Infoblox IQ detects issues, diagnoses root cause and surfaces a recommendation—before anyone files a ticket.
Why We Built Infoblox IQ
I’ve spent a lot of time over the last year sitting with customers. At their offices, at our EBCs, in roadmap reviews, on our Customer Advisory Board and in 1:1 chats about where AI is going. When you ask network and security operators what’s breaking their week, the answers are consistent. And they are the problems we set out to solve.
A network lead at a large retailer told me, “I don’t want more insights and alerts, I already have enough of those. What I want is someone to take the next step, troubleshoot things like I would do and tell me what to do next.” His tools already tell him what’s wrong. What they don’t do is take the next step. By the time he’s catching up on a red chart, his boss is already asking why he didn’t get ahead of it.
A security lead at a global enterprise told me his SOC team is drowning in alerts. They have the tools to detect threats. What they don’t have is the time to investigate which alerts are real, which users and devices are at risk, and what to do about it. The gap is not detection. It is everything that comes after.
A networking architect at a large hospitality customer told me he wants to give his help desk a way to ask DNS questions in plain language, so the help desk can resolve issues without escalating. Today, every ticket finds its way back to the same handful of DDI experts. Those experts are expensive, hard to hire and harder to keep.
And almost every customer asks me the same thing about AI. “Will I be able to plug your data into my own agents?” One customer told me directly that an external Model Context Protocol (MCP) framework was critical. Another has already started building one. These customers are not waiting for any one vendor to ship the perfect assistant. They are building agentic workflows themselves, and they need network truth to ground those agents.
Three patterns. Increasing complexity. A widening expert gap. Response delays that are now costing real money.
That is why we built Infoblox IQ.
For more than 25 years, Infoblox has held the most authoritative record of what is happening on an enterprise network—every device, every IP address, every DNS query. What Infoblox IQ adds is the layer that reasons across all of it and takes the next step, so operators don’t have to.
How Infoblox IQ Works
Infoblox IQ is an agentic AI operations layer for network and security teams. It runs across the Infoblox Platform and grows with it, turning the most authoritative data on your network into something that detects issues, investigates incidents, surfaces the right actions to resolve them and puts the operator in the right place in the loop.
Three things shape how Infoblox IQ works.
First, it runs on network truth. DNS, DHCP and IP address management (IPAM) are the authoritative record of what is happening on the network. DNS is the first protocol touched in most attacks. By the time a threat shows up in a security information and event management (SIEM) or endpoint detection and response (EDR), the connection has already been made. Configuration state is not inferred from change tickets; it is the system of record. An agent reasoning from a representation of the network gives different answers depending on which downstream system it queries—and the operator has no way to know which one is right. Infoblox IQ runs on the data directly. Same source. Same answer. Every time.
Second, the agents are built on 25-plus years of operating experience, not on a generic model pointed at network data. We learned this the hard way. We started this work believing the frontier models would figure DDI and DNS security out on their own. Give them the data, give them a good prompt, let them reason. They couldn’t. Not reliably, not at the depth an operator needs. The models are powerful, but they don’t know the many reasons DNS latency or SERVFAIL errors suddenly spike—or what to do about each one. So we changed our approach. We took 25-plus years of Infoblox operating knowledge (what fails, what drifts, what matters, what to ignore, what a good operator does next) and built that into Infoblox IQ. The agents are built by the people who have spent their careers running these systems in production. That is the difference between a chatbot that sounds confident and an agent you can actually trust with your network.
Third, AI actions are designed to close the loop between insight and action. The hardest part of operations is not noticing something is wrong. It is getting from “noticed” to “resolved.” That gap is where the time, cost and frustration sit.
AI actions are built to compress that gap. The agent does what a strong human operator would do, just much faster. It spots the issue, often before users feel it. It pulls the relevant data, analyzes it, finds the root cause and produces a recommendation. All of that runs in the background, in seconds. By the time the operator picks up the ticket, 90 percent of the work is already done. They can dig in further with the agent or apply the recommendation and move on.
Infoblox IQ automatically investigates threats in Infoblox Threat Defense™ and hands the analyst a confirmed scope and remediation options. A configuration drift in DDI (a DNS record edited by hand, a DHCP scope quietly modified, a recursion setting flipped by a script no one tracked) shows up with the context to act, not just an alert.
Three numbers move because of this. MTTR (mean time to respond) drops, because Infoblox IQ surfaces issues before anyone files a ticket. MTTR (mean time to resolve) and MTTI (mean time to innocence, the hours DDI teams burn proving the problem isn’t theirs) drop for the same reason—most of the diagnostic work is already done when the human arrives. All three are too high in most enterprises today.
How much autonomy Infoblox IQ gets is the customer’s call. We start with recommendations for the operator to review and approve. As trust builds, customers can pre-authorize Infoblox IQ to execute specific, well-bounded workflows on their behalf, with full autonomy available for selected workflows down the road. DDI is foundational to how an enterprise runs, and we are not going to push autonomy faster than customers want it. Every action, regardless of mode, is logged and auditable.
To the customer who said he didn’t need more alerts, just someone to take the next step, this is exactly what he asked for. Troubleshooting already done. A recommendation ready. An action he can approve.
Automated Actions, Conversational AI and Extensibility
These will be available in the tools and workflows customers already use:
Infoblox IQ for Threat Defense takes a large volume of DNS security signals, distills them into a small number of confirmed threats, traces each one across affected users and devices, and presents the analyst with a confirmed scope plus a set of remediation options for approval. Existing SOC Insights customers can move over with zero friction.
Infoblox IQ for DDI enables AI actions for DNS on Infoblox Universal DDI™. Infoblox IQ surfaces operational issues with full context and a recommendation, executed through approval workflows the operator controls. Support for DHCP, IPAM and NIOS will follow in the coming weeks. Customers can start with what’s available today and expand as we enable the rest.
The Infoblox IQ AI assistant is available across the portfolio as the conversational layer of Infoblox IQ. It answers natural language questions about network state, security threats and assets. It translates plain English into precise configuration changes. This core capability embedded with every Infoblox product is available at no extra charge.
The Infoblox Model Context Protocol (MCP) Server is open by design and included with Infoblox products. Customers, partners and developers can build their own agentic apps on top of Infoblox network, security and asset data. They can connect Infoblox agents to AI systems from other vendors for agent-to-agent workflows that span network, security and broader IT operations.
The Infoblox Model Context Protocol (MCP) Server is built on a simple belief. Customers should not be locked into any one vendor’s AI agents, including ours. They will create agents tailored to their own environments and use cases, and some may be more effective than anything we could build ourselves. We provide the trusted data, open standards and an extensible platform that will allow customers to build, connect and orchestrate the agents they need today and in the future.
What Comes Next
Network and security teams are being asked to manage more infrastructure, against more threats, on a tighter clock than ever before. The answer is not another console. It is not another assistant. It is an operations layer that closes the gap between what the network already knows and what teams can act on.
To every customer who told me they wanted someone to take the next step instead of more alerts, actions an operator can approve instead of tickets to chase and an open platform they can build on: June 3 is the start. The teams that will get the most out of Infoblox IQ are the ones who stop treating it as a reporting tool and start treating it as a colleague who already knows their environment.
The roadmap goes much further, but the foundation is in place. And we built it because customers asked us to.


