Skip to main content
Endpoint grouping strategies for targeted IT operations - Tanium Tech Talks #160 video thumbnail
Module Deep Dive

Endpoint grouping strategies for targeted IT operations: Tanium Tech Talks #160

Computer groups are the unsung foundation of every targeted action in Tanium, and Tanium Product Enablement Architect Jesh Sax delivers a practical, step-by-step walkthrough of how to build, configure, and use them to manage endpoints at scale with precision and control. This episode is part of the Tanium Basics series, which covers the core concepts and building blocks you need to get the most out of the Tanium platform.

When you need to push a patch to 1,000 machines, deploy software to a specific department, or enforce a security policy across a defined set of endpoints, the question isn't just what action to take. It's who you're targeting.

In Tanium, that answer lives in computer groups. Computer groups are a building block of the platform, used across patching, software deployment, security tooling, and role-based access control to define exactly which endpoints should receive a given action. Without them, targeting endpoints individually at scale becomes unmanageable, and the efficiency that makes Tanium powerful breaks down.

Jesh walks through how computer groups work from the ground up, starting with the out-of-the-box groups Tanium provides and moving into how organizations can create their own using the Filter Builder. She covers how expressions, built from the same sensors used in Tanium questions, determine group membership dynamically, and how those groups connect directly to role-based access control and deployment targeting across the platform.

If you manage endpoints in Tanium and haven't taken a close look at your organization's computer groups, this episode will change how you think about targeting and scale. Jesh also demonstrates live how computer groups appear in the Deploy module when creating a deployment, making the connection between group configuration and real operational use clear and practical. Watch the full episode below.

Key takeaways

  • Building blocks for everything: Computer groups are a building block of Tanium, used across patching, deploying security tools, and any action that requires targeting a specific set of endpoints, making them one of the first concepts to understand in the platform.
  • Expressions define membership: Each computer group uses an expression, built from the same sensors used in Tanium questions, to filter and determine which endpoints belong to that group, such as "Windows OS type = Windows Workstation." A preview of matching endpoints is available directly from the group configuration page.
And computer groups let us do exactly that and kind of answer that "Who" question of when we're going to target something or even manage something. Who are we targeting this to? Who in terms of what endpoints do you have the permissions to manage? All of that is defined by a computer group.
Tanium Product Enablement Architect Jesh Sax
  • Role-based access control: Computer groups can be assigned as part of role-based access control, so that different administrators manage only the endpoints within their designated group, for example, one person managing Windows workstations and another managing Mac workstations.
  • Dynamic groups for departments: Custom computer groups can be built using the Filter Builder to match endpoints by department, naming convention, or custom tag, so that software deployments reach the intended machines based on the selected criteria, such as pushing software only to finance endpoints or grouping by legal department tag.
Well let's do away with that nonsense. Let's do something like a tag or a dynamic criteria that as endpoints come online that match this, they now are part of that group. So as your environment changes and scales, these groups can adapt as your environment changes and scales, helping account for new endpoints that match the defined criteria.
Tanium Product Enablement Architect Jesh Sax
  • Dynamic vs. manual groups: Tanium supports both dynamic and manual computer groups, but manual groups, which list specific hostnames, become outdated as machines are renamed or replaced, making dynamic groups the strongly recommended approach for most production environments.
  • Targeting deployments directly: In the Deploy module, computer groups appear directly in the targeting criteria when creating a deployment, making it straightforward to push software, patches, or security tools to a precisely defined set of endpoints. The same targeting approach applies across patching, BitLocker enforcement, security tooling, and file integrity monitoring.
If you're not familiar with your organization's computer groups, because we've been showing you our default out-of-the-box Tanium computer groups, right? Your organization probably has some ones that are more customized and make more sense to you. They might be based off department, off of different access controls. Jump into, if you have the permissions, that Administration and Computer Groups, and take a look at the groups that your organization has and kind of try to start thinking through, "Oh, why do we have this group? Where do I use this other one?" to get yourself familiar with your environment and the options that you have in targeting things.
Tanium Product Enablement Architect Jesh Sax

Additional resources