← All blog articles

Umbrella Roaming Client End of Life: What Replaced It and What Happens If You Wait

Jonas Delrue
Umbrella Roaming Client End of Life: What Replaced It and What Happens If You Wait

The Cisco Umbrella Roaming Client reached the end of software maintenance and support on 2 April 2025. Its replacement is the Umbrella module in Cisco Secure Client, which Cisco provides at no extra cost to customers with a valid Umbrella licence and active support.

If the old client is still on some of your laptops, it probably still works. That is the problem. It will keep working until the day it silently does not, and nothing in your dashboard will tell you when that day comes.

This article covers the dates, what the replacement actually installs, what happens on machines you have not migrated, and why the client migration has become a platform decision for many Umbrella customers.

When did the Umbrella Roaming Client reach end of life?

Cisco announced the end of life of the Umbrella Roaming Client on 1 April 2024. Software maintenance and support ended on 2 April 2025. Since then, Cisco releases no patches or maintenance builds for the client, TAC does not support it, and new installations of the legacy client can no longer register with Umbrella.

Milestone Date What it means
End-of-life announcement 1 April 2024 Cisco publishes the retirement and names Cisco Secure Client as the replacement
End of software maintenance 2 April 2025 No more patches or maintenance releases for the Roaming Client
Last date of support 2 April 2025 TAC no longer supports the standalone client
Installers and new registrations From 2 April 2025 Installers removed from the dashboard; newly installed legacy clients cannot register
Last Windows release Version 3.0.466 The final build Cisco shipped for Windows

Source: Cisco end-of-life announcement for the Umbrella Roaming Client and the Umbrella end-of-support community announcement. Some partner lifecycle databases list a later end-of-service-life date for the SKU; Cisco’s own announcement puts the end of software maintenance and support on 2 April 2025.

What happens to machines still running the old client

This is the part most migration guides skip, and it is the part that matters for a security team.

A Roaming Client that registered before 2 April 2025 keeps its identity and keeps forwarding DNS queries to Umbrella. Policies still apply. On a normal day, nothing looks wrong.

The client is designed to fail open. If its local DNS service stops, crashes or cannot reach Umbrella’s resolvers, the machine falls back to the DNS servers it received from the local network. Internet access keeps working, so the user notices nothing. DNS-layer filtering, phishing protection and content policy stop working at the same moment, and because the client is no longer maintained, the failure does not arrive with a fix.

Two things make this more likely over time. Operating system updates keep arriving while the client does not change, so compatibility problems accumulate. And a client that breaks cannot be reinstalled: installers are gone from the dashboard and the legacy registration path is closed. A reimaged laptop with the old client is simply unprotected.

So the honest summary for an unmigrated estate is this: protected until further notice, with no alert when the notice comes.

What replaces the Roaming Client

The replacement is the Umbrella module in Cisco Secure Client, the product formerly known as AnyConnect. Cisco points customers to the 5.1 release family. Customers with a valid Umbrella licence and active support can deploy it at no additional software cost.

The replacement is not a like-for-like swap, and the differences decide how much work the migration is.

Area Umbrella Roaming Client Cisco Secure Client with Umbrella module Gap or change
Architecture Single-purpose DNS agent Modular client; the core VPN module is installed as a base component The VPN component installs even if you never use Cisco VPN; the VPN tile can be hidden
Web security DNS layer plus selective Intelligent Proxy DNS module plus an optional full secure web gateway agent Full web inspection requires the Umbrella root certificate on every endpoint
Windows Windows 10 and 11 Windows 10 and 11, including ARM64 Azure Virtual Desktop multi-session is not supported
macOS Supported, with intermittent issues on newer releases Current macOS releases Requires MDM profiles for system extensions and content filtering
iOS Cisco Security Connector via MDM Cisco Security Connector via MDM No Secure Client Umbrella module for iOS; separate workflow remains
Android Limited Secure Client in an Android Enterprise work profile Only work-profile traffic is covered
ChromeOS Umbrella Chromebook client Umbrella Chromebook client Not covered by Secure Client; stays a separate deployment
Servers running DNS Not a supported use Not supported Do not install on domain controllers or other DNS servers

Source: Cisco Secure Client documentation and Umbrella migration guides.

The first row is the one administrators push back on most. Teams that chose the Roaming Client because it was small and did one thing now install a multi-module client with a VPN component underneath, sometimes next to another vendor’s VPN client. The migration is technically supported. It is also a different kind of software on every laptop.

The migration in practice, for 100 to 1,000 devices

Cisco built the migration into the installer. When Secure Client with the Umbrella module is installed on a machine that runs the Roaming Client, it detects the old client, carries over the device identity and removes it. Reporting continuity in the Umbrella dashboard is preserved because the device keeps its identity.

The work sits in the packaging and in a handful of details that cause most failed rollouts.

  1. Get the organisation file. Download OrgInfo.json from the Umbrella dashboard. The module needs it to register.
  2. Save it with the right encoding. Administrators have repeatedly reported agents that go offline because a deployment script wrote OrgInfo.json as UTF-16 or UTF-8 with a byte-order mark. Use UTF-8 without BOM or plain ASCII.
  3. Package the core and the Umbrella module. On Windows, install the core package first and then the Umbrella module. If you do not use Cisco VPN, the installer property PRE_DEPLOY_DISABLE_VPN=1 hides the VPN interface from users. Place OrgInfo.json in the Umbrella folder under the Secure Client program data directory before the module starts.
  4. Prepare macOS in advance. Push the MDM profiles that approve Cisco’s system extension and content filter before the package runs. Without them, users see approval prompts and the filter does not load.
  5. Deploy the root certificate first if you use the web gateway. The secure web gateway agent inspects TLS traffic. Endpoints without the Umbrella root certificate will show certificate errors on every site.
  6. Pilot, then roll out. Start with a group that includes docked laptops, travellers and anyone on another vendor’s VPN. DNS binding issues after network changes are the most common complaint in the field.

One more change sits in the background. Cisco retired SecureX on 31 July 2024, and with it the free console many teams used to build deployment packages and manage client updates. Packaging now runs through your own MDM, such as Intune or Jamf, or through Cisco Security Cloud Control.

Why this is a platform decision now

The client migration does not happen in isolation. Under bulletin EOL15688, Cisco stopped selling the legacy Umbrella packages on 30 September 2025, and software maintenance for those packages ends on 30 September 2026. Support continues until 30 September 2030. Cisco’s forward path for these customers is Cisco Secure Access, its security service edge platform. The package dates and what each milestone means are covered in Umbrella end of sale versus end of life.

Secure Access works differently from the Umbrella many mid-market teams bought. The selective Intelligent Proxy, which only proxied risky domains, gives way to full web proxying, with decryption and root certificates on every endpoint. The Intelligent Proxy timeline explains what that change means in practice.

Put the two together and the situation looks like this: you are about to touch every endpoint to install a new client, and within the same period the commercial basis of your Umbrella subscription changes. That is the natural moment to ask whether the next platform should be Cisco’s, rather than the moment after the client is rolled out.

For a European mid-market organisation, the comparison worth making is between Secure Access and a single platform that combines DNS and web security with zero trust network access, run from Europe. Jimber is built for that: one EU-sovereign platform for web security, ZTNA and firewalling, with agentless access for applications, instead of stacking modules and licences. If you want to test that before rolling a new client to every laptop, the 60-day migration plan shows how the switch is usually staged.

The case for simply migrating the client

A Cisco-shop network lead will make three fair points.

“It is an afternoon of packaging.” For a team with Intune and a clean estate, building the Secure Client package is quick, the installer removes the old client, and the licence is included. True. The packaging is quick. The client it installs is larger than the one it replaces, and the subscription it depends on is moving to a new commercial model within months. A quick migration to a platform you may leave next year is still two migrations.

“One Cisco agent is better than five tools.” Consolidation is a real benefit. It only holds if the consolidated client stays simple to run. With SecureX gone, lean teams now manage installer transforms, macOS profiles and certificate deployment themselves. Consolidation that moves the complexity to your MDM is not the same as less complexity.

“Cisco Talos sees more threats than anyone.” Cisco’s threat intelligence is extensive, and that is a genuine strength. For European organisations under NIS2, the questions that follow are where traffic and logs are processed, who can access them, and what the platform costs a 200-person company. Threat intelligence scale is one criterion among several, not the decision.

What to do next

Find out where you stand first. Check the Roaming Computers view in the Umbrella dashboard for devices still on the legacy client, and compare the count with your MDM inventory. The difference is the number of machines you cannot currently prove are protected.

Then decide the order: migrate the client and review the platform later, or review the platform and migrate once. If you want to compare before you package anything, try Jimber free with a pilot group, or book a demo to walk through your Umbrella setup with us. For the full set of migration routes, see Umbrella migration paths for 2026.

Frequently asked questions

When did the Cisco Umbrella Roaming Client reach end of life?

Cisco announced the end of life on 1 April 2024. Software maintenance and support ended on 2 April 2025. Since then there are no patches or maintenance releases, TAC does not support the client, and newly installed legacy clients cannot register with Umbrella.

What replaces the Umbrella Roaming Client?

The Umbrella module in Cisco Secure Client, formerly AnyConnect. Customers with a valid Umbrella licence and active support can deploy it at no additional software cost. Cisco points customers to the 5.1 release family for ongoing fixes.

Does the Umbrella Roaming Client fail open or fail closed?

It fails open. If the client’s DNS service stops or cannot reach Umbrella, the machine falls back to the local network’s DNS servers. Internet access keeps working, but DNS filtering and policy enforcement stop, without a visible warning to the user.

Do I need a Cisco VPN licence to use the Umbrella module?

No. The core VPN component installs as a base dependency of Secure Client, but no VPN licence is required if you do not use Cisco’s VPN. On Windows, the installer property PRE_DEPLOY_DISABLE_VPN=1 hides the VPN interface from users.

Why does the Umbrella module go offline after a scripted deployment?

A common cause is the encoding of OrgInfo.json. Scripts that save the file as UTF-16 or as UTF-8 with a byte-order mark can stop the module from reading it. Save the file as UTF-8 without BOM or as ASCII and redeploy.

Can I install the Umbrella module on a domain controller?

No. Cisco does not support the module on machines that run DNS server software, such as domain controllers. Installing it there causes conflicts on the DNS port and can break name resolution for the network. Protect servers at the network level instead.

Is there a Secure Client Umbrella module for iPhone and iPad?

No. iOS devices still use the separate Cisco Security Connector, deployed through MDM on supervised devices. Chromebooks also keep their own Umbrella Chromebook client, so mixed fleets continue to need more than one deployment.

Will migrated devices keep their Umbrella reporting history?

Yes. When Secure Client replaces the Roaming Client on the same machine, it carries over the device identity, so historical reporting and identity-based policies stay linked to the device in the Umbrella dashboard.

Is migrating the client the right moment to review Umbrella itself?

For many organisations it is. Legacy Umbrella packages leave software maintenance on 30 September 2026, and Cisco’s forward path is Secure Access. Reviewing the platform before rolling a new client to every endpoint avoids migrating twice.