Stop threats before compromise for every customer you serve. Enhanced multi-tenancy for Infoblox Threat Defense™ helps MSSPs deliver stronger, more scalable protection across every customer environment.
Count the tenants your security operations center (SOC) carried this time last year. Then count them today. For most managed security service providers (MSSPs), the second number is meaningfully larger, and the analyst roster behind it looks about the same.
That is the shape of a healthy managed security business. It is also where the delivery model starts to drive margin decisions. The useful question is not whether threats are rising. Everyone here knows they are. It is where your control sits, because that decides how much work ever reaches an analyst.
Where the Control Sits Decides the Rest
Attacker infrastructure is disposable by design. The Infoblox 2026 Threat Landscape Report, published in July 2026 on an analysis of trillions of Domain Name System (DNS) queries, found that 44 percent of threat-related domains stayed active for just one day. The analysis also found that 88 percent appeared in no more than a single environment. More than 22 percent of newly observed domains showed malicious or suspicious characteristics.
Read those three numbers together, and a familiar assumption falls apart. A domain that lives for one day and touches one customer will never produce a shared indicator in time to matter. By the time it could be cataloged, the campaign has moved on.

Figure 1. AI and automation help threat actors increase sophistication, generate disposable domains at scale and adapt malicious traffic in real time.
Artificial intelligence (AI) is what made that economical for the attacker. The same research describes a cybercrime economy where campaigns are assembled from rented infrastructure and purchased kits. AI cut the cost of creating convincing phishing content, fake sites and multilingual lures. Personalization used to be expensive, so it was aimed at high-value targets. Now it is cheap enough to aim at everyone.
None of this is an argument for alarm. It is an argument about where the control must sit.
If the infrastructure is disposable and the lure is tailored, then a service built on recognizing known bad is always working one step behind. The gap is measurable. Infoblox Threat Defense is Protective DNS powered by predictive threat intelligence, and it blocks five times more risky domains than tools that rely only on known malicious behavior. The control has to act on the infrastructure before it is weaponized. That means acting at the point where nearly every connection begins, which is DNS. Prevention there is not an earlier version of detection. It is a different posture, one which stops the criminals while they are outside casing the house before the planned intrusion.
That is the case for Protective DNS for MSSPs, and it is as much an economic argument as a security one. Every threat stopped before the first query is an investigation your analysts never open. And it is an incident your customers never need to respond to.
The Category Has Public Standing
You do not need a vendor’s word for this. Protective DNS is the recognized term for a service that inspects DNS queries and acts on them before a connection is made. The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) set out how to select and evaluate DNS in joint guidance published in March 2021. The U.K. National Cyber Security Centre (NCSC) runs its own Protective DNS service for public sector bodies. That is unusually solid ground for a managed offer. Your customers can look the category up without reading a datasheet.
What Becomes Generally Available in October
Infoblox makes DNS the first line of defense, blocking 90 percent of threats before the first query and detecting threats an average of 68 days earlier than other tools. The false positive rate is 0.0002 percent, measured across more than 20 million indicators on customer-reported impact rather than in a laboratory. That matters less as a headline than as a description of where analyst attention goes. That time advantage does not come from a purchased feed. Infoblox Threat Intel applies algorithmic and machine-learning analysis to DNS query data at scale, combined with DNS expertise, to identify attacker infrastructure as it is built and block it before it is weaponized, before anyone reports an attack.
On October 15, 2026, enhanced multi-tenancy for Infoblox Threat Defense reaches general availability. This operating model lets you deliver that advantage across every customer at once, rather than one at a time. It advances the invite-only MSSP sub-track of the Skilled to Secure, Trusted Partner Program, announced in January 2026 and already live. October delivers the layer that makes it scale.
The Question Your SOC Has to Answer
Here is a question every practice lead has fielded under pressure. A significant threat surfaces on a Monday morning. Which of your customers were hit, and when?
Answering that today often means working through each environment in turn, assembling the picture by hand. The customer on the phone does not care how many others you carry. They care whether you can tell them where they stand, and how quickly.
Infoblox IQ™ for Threat Defense answers that question directly. It turns telemetry from every customer you protect into focused SOC action, so your analysts can see which customers a threat reached and when. They can cover more tenants without stitching together data environment by environment or adding analysts.

Figure 2. A single Protective DNS policy extends from an MSSP’s SOC across every customer environment, stopping threats before the first query.
What Else Do You Get?
The rest is the machinery that makes a preemptive service profitable to run at scale.
Policy is authored once and applied across every tenant, so you do not copy settings customer by customer and hope they hold. Tenant Organization Groups let you group customers by whatever hierarchy your business actually uses. Service-provider roles govern who on your team can act, and where. Per-tenant entitlement sets what each customer receives, which gives you good, better and best packaging without separate deployments. Cross-tenant dashboards show security, operations and consumption usage, and tenant reporting gives each customer their own view. You self-manage the tenant lifecycle throughout, without Infoblox intervention in tenant operations so you can launch and scale the service profitably across your portfolio. Programmatic application programming interface (API) access wires it into the systems you already run, and billing is post-paid, per user.
Why This Holds Up Commercially
The commercial case rests on four operating metrics every practice leader already tracks: incidents avoided, analyst hours saved, response time and cost to serve.
Earlier threat disruption means fewer incidents reach the stage where they burn analyst hours. Alerts that never fire do not become cases or tickets, which can lower analyst effort and cost to serve and help protect margin as you scale. Fewer low-value investigations mean the same team covers more customers, and Infoblox IQ for Threat Defense saves the SOC operating it an average of 500 analyst hours per month. Faster response makes contracted service levels easier to hit, because threats close in minutes instead of hours. A cost to serve that no longer climbs with every new logo means forecastable margin. Protective DNS for MSSPs stops being a specialist add-on and becomes a service you sell into every account.
How This Sits Alongside the Stack You Already Run
Every MSSP evaluating a new control asks the same question first. What does this replace?
Usually nothing. Managed detection and response (MDR) is your category and your margin. Infoblox does not sell MDR and does not run your SOC. We supply a DNS-layer control that feeds the service you already deliver, whether you take it to market as MDR, extended detection and response (XDR) or SOC as a service. The analysts stay yours. So does the customer relationship.

Figure 3. Infoblox supplies a Protective DNS control and cross-tenant SOC intelligence; enhanced multi-tenancy is the operating model MSSP partners use to deliver both consistently across every customer.
It does not displace the rest of the stack either. Your security information and event management (SIEM) platform correlates. Your secure web gateway inspects traffic. Your next-generation firewall enforces at the perimeter. Endpoint protection defends the device. Each acts on a different point in the kill chain, and DNS sits earlier than all of them. Sitting earlier shows up downstream. Customers report up to a 50 percent reduction in alerts on next-generation firewall and endpoint detection and response (EDR) systems, because a connection blocked at DNS never becomes an alert anywhere else. Correlated DNS events flow into the SIEM as another high-value source, not a substitute for it.
The real contrast is not with those products. It is the posture the stack produces. An EDR and SIEM-led operation is built to detect and respond, which means something must happen first. Someone clicks. A device beacons. An alert is triggered and the clock starts. That model works, and your customers pay for it. But it always begins after the fact. There is a patient zero in every one of those investigations.
Prevention at the DNS layer changes the order. The connection fails before the session exists, so there is no beacon to chase and no host to rebuild. Protective DNS for MSSPs does not replace detect-and-respond. It reduces how often you need it, or put another way, it reduces the number of patient zeros.
Who This Is For
The Infoblox Protective DNS capability is built for MSSPs with SOC-led delivery running MDR, XDR or SOC as a service for multiple customers.
If you have no DNS-layer prevention in your service today, this is a new line you can sell into your existing base, opened with proof-of-concept engagements and free assessments. If you already run a mature detect-and-respond practice, it covers the gap the endpoint agent never reached, on the unmanaged and off-network devices your customers keep adding. Either way, the enhanced multi-tenancy layer means you can now operate enterprise-grade DNS protection at MSSP scale. The MSSP sub-track post from January covers the enablement and program benefits in more detail.
Your Next Step
Reach out and learn more. Talk to your Infoblox partner team about what a preemptive DNS-layer service looks like in your portfolio and see the partners already delivering managed services on Infoblox.

