Standing privileges are one of the most persistent and underappreciated risks in enterprise IT environments. Contractors who left months ago, support engineers with broader access than their role requires, and sessions that were never properly closed—these are the conditions that create exposure.
Jump Gate is Tanium's answer to that problem. It removes standing privileges and replaces them with just-in-time and just-enough access, giving organizations a structured, auditable way to control who can reach which endpoints, when, and under what conditions. The product grew out of an internal Tanium tool called Lockbox, developed to meet Tanium's own secure access needs, and was brought to market after customers who heard about it responded with enthusiastic demand.
Nat covers the full scope of how Jump Gate works in practice: from how access policies are constructed and prioritized, to how approval requests flow through Slack and Teams notifications, to how every session is recorded and stored for audit purposes. She also explains the three distinct roles available within Jump Gate, how the product leverages existing Tanium agent connections without requiring new ports or infrastructure changes, and how a planned integration with ScreenMeet will extend Jump Gate's capabilities to include screen sharing and file transfer within the same audited framework.
If you manage endpoint access, support engineers, or privileged sessions in any capacity, this episode covers capabilities that directly affect how your team operates day to day. Nat also shares early customer feedback, including responses from organizations that evaluated Jump Gate as a replacement for existing privileged access solutions, and previews what's still to come beyond the initial release. Watch the full episode below to see Jump Gate in action.
Key takeaways
- Built from internal tooling: Jump Gate evolved from an internal Tanium product called Lockbox, which was developed out of Tanium's own need for secure access—and was brought to market after customers responded enthusiastically when they heard about it.
- Access policies are foundational: Jump Gate does not work without access policies in place, and those policies evaluate who is requesting access, what they're requesting access to, and whether that requires an extra approval.
- Replacing standing privileges: Jump Gate is designed around the principle of removing standing privileges and replacing them with just-in-time and just-enough access, with access policies built to be flexible enough to accommodate different industries, environments, and user definitions of what those terms mean.
“We remove standing privileges and we replace it with just in time and just enough.”Tanium Lead Product Manager Nat Dunlap
- Slack and Teams approval notifications: When an access request requires approval, Jump Gate supports external notifications to both Slack and Teams channels—the direct result of customer feedback telling Tanium, "Don't give us any more emails."
- Session recordings for audit: Jump sessions can be recorded and stored individually, capturing activity flowing through the connection so that IT managers, forensics teams, and auditors can review what was done, when, and by whom without requiring administrators to manage that process manually.
- No new ports or infrastructure: Jump Gate uses the existing Tanium agent connection to provide remote access into endpoints, meaning that, in most environments, customers can use Jump Gate without opening new ports or adding new infrastructure, firewall changes, or whitelisting requirements.
“No, we are definitely using the existing Tanium agent connections, actually, so we're not opening up anything new within our customers' environments—no new ports, no firewall, no whitelisting, no new infrastructure. If the Tanium agent is there within the endpoint, that is actually what we're leveraging for the CX connection, and that is how we're able to provide this remote access into endpoints for our customers to leverage.”Tanium Lead Product Manager Nat Dunlap
- Three distinct roles: Jump Gate ships with three scoped roles—Jump Gate Auditor (view-only access to activity), Jump Gate Operator (admin configuration and access policy management), and Jump Gate User (the core role for requesting endpoint access)—designed to let customers bring new users into the platform with tightly controlled permissions.
- ScreenMeet integration planned: Tanium plans to make ScreenMeet a jump target within Jump Gate, allowing help desk engineers to request a ScreenMeet session that, once approved, delivers ScreenMeet's screen sharing, file transfer, and chat capabilities alongside Jump Gate's full auditing with cloud customers receiving Jump Gate at general availability first, and on-premises support planned for a later release.
“Right now it feels like we're giving a little bit of an appetizer feel to what Jump Gate is truly capable of.”Tanium Lead Product Manager Nat Dunlap
Additional resources
- Tanium Jump Gate: just-in-time, just-enough access to critical endpoints: Learn how Jump Gate helps organizations replace standing privileges with controlled, auditable access using their existing Tanium agent infrastructure.
- Jump Gate overview and access policy configuration in Tanium: Documentation covering how Jump Gate works, how to set up access policies, and how approval workflows are evaluated within the Tanium console.
- Managing and maintaining Tanium Jump Gate—roles, sessions, and operational settings: Technical reference for day-to-day Jump Gate administration, including session management, role assignments, and configuration settings for request expiration and data retention.
