sensors or switch telemetry, cloud flow logs, virtual switch) and therefore in how completely agentless assets are covered.

Compliance

certifications
FedRAMP ModerateFIPS 140-2SOC 2 Type II

Integrations

compatible tools
AWS Security HubBMCIBM Security QRadarOktaServiceNowSplunk

Implementation & support

Deployment model
Endpoint AgentHybridOn-PremisesSaaS
Support channels
24/7 SupportCommunity ForumCustomer Success TeamEmail SupportKnowledge BasePhone SupportTechnical Account Manager (TAM)Ticketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

See how Illumio Segmentation fits your stack

Add Illumio Segmentation to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.