Illumio Zero Trust Segmentation (ZTS) Platform is the only solution that handles it all: Endpoint-Endpoint, Endpoint-Server, Server-Server, as well as extensive support for cloud workloads, containers, IoT, and OT devices. Empowering organizations to be more resilient for whatever may come their way. ZTS contains the spread of breaches and ransomware across the hybrid attack surface by continually visualizing how workloads and devices are communicating, creating granular policies that only allow wanted and necessary communication, and automatically isolating breaches by restricting lateral movement proactively or during an active attack.
In addition, Illumio ZTS includes the Illumio Virtual Advisor (IVA) which provides actionable, AI driven guidance for even the most complex tasks. With IVA, teams can streamline their workflows with instant, expert-level answers to their questions. Quickly access critical information and achieve complex tasks simply by asking the virtual advisor.
Illumio Breach Containment Platform provides comprehensive mapping of traffic telemetry across hybrid multi-cloud environments and endpoints for applications, data, and cloud workloads. This visualization allows security teams to uncover unnecessary connectivity that increases risk. With the Illumio Breach Containment Platform, you can easily know if you are at risk of an attack or currently under attack. Detailed context-based label descriptions of objects guides teams as they create policies, based on applications' components and relationships. With Illumio, teams can make faster, more informed decisions about what traffic to segment to proactively maintain a strong security posture or reactively isolate a breach.
Illumio Breach Containment Platform is made up of these solutions:
Illumio Insights for visibility and incident response. Quickly identify risk, detect attacks, and contain threats with a single click. Empower security teams to protect critical assets and respond instantly.
Illumio Segmentation for cloud and on-premises data center workloads. Limit an attacker's ability to travel across lateral traffic with proactive policy controls that limit the exposure of valuable assets
Highlights
See risk
Visualize all communication and traffic between workloads and devices across the entire hybrid attack surface. Gain visibility with real-time telemetry and data, understand application communications, security policy, usage, access and security exposure with a comprehensive map of traffic flows.
Set policy
Comprehensive monitoring and simplified labeling that helps eliminate blind spots by automatically setting granular and flexible segmentation policies that control communication between workloads and devices to only allow what is necessary and wanted.
Stop the spread
Proactively isolate high-value assets or reactively isolate compromised systems during an active attack to stop the spread of a breach by programming dynamic workload policies for hybrid multi-cloud networks and endpoints, and applying automated policy recommendations.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this platform in two unit types that you can combine based on what you protect. The first unit covers 250 secured workloads and includes the Breach Containment Platform. The second unit covers 100 public cloud workloads. Both scale by adding more units as your workload count grows. A workload is a countable resource such as a virtual machine, database, or server operating system. Different resource types convert to workloads at different ratios, so you size your quantity from your actual environment. The two units are independent, so you select the mix that matches your infrastructure.
Top-of-mind questions for buyers
How do resource types convert into billable workloads for these units?
Different resources count at different ratios. A cloud virtual machine, database, or standard server operating system each counts as one workload. A container cluster host counts as two. Legacy operating systems count as two, and five user endpoints count as one workload. You size your quantity from your actual environment.
How do the two units combine on my bill, and which one drives cost?
The two units bill independently and appear together on the same invoice. The 250 secured workloads unit covers your servers, endpoints, and data center resources plus the platform. The 100 CloudSecure Workloads unit covers public cloud resources. Your infrastructure mix decides which unit contributes more.
What is included per workload for data processing or traffic retention?
Each cloud workload includes 50MB per day of data processing. Each data center and endpoint workload includes 50MB of data traffic retention. Container cluster counting here does not include Kubernetes-specific visibility or enforcement, which requires a separate deployment. Contact the vendor to discuss that option.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Comprehensive mapping and visualization of all communication and traffic flows between workloads and devices across hybrid multi-cloud environments and endpoints with real-time telemetry data.
Granular Segmentation Policy Creation
Automated generation and application of granular, context-based segmentation policies that control communication between workloads and devices to allow only necessary and wanted traffic.
Multi-Environment Workload Support
Support for diverse workload types including endpoint-to-endpoint, endpoint-to-server, server-to-server communications, cloud workloads, containers, IoT devices, and OT devices across hybrid architectures.
Dynamic Breach Isolation
Proactive and reactive isolation capabilities that restrict lateral movement by programming dynamic workload policies and applying automated policy recommendations during active attacks or for high-value asset protection.
AI-Driven Policy Guidance
Integrated artificial intelligence-driven virtual advisor that provides actionable recommendations for policy creation and complex segmentation tasks through natural language interaction.
Network Policy Enforcement
Fine-grained network policies that limit egress traffic by IPs, domains, and IP CIDRs with automatic namespace boundary identification and policy recommendations for namespace isolation.
Egress Traffic Management
Egress Gateway functionality that assigns static IP addresses to egress traffic from Kubernetes pods for integration with firewalls and tools requiring static IP identification.
Ingress Traffic Management
Ingress Gateway using Gateway API standard with integrated Envoy Gateway for comprehensive security and observability of ingress traffic.
Multi-Cluster Network Security
Centralized network security management across multiple Kubernetes distributions supporting individual and multi-cluster deployments in cloud and on-premises environments.
Network Observability and Risk Mitigation
Observability and risk mitigation capabilities for detecting and mitigating security breaches across all types of network traffic including egress, ingress, in-cluster, and cross-cluster communication.
Zero Trust Architecture
Cloud-native zero trust platform that applies zero trust principles to eliminate attack surface and prevent lateral movement across users, applications, and infrastructure.
AI-Powered Threat Detection
AI-powered cyberthreat and data loss prevention services that detect and prevent advanced threats, accidental exposure, theft, and ransomware attacks.
Next-Generation Network Access
Next-generation zero trust network access (ZTNA) platform enabling seamless and secure connectivity to private applications, services, and operational technology devices.
Data Loss Prevention
Data protection capabilities preventing data loss from users, SaaS applications, and public cloud infrastructure through comprehensive loss prevention policies.
End-to-End Digital Experience Monitoring
End-user perspective monitoring and visibility across device, ISP, cloud proxy, and application layers to optimize performance and identify application, network, and device issues.
Smooth Implementation Without Impacting Production
Reviewed on Aug 12, 2026
Review provided by G2
What do you like best about the product?
Implementation, with the right methodology doesn't impact production.
What do you dislike about the product?
It wasn't an fancy product in the past but this has changed with the AI tools. So there is nothing i really dislike.
What problems is the product solving and how is that benefiting you?
It solve the issue of limiting the lateral movement and reducing the blast radius. It can also help identifying abnormal traffic and rogue actor movements.
Mohammad Lokman Nur Al-Hakim K.
Strengthening Zero Trus with Workload Visibility and Microsegmentation
Reviewed on Aug 12, 2026
Review provided by G2
What do you like best about the product?
What I like best about Illumio is its ability to provide clear visibility into workload communications and enable granular microsegmentation without relying heavily on traditional network boundaries. The label-based policy model makes it easier to manage segmentation across complex hybrid environments, while providing strong control over east-west traffic and reducing lateral movement risk.
What do you dislike about the product?
One area that could be improved is the workload management experience. For example, the Workloads page does not make it easy to search for or work with multiple specific workloads at the same time, which can be inconvenient when managing a large environment.
Additionally, reporting and bulk operational tasks could be more flexible, especially for larger deployments. More advanced filtering, easier bulk actions, and better customization of dashboards and reports would improve the overall day-to-day operational experience.
What problems is the product solving and how is that benefiting you?
Illumio helps address the challenge of controlling east-west traffic and reducing lateral movement across a complex hybrid environment. It provides visibility into workload-to-workload communication and allows us to apply granular segmentation policies based on labels rather than network boundaries. This helps strengthen our Zero Trust approach, reduce exposure to risky or unnecessary traffic, and provide better control during security incidents without requiring major changes to the underlying network architecture.
Hospital & Health Care
Critical Micro-Segmentation Security Control That Meets Expectations
Reviewed on Aug 12, 2026
Review provided by G2
What do you like best about the product?
Provides a critical micro-segmentation security control. Absolutely meets expections.
What do you dislike about the product?
There are some complexities in our environment that made the implementation more difficult than expected.
What problems is the product solving and how is that benefiting you?
Creating a fully segmented environment to prevent lateral movement.
Computer & Network Security
Massive Visibility Gains Across Client Networks
Reviewed on Aug 11, 2026
Review provided by G2
What do you like best about the product?
The massive gain in visibility across client networks and the cloud interface is intuitive It's well presented and performs well locally. Great price for effect, and support is generally good
What do you dislike about the product?
Unfortunately the cloud element can be some what slow The integrations with 3rd party platforms is somewhat lacking
What problems is the product solving and how is that benefiting you?
Ensure the edge is secured from bad VLAN configuration. from unpatched or unpatchable devices. ensureing device out of office are secured as well. ultimately we're providing client visibility and control
Consumer Goods
Intuitive and Evolving Product, Though Traffic Data Can Lag
Reviewed on Aug 11, 2026
Review provided by G2
What do you like best about the product?
The interface is intuitive and the product works as expected. They are also constantly evolving the product and making enhancements where needed.
What do you dislike about the product?
Sometimes the traffic data can take a bit to show up and some flows don't always seem to be present.
What problems is the product solving and how is that benefiting you?
It is helping us solve network segmentation issues, by restricting common malware ports on our servers.