When you need to push a patch to 1,000 machines, deploy software to a specific department, or enforce a security policy across a defined set of endpoints, the question isn't just what action to take. It's who you're targeting.
In Tanium, that answer lives in computer groups. Computer groups are a building block of the platform, used across patching, software deployment, security tooling, and role-based access control to define exactly which endpoints should receive a given action. Without them, targeting endpoints individually at scale becomes unmanageable, and the efficiency that makes Tanium powerful breaks down.
Jesh walks through how computer groups work from the ground up, starting with the out-of-the-box groups Tanium provides and moving into how organizations can create their own using the Filter Builder. She covers how expressions, built from the same sensors used in Tanium questions, determine group membership dynamically, and how those groups connect directly to role-based access control and deployment targeting across the platform.
If you manage endpoints in Tanium and haven't taken a close look at your organization's computer groups, this episode will change how you think about targeting and scale. Jesh also demonstrates live how computer groups appear in the Deploy module when creating a deployment, making the connection between group configuration and real operational use clear and practical. Watch the full episode below.
Key takeaways
- Building blocks for everything: Computer groups are a building block of Tanium, used across patching, deploying security tools, and any action that requires targeting a specific set of endpoints, making them one of the first concepts to understand in the platform.
- Expressions define membership: Each computer group uses an expression, built from the same sensors used in Tanium questions, to filter and determine which endpoints belong to that group, such as "Windows OS type = Windows Workstation." A preview of matching endpoints is available directly from the group configuration page.
“And computer groups let us do exactly that and kind of answer that "Who" question of when we're going to target something or even manage something. Who are we targeting this to? Who in terms of what endpoints do you have the permissions to manage? All of that is defined by a computer group.”Tanium Product Enablement Architect Jesh Sax
- Role-based access control: Computer groups can be assigned as part of role-based access control, so that different administrators manage only the endpoints within their designated group, for example, one person managing Windows workstations and another managing Mac workstations.
- Dynamic groups for departments: Custom computer groups can be built using the Filter Builder to match endpoints by department, naming convention, or custom tag, so that software deployments reach the intended machines based on the selected criteria, such as pushing software only to finance endpoints or grouping by legal department tag.
“Well let's do away with that nonsense. Let's do something like a tag or a dynamic criteria that as endpoints come online that match this, they now are part of that group. So as your environment changes and scales, these groups can adapt as your environment changes and scales, helping account for new endpoints that match the defined criteria.”Tanium Product Enablement Architect Jesh Sax
- Dynamic vs. manual groups: Tanium supports both dynamic and manual computer groups, but manual groups, which list specific hostnames, become outdated as machines are renamed or replaced, making dynamic groups the strongly recommended approach for most production environments.
- Targeting deployments directly: In the Deploy module, computer groups appear directly in the targeting criteria when creating a deployment, making it straightforward to push software, patches, or security tools to a precisely defined set of endpoints. The same targeting approach applies across patching, BitLocker enforcement, security tooling, and file integrity monitoring.
“If you're not familiar with your organization's computer groups, because we've been showing you our default out-of-the-box Tanium computer groups, right? Your organization probably has some ones that are more customized and make more sense to you. They might be based off department, off of different access controls. Jump into, if you have the permissions, that Administration and Computer Groups, and take a look at the groups that your organization has and kind of try to start thinking through, "Oh, why do we have this group? Where do I use this other one?" to get yourself familiar with your environment and the options that you have in targeting things.”Tanium Product Enablement Architect Jesh Sax
Additional resources
- Tanium Console and Interact overview: Learn how the Tanium Console GUI, Interact module, and Data Service work together to help you query endpoints, deploy actions, and manage your environment at scale.
- Best practices for deploying large files with Tanium Deploy: Learn how the two-package approach and single-package method compare when distributing large files across bandwidth-sensitive environments.
- Navigating the Tanium console—Tanium Tech Talks #154: In the inaugural episode of the Tanium Basics series, Jesh Sax walks through every major section of the console to give new and experienced administrators a practical orientation to the platform.
