Tanium Inc Cloud
Simplifies Endpoint Management, Needs Better Reporting
Real-time visibility that transformed our incident response
The single-console design covering asset discovery, patching, compliance, and threat response means our team isn't jumping between five different tools anymore. This alone has saved us several hours a week that used to go into manually correlating data across systems.
Integrations with our existing SIEM and ticketing systems were straightforward to set up, and the platform's linear chain architecture means it scales without the performance hit we used to see with agent-heavy tools that bogged down endpoints and network bandwidth.
On the AI/intelligence side, the risk scoring and automated prioritization have been genuinely useful for surfacing the vulnerabilities that actually matter instead of drowning us in low-priority alerts.
Onboarding did take some investment upfront; the initial deployment and getting our team comfortable with the query syntax took a few weeks, but Tanium's support team was responsive throughout, and once ramped up, the ROI became clear: fewer blind spots, faster patch cycles, and less time spent stitching together data from disconnected tools.
The module licensing and pricing structure can also be confusing, since features are split across separate modules (Patch, Comply, Threat Response, etc.), and it isn't always clear upfront what's included versus what requires an add-on purchase. This has occasionally caused budget surprises during renewal conversations.
Report and dashboard customization feels more rigid than I'd like; building tailored views for different stakeholders (security vs. IT ops vs. compliance) often requires workarounds rather than native flexibility, which adds extra effort when preparing cross-team reporting.
Console performance can also lag when running very broad, unfiltered questions against the full endpoint fleet, and the error messaging in those cases isn't always clear about whether the issue is query design, network latency, or endpoint responsiveness; better diagnostic feedback here would save troubleshooting time.
Finally, documentation for some of the more advanced sensor authoring and API integration scenarios is sparser than I'd expect for an enterprise platform at this price point, often requiring a support ticket to fill in gaps that could be solved by more detailed public docs or example libraries.
We also struggled with slow patch and vulnerability remediation cycles, often taking weeks to confirm that a critical patch had actually been applied across all endpoints. Now we can push patches and validate completion in near real time, which has shortened our patch compliance cycle significantly and reduced our exposure window to known vulnerabilities.
Incident response used to be a major pain point: when a threat was detected, it often took our security team hours to scope which endpoints were affected because we had to pull data from several disconnected tools. With Tanium's unified console, we can now identify and isolate affected endpoints within minutes instead of hours, which has directly reduced the potential blast radius of incidents.
Compliance reporting was another area of friction; audits used to require manually compiling data from multiple sources, consuming several days of staff time per audit cycle. Now that reporting is centralized and largely automated, we've cut that prep time down substantially, freeing up our compliance team to focus on remediation instead of data gathering.
Overall, the combination of real-time visibility, faster patching, and quicker incident response has reduced the operational overhead on our IT and security teams and lowered our overall risk exposure, translating into measurable time savings and a stronger security posture.
Real-Time Asset Discovery with Robust Features
Real-Time Endpoint Visibility and Control in One Platform
Reduces security risk by identifying and fixing vulnerabilities
Speeds up incidents response
Automated routine tasks
Effective for Configuration Management with Room for Improvement
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
What is our primary use case?
Implementation is based on client requirement and we don't create any particular policies or any rules among all the networks. The decision is completely based on client-side requirement. Analytics are also completely based on client requirement. To the end users, everything is completely provided by the client. We don't know exactly what they have invested in the particular tool or the subscription value. However, I can suggest that it plays a main role while any high alert is going on and it should be present in any endpoint or any user's machine within enterprise-level security patches.
What is most valuable?
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use.
We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5.
Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.
What needs improvement?
In my opinion, sometimes it takes a long time to give solutions or resolve the issue. Tanium side team will respond instantly but sometimes they are delaying in the response. These are the two major causes which I have observed so far. Additionally, while remotely connecting, sometimes it automatically disconnects and the issue is still unresolvable. We are working on that, but it is still a question mark.
For how long have I used the solution?
I have four years of experience in cybersecurity and I have experience with Tanium for around two years.
Which solution did I use previously and why did I switch?
I am not using Sophos products like Cloud Optix or Sophos Labs. Previously, I worked in one organization which used Sophos Firewall Endpoint and XDR, and SecurOn as well. However, I have joined a new organization and they are not using either SecurOn or Sophos.
How was the initial setup?
It is completely simple and no need for any tension while installing it.
What was our ROI?
Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection.
What's my experience with pricing, setup cost, and licensing?
It is moderate. It is not that much too costly or really that much low cost, but it is moderate.
Which other solutions did I evaluate?
Splunk or CrowdStrike are competitors for Tanium right now. However, Tanium is still at the top.
What other advice do I have?
We are not reselling Tanium but we are taking services from them. Implementation is based on client requirement. The review rating for this product is nine out of ten.
Real-Time Endpoint Visibility and Powerful Automation in One Platform
Simplifies Security with Real-Time Visibility
Real-Time Endpoint Management, Seamless Setup
Lightning-Fast Endpoint Queries with Powerful Custom Automation
The appeal of their platform is how they pull this off. Being able to live-query or execute across 10,000 endpoints in 30 seconds is pretty awesome.
I tend to skip a lot of the out-of-the-box stuff, because it’s almost never designed for anyone’s specific use case. For me, the real benefit is the platform itself and the custom content you can build on top of it.
Sensors are custom-designed scripts to gather whatever data you want, in whatever two-dimensional way you want. Packages let you deploy scripts to make changes to systems, whether that’s uninstalling, installing, changing reg keys, updating group policy, etc. Automate lets you chain sensors and packages together for more advanced routines—think downtime procedures, or a series of if/then/else steps.
The biggest benefit for me has been using it to answer C-suite questions immediately. They ask something, I write a short sensor script, push it out, and I instantly have an answer. From there, I can chain it into a package to fix the underlying problem, and then schedule that sensor and package to run automatically. In an afternoon, it becomes something I don’t have to worry about again.
If you get caught up in all the frills and extra stuff they layer on top, you might be disappointed—unless what they built happens to match your exact use case. But if you think of it mainly in terms of those three (really just two) core pieces, and you have people you can dedicate to learning and using it well, it’s a great tool.
Besides that, it depends what modules your new company owns. Modules are add-ons you can purchase from Tanium. One does patching. Another scans for vulnerabilities. Another does file integrity monitoring. So it's a fairly wide range of possibilities.
We run Tanium alongside our anti-virus solution. Tanium provides documentation on the exclusions. They also provide free training.