Cisco Umbrella DNS Playbook
This playbook is designed to provide you with use case education, customer requirements, and actions you'll need to take to help your customers navigate their Cisco product adoption.


How to coach for success with Cisco Umbrella DNS
Help your customers get started with inital Cisco Umbrella DNS onboarding steps, then learn how to tap into advanced features to further configure, customize, and secure their network.
Help your customer kick off their Umbrella DNS deployment. Support their initial login process by getting them familiar with key resources available that will provide guidance throughout their deployment. Walk them through the initial five steps to deploy Umbrella DNS, which will get their configuration up and running. Ensure that the customer has added a network identity and pointed their DNS to Umbrella to ensure basic coverage. For additional coverage, guide your customer through setting up the Cisco Secure Client or Umbrella Roaming Client. Once they have configured their DNS traffic, ensure your customer is aware of policy best practices and has set up a DNS policy to ensure a more customized deployment.
A customer who enters this journey has not yet logged into their dashboard, despite having received emails in the initial onboarding journey. Help your customer understand the value of logging into their dashboard, and guide them to log into their dashboard to begin their onboarding process. Logging into the Umbrella dashboard is a critical step, allowing the customer to set up their Umbrella DNS configuration and start protecting their organization from internet-based threats.
A customer who enters this journey has either not configured DNS traffic or has not set up a DNS policy, despite having received emails in the initial onboarding journey. If your customer has not yet pointed their DNS to Umbrella, help them do so by guiding them through the initial three steps of a DNS deployment, which covers adding a network identity and pointing their DNS to Umbrella, configuring policies, and installing the root certificate. These steps will get their configuration up and running, and provide security from internet-based threats. If your customer has already pointed their DNS traffic and configured a network, then ensure they have set up their initial DNS policy and are following policy best practices.
Help your customer take their Umbrella DNS deployment further and maximize value by enabling advanced features. Walk them through available deployment resources for self-service support options. Assist in their creation of reports to help monitor their security environment, ensuring they know the different reports available and how each can add value to their deployment. Guide your customer through more advanced policy features, including block pages, tenant controls, and Web Selective Decryption. Ensure they have APIs and integrations configured, which will help automate tasks and workflows.
Once they have configured all their advanced features, suggest they register for an upcoming health check webinar or, if no upcoming webinars are available, have them watch a recording. Health checks are a great way to check if their deployment is healthy and valuable to their organization.
Customers enter the Umbrella DNS journey when they meet the following corresponding entry criteria:
Customers are eligible for the journey when they have purchased:
Eligibility Rule | Hierarchy Component | Rule Description |
---|---|---|
Rule 1 | License | Must have at least one license (DNS Essentials, DNS Advantage, Cisco Umbrella Security Subscription) |
Eligibility Scenarios |
---|
If Rule 1 is TRUE, then your customer is ELIGIBLE |
Guidance on helping your customer adopt OnbImp journey
In this stage, the customer will:
- Bookmark important resources provided via Getting Started email
- Log into their dashboard and review a two minute video tutorial
- Submit a ticket for any technical issues while implementing
The customer will exit this stage when they have:
- Received the Getting started email
Tips for Partner:
- Ensure your customer is aware of all available self-service resources
- Direct your customer to subscribe to the Umbrella Product Announcements page
- Guide your customer to subscribe to the Umbrella Software Release Notes page
- Ensure your customer registers and attends an upcoming DNS webinar or watch a recording
- Ensure your customer is able to log into their DNS dashboard
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Getting started
Preheader: Everything you need for a successful deployment.
Trigger: Customer enters journey once they have an organization ID created
Goal: Ensure customer has important resources provided via Getting Started email
Getting started
In this stage, the customer will:
- Register their network to inform Umbrella of their traffic location
- Configure their policies to define security and access controls for your identities
The customer will exit this stage when they have:
- Logged into Umbrella and registered their network
- Installed Cisco Secure Client
- Assigned additional administrators to prevent lockout
Tips for Partner:
- Have your customer watch the DNS deployment on-demand video course
- Share the following documentation with your customer for step-by-step guidance on how to get their deployment up and running
- Ensure your customer has successfully pointed their DNS by testing their DNS settings
- If a customer needs help determining their IP address, point them to Whats my IP
- Have your customer watch the on-demand video on how to install the Umbrella Secure Client
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
5 steps
Preheader: Implement with these best practices for success.
Trigger: Customer receives this email two weeks after the Getting Started email is sent
Goal: Encourage your customer to complete the five steps from the 5 steps email
5 steps
In this stage, the customer will:
- Set up a policy using the DNS Policy Wizard
- Prioritize their policies
- Test their policies using the policy tester
The customer will exit this stage when they have:
- Received each of the emails from this journey
Tips for Partner:
- Ensure your customer has a good understanding of DNS policy best practices
- Support them in configuring a basic Umbrella DNS policy and allow them to set up more advanced policy settings later in their deployment
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Policy best practices
Preheader: Secure your users exactly how you want.
Trigger: Customer receives this email one week after the 5 steps email is sent
Goal: Encourage customer to follow the steps to set up and test a policy
Policy best practices
Guidance on helping your customer adopt No Login journey
The customer will exit this stage when they have:
- Logged into their dashboard or received the 2 emails from the No Login journey
Tips for Partner:
- If a customer says they have logged in but are still receiving no login emails, they may be logged into their trial dashboard. You can help them navigate to the lower lefthand side of their dashboard, where they can click on the expand symbol next to their organization name, and they should see their paid organization under "Other organizations"
- If a customer is having trouble logging in, please direct them to this FAQ which can help assist in common login questions
- The customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Login guidance
Preheader: It's time to log in and deploy your Cisco Umbrella DNS
Trigger: The customer completed the initial onboarding journey and has not logged into their dashboard in the last 30 days
Goal: Customer logs into their dashboard
Login guidance
In this stage, the customer will:
- Log in to their dashboard
The customer will exit this stage when they have:
- Logged into their dashboard or received the 2 emails from the No Login journey
Tips for Partner:
- If a customer has recently logged in but is receiving this no login email, they may be logged into their trial dashboard. Assist them in navigating to the lower lefthand side of their dashboard, click on the expand symbol next to their organization name, and they should see their paid organization under "Other organizations"
- If a customer is having trouble logging in, please direct them to this FAQ which can help assist in common login questions
- The customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Login guidance followup
Preheader: View your Cisco Umbrella dashboard
Trigger: The customer completed the initial onboarding journey and has not logged into their dashboard in the last 30 days
Goal: Customer logs into their dashboard
Login guidance followup
Guidance on helping your customer adopt No DNS journey
In this stage, the customer will:
- Add a network identity and point their DNS to Umbrella
- Understand the default security policy and configure their policies
- Install the root certificate and deploy
The customer will exit this stage when they have:
- Configured at least one network or implemented a deployment method and set up at least one DNS policy, or they have received all three emails
Tips for Partner:
- Have your customer watch the DNS deployment on-demand video course
- Share the following documentation with customers for step-by-step guidance on how to get their deployment up and running
- Ensure your customer has successfully added a network identity and pointed their DNS by testing their DNS settings
- Ensure your customer has a good understanding of DNS policy best practices
- Ensure your customer has setup a root certificate to enable more advanced features later in their deployment. For more guidance, have them watch this on-demand video
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
DNS Deployment Steps
Preheader: Protect your organization in minutes
Trigger: The customer completed the initial onboarding journey and has logged into their dashboard
Goal: Customer has pointed their DNS to Umbrella
DNS Deployment Steps
In this stage, the customer will:
- Add a network identity and point their DNS to Umbrella
- Understand the default security policy, configure their policies
- Install the root certificate and deploy
The customer will exit this stage when they have:
- Configured at least one network or implemented a deployment method and set up at least one DNS policy, or they have received all three emails
Tips for Partner:
- Have your customer watch the DNS deployment on-demand video course
- Share the following documentation with customers for step-by-step guidance on how to get their deployment up and running
- Ensure your customer has successfully added a network identity and pointed their DNS by testing their DNS settings Ensure your customer has a good understanding of DNS policy best practices
- Ensure your customer has setup a root certificate to enable more advanced features later in their deployment. For more guidance, have them watch this on-demand video
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
DNS Deployment Steps Follow up
Preheader: Deploy Umbrella DNS to defend against internet-based threats
Trigger: The customer completed the initial onboarding journey and has logged into their dashboard
Goal: Customer has pointed their DNS to Umbrella
DNS Deployment Steps Follow up
In this stage, the customer will:
- Set up a policy with the DNS Policy Wizard
- Choose which identities to apply the policy to
- Determine which security threats to block and control access to sites and applications
- Set policy order and precedence
- Test your policies
- Schedule reports for visibility
The customer will exit this stage when they have:
- Pointed their DNS to Umbrella
Tips for Partner:
- Ensure your customer has a good understanding of DNS policy best practives
- Support them in configuring a basic Umbrella DNS policy. They will be able to set up more advanced policy settings later in their deployment
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
DNS Policy Configuration
Preheader: Follow these policy best practices
Trigger: The customer completed the initial onboarding journey and has logged into their dashboard
Goal: Customer has pointed their DNS to Umbrella and applied best practices to their Umbrella deployment
DNS Policy Configuration
Guidance on helping your customer adopt UsePlus journey
In this stage, the customer will:
- Bookmark and share reports
- Explore the Top Threats report to highlight a set of threats their organization has been exposed to over a period of time
The customer will exit this stage when they have:
- Once they have received this email
Tips for Partner:
- Guide your customer to the on-demand learning course on Umbrella reports
- Help your customer get familiar with their Umbrella reports and what is available
- Ensure your customer reviews their reports to make sure their policies are working how they want them to be. Reports are a great way to see if policies are working as intended
- Help your customers set up scheduled reports
- Guide your customer through the Umbrella Investigate tool and have them watch this 20 minute Investigate course
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Core feat (Logging and reporting)
Preheader: A look at your network.
Trigger: Customer will enter after they configured DNS
Goal: Encourage customer to utilize reports to monitor their security
Core feat (Logging and reporting)
In this stage, the customer will:
Ensure they have installed the root certificate and added a web destination list in order to continue with the following advanced feature policies:
- Create a custom block page
- Set up tenant controls to manage user access to Sass apps
- Add a Web Selective Decryption list to exclude selected categories
The customer will exit this stage when they have:
- Once they have received this email
Tips for Partner:
- Some advanced policy features must be enabled manually in your customer's ruleset settings. To learn more about all available ruleset settings, ensure they have watched our DNS policy on-demand videos playlist (scroll down to the policy section)
- Customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Feature focus
Preheader: Scale and deploy with these best practices.
Trigger: Customer will enter one week after receiving the Core feat (Logging and reporting) email
Goal: Encourage customer to create and enable advanced policy features
Feature focus
In this stage, the customer will:
- Explore the use cases for APIs and integrations available to them
- Schedule reports to be emailed daily, weekly, or monthly
The customer will exit this stage when they have:
- Once they have received this email
Tips for Partner:
- Ensure your customer is familiar with the different APIs available, and how they can use these APIs to automate time consuming tasks
- The customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Advanced feature focus
Preheader: Automate time-consuming tasks for your Cisco Umbrella DNS solution
Trigger: Customer will enter one week after receiving the Feature focus email
Goal: Customer has enabled and automated APIs and integrations
Advanced feature focus
In this stage, the customer will:
- Complete a health check to ensure their deployment is meeting their security needs
The customer will exit this stage when they have:
- Once they have received this email
Tips for Partner:
- Have your customer register and attend an upcoming DNS health check webinar or watch a recording
- The customer receives this email in their preferred language (EN-US, ES-XL, EN-UK, DE, and EN)
Final checkpoint
Preheader: Maximize your Cisco Umbrella DNS deployment.
Trigger: Customer will enter one week after receiving the Advanced features email
Goal: Customer has completed a health check