Cisco Umbrella License provides cloud-delivered DNS security, web protection, cloud application visibility, malware defense, and internet access controls for users both inside and outside the corporate network. As one of Cisco’s established cloud-security platforms, Umbrella helps organizations block malicious destinations before connections are established and apply consistent security policies to roaming users, branch offices, and distributed environments.
Cisco is currently evolving Umbrella into Cisco Secure Access, its newer Security Service Edge platform. Existing Cisco Umbrella License deployments remain relevant for organizations already using DNS Security or Secure Internet Gateway services, while new projects should also evaluate Cisco Secure Access DNS Defense and Secure Internet Access as the strategic migration path.
Quick Benefits
- DNS-layer threat protection
- Malware and phishing domain blocking
- Protection for roaming users
- URL and content filtering
- Cloud application discovery
- Secure Web Gateway capabilities
- Cloud-delivered firewall
- CASB functionality
- Malware analysis and sandboxing

At a Glance
- Product: Cisco Umbrella
- Parent Category: Cisco Security
- Primary Use: DNS and internet access security
- Deployment: Cloud-delivered
- DNS Packages: DNS Essentials and DNS Advantage
- SIG Packages: SIG Essentials and SIG Advantage
- Roaming Protection: Cisco Secure Client integration
- Threat Intelligence: Cisco Talos
- Web Security: Secure Web Gateway
Cisco Umbrella License Overview
Cisco Umbrella licensing has historically been divided between DNS-focused packages and broader Secure Internet Gateway packages.
DNS Security Essentials provides foundational DNS-layer protection, including malicious-domain blocking, content filtering, application discovery, and protection for users connecting both on and off the corporate network.
DNS Security Advantage extends the DNS security model with deeper inspection of risky domains, URLs, and files, providing additional visibility beyond basic DNS filtering.
For organizations requiring broader internet-security controls, Umbrella Secure Internet Gateway packages combine DNS-layer protection with technologies such as Secure Web Gateway, CASB, cloud-delivered firewall, malware analysis, and additional application-security controls.
Cisco currently offers SIG Essentials and SIG Advantage for existing Umbrella environments. However, organizations planning new deployments should consider the transition to Cisco Secure Access because Cisco is moving Umbrella functionality into its newer SSE architecture.
Cisco Umbrella Product Overview
Cisco Umbrella operates primarily through Cisco’s globally distributed cloud infrastructure. Instead of allowing devices to resolve internet destinations directly through an ISP or public DNS resolver, organizations can direct DNS requests through Cisco Umbrella.
Umbrella evaluates the requested domain against threat intelligence, reputation information, security policies, and content categories before returning the destination to the user.
If a domain is associated with malware, phishing, command-and-control infrastructure, or another prohibited category, the request can be blocked before a direct connection to the malicious destination is established.
More advanced Umbrella packages extend inspection beyond DNS. Web traffic can be proxied through Secure Web Gateway services, cloud applications can be analyzed through CASB functionality, and network traffic can be controlled through cloud-delivered firewall policies.
This layered model allows organizations to secure users even when they are outside traditional enterprise perimeter defenses.
Core Technical Flow
Cisco Umbrella protection begins when a user attempts to reach an internet destination.
DNS requests are forwarded to Cisco’s cloud infrastructure rather than directly to an unprotected DNS resolver.
Umbrella evaluates the domain using Cisco Talos intelligence, reputation data, application information, configured categories, and organizational security policies.
Known malicious or prohibited destinations can be blocked immediately at the DNS layer.
If deeper inspection is required and the relevant Umbrella package is licensed, web traffic can be routed through the Secure Web Gateway for URL-level inspection, file analysis, application controls, and additional policy enforcement.
CASB capabilities can identify cloud applications and provide risk information, while cloud-delivered firewall services can apply network-level rules.
Security events and user activity are then made available through centralized reporting, APIs, and supported integrations.
Options & Licensing Models
| Cisco Umbrella Package | Primary Capabilities | Typical Use |
|---|---|---|
| DNS Essentials | DNS-layer security, domain filtering, application discovery and roaming DNS protection | Organizations requiring foundational DNS security |
| DNS Advantage | DNS protection plus deeper URL and file inspection for risky destinations | Organizations requiring enhanced DNS-based protection |
| SIG Essentials | DNS security, SWG, CASB, cloud firewall and malware protection | Broader internet and SaaS security |
| SIG Advantage | Expanded SIG security including advanced firewall, malware, DLP and cloud-app controls | Enterprise SSE-style protection |
| Secure Access DNS Defense | Strategic successor to Umbrella DNS | New DNS-security deployments |
| Secure Access SIA | Strategic successor to Umbrella SIG | New internet and SaaS security deployments |
Organizations with existing Umbrella subscriptions should verify their current package through the Umbrella dashboard before renewal, expansion, or migration. New deployments should compare Umbrella availability with Cisco Secure Access because Umbrella DNS and SIG are approaching end-of-sale.
Features & Benefits
DNS-Layer Threat Protection and Roaming Security
Cisco Umbrella provides an early security enforcement point by analyzing DNS requests before users connect to internet destinations. Malicious domains associated with phishing, ransomware, malware distribution, or command-and-control infrastructure can be blocked before the endpoint establishes a connection. Cisco Secure Client integration extends this protection to roaming users, helping organizations maintain DNS security when employees leave the corporate network or connect directly to the internet.
Secure Web, Cloud Application, and Malware Protection
Advanced Umbrella packages expand protection beyond DNS by introducing Secure Web Gateway, CASB, URL inspection, and malware-analysis capabilities. Organizations can inspect web traffic, control access to risky applications, discover shadow IT, analyze suspicious files, and enforce acceptable-use policies. SIG deployments can therefore provide broader protection for SaaS and internet traffic without requiring users to connect through a traditional centralized security gateway.
Cloud-Delivered Security and Centralized Management
Because Umbrella security services are delivered from Cisco’s cloud infrastructure, organizations can enforce policies across headquarters, branches, remote users, and distributed environments without deploying security appliances at every location. Centralized policy configuration, activity reporting, APIs, and integrations with Cisco Secure Client, Meraki, Secure Firewall, SD-WAN, and other Cisco technologies simplify administration while maintaining consistent internet-security controls.
Compatibility & Requirements
Before ordering or renewing a Cisco Umbrella License, organizations should evaluate:
- Number of protected users
- Existing Umbrella license package
- DNS Security versus SIG requirements
- Cisco Secure Client deployment
- Branch and roaming-user architecture
- Existing DNS infrastructure
- Secure Web Gateway requirements
- CASB requirements
- Cloud-delivered firewall requirements
- Malware-analysis requirements
Activation and Deployment
Cisco Umbrella deployment normally begins by creating or provisioning the Umbrella organization and defining the networks, users, or roaming devices that require protection.
For network-based DNS protection, administrators configure DNS forwarding so requests are sent to Cisco Umbrella resolvers. Networks can then be identified and associated with security policies.
Cisco Secure Client can be deployed to laptops and other supported endpoints to provide roaming protection when users operate outside the corporate network.
Organizations using SIG packages can additionally configure web traffic forwarding, Secure Web Gateway policies, CASB controls, firewall policies, and malware inspection.
Before expanding an existing Umbrella deployment, organizations should also review the Cisco Secure Access migration path. Existing DNS and SIG customers can transition to the corresponding Secure Access services while retaining the general security objectives of their Umbrella environment.
Cisco Umbrella License Pricing and Quote
Cisco Umbrella License pricing depends on the selected package, number of protected users, subscription term, required cloud-security functions, and existing Cisco security environment.
DNS Essentials and DNS Advantage are appropriate for organizations focused primarily on DNS-layer security, while SIG packages provide broader internet and SaaS security capabilities.
However, because Cisco has announced the end-of-sale transition for Umbrella DNS and SIG, licensing decisions made in 2026 should also consider the equivalent Cisco Secure Access offerings.
The last date for new Umbrella DNS and SIG orders is January 31, 2027. Existing customers can renew or expand qualifying subscriptions until January 31, 2028.
Before requesting a quote, prepare the number of users, existing Umbrella package, subscription expiration date, required security capabilities, roaming-user count, Secure Client environment, and whether the project should remain on Umbrella temporarily or migrate to Cisco Secure Access.
