04-14-2025 09:29 PM
has anyone done WSA onprem to umbrella SIG migration. How to get the Identification Profiles, Access Policies from WSA migrated to Umbrella SIG.
What config changes to be done in Endpoint for the new Umbrella SIG proxy control to be effective.
04-22-2025 03:34 AM
Hybrid Policy and Reporting support in Cisco Secure Web Appliance (SWA) was introduced starting with AsyncOS 15.1. This functionality allows integration with Cisco Umbrella, enabling centralized policy management and visibility through the Umbrella dashboard.
You can refer to this link for more information: https://docs.umbrella.com/umbrella-user-guide/docs/hybrid-policy
At the endpoints (Clients), you don't need to change anything and they can continue working as before. The difference is that the management of policies can now be done in Umbrella. Additionally, you can have the SWA reports on the Umbrella reporting as well.
Here are some limitations that are important for you to be aware of: https://docs.umbrella.com/umbrella-user-guide/docs/hybrid-policy#lim
Please let me know if you have more question.
04-22-2025 04:52 AM
existing WSA won't be used anymore. It wd be decommissioned.
I think hybrid policy wont work here. Other than manually creating the policies in umbrella, any other mechanism to migrate?
04-22-2025 05:32 AM
You need to create a policy from scratch in Umbrella. With a Hybrid Policy, you can only push policies from Umbrella to SWA.
07-07-2025 07:46 AM
Since WSA will be decommissioned, Hybrid Policy won’t apply. There’s no automatic migration tool, you’ll need to manually recreate identification and access policies in Umbrella. Endpoints don’t need config changes if they’re already using Umbrella SIG.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide