For years, Tanium's visibility has been scoped to endpoints running the Tanium client: Windows, Mac, and Linux devices. But IT administrators and security leaders are responsible for securing and managing far more than that. Mobile devices, Chromebooks, and other endpoints that cannot run the Tanium client have remained outside that unified view, forcing teams to work across multiple consoles and reconcile data from disconnected sources.
The Tanium Connector for Microsoft Intune is among the first of our capabilities released in support of our endpoint expansion initiative, a deliberate effort to bring outside device data into Tanium as native attributes, making those devices look and behave just like any other managed endpoint in the console.
Tim walks through the full scope of this integration: how it works inside the Tanium Integrations Gallery, how to configure connections to multiple Intune tenants, what the new "from all entities" query syntax means for day-to-day operations in Tanium Interact, and how teams can take action on Intune-managed devices directly from the Tanium single endpoint view. He also covers the RBAC model for controlling who can perform standard vs. high-impact device actions, and how synchronized mobile device data can flow into ServiceNow through Tanium's asset integration.
If your organization manages mobile devices through Microsoft Intune, or experiences visibility gaps across multiple Intune tenants, this episode covers capabilities that directly address those challenges. Watch the full video below to see it in action.
Key takeaways
- Endpoint expansion initiative: Tanium is bringing devices that cannot run the Tanium client, starting with mobile devices managed through Microsoft Intune, natively into the Tanium ecosystem, just like any other Tanium client device.
“We are bringing in those mobile devices and making those mobile devices native into the Tanium ecosystem, just like any other Tanium client device, even though they are not running the Tanium client.”Tanium Product Manager Tim Mintner
- New "from all entities" syntax: Tanium has updated the query language in Interact for the first time, replacing "from all machines" with "from all entities," where an entity can be any number of providers, including a Tanium client or Microsoft Intune, with additional provider types planned for future releases.
- Licensing requirements: On the Microsoft side, any access to Intune, including through a Microsoft 365 E3 or E5 license or a standalone Intune purchase, is sufficient. On the Tanium side, the endpoint management solution (which includes Deploy, Patch, and Performance modules) is required, and Intune endpoints do not require per-device Tanium licensing.
- Multi-tenant support with near-real-time sync: The connector supports up to 20 Intune tenants simultaneously. On first configuration, it performs a full sync of all mobile devices visible in Intune; after that, it checks for changes every two minutes and brings in those deltas.
“So even though Intune is not necessarily a real-time platform, Tanium is bringing in that data from Intune in as about as real-time as you can get. So it's generally within two minutes of a change that is occurring on Intune—we're bringing that data into Tanium.”Tanium Product Manager Tim Mintner
- Actions from single endpoint view: Users can take actions on Intune-managed devices directly from the Tanium console, including standard actions such as reset passcode, remote lock, restart device, and custom notification messages, as well as high-impact actions such as wipe device and retire device. Action history reflects activity from both the Tanium console and the Intune console.
- RBAC for Intune actions: Two specific RBAC roles, Intune action user and high impact action user, control who can perform standard versus high-impact actions on synchronized devices, allowing organizations to limit access to consequential actions like full device wipe or retire device.
- ServiceNow integration for mobile devices: Mobile device data synchronized from Intune into Tanium can be pushed into ServiceNow through Tanium's asset integration. A new "Tanium Entity Providers" setting inside assets allows administrators to explicitly enable this synchronization, giving teams control over when mobile devices begin appearing in ServiceNow.
- Scale validated in production: The largest synchronization to date involved just under about 70,000 devices synchronized into the Tanium console in under two minutes, with incremental updates running every two minutes from that point forward to capture any changes.
Additional resources
- Tanium Endpoint Management—unified management across all endpoint types: Learn about the Tanium endpoint management solution, which includes the deploy, patch, and performance modules required to use the Tanium Connector for Microsoft Intune.
- How the Tanium Connector for Microsoft Intune extends autonomous endpoint management to mobile devices: Explore how integrating Tanium with Microsoft Intune closes mobile device visibility gaps and supports unified endpoint management across complex enterprise environments.
- Configuring the Tanium Connector for Microsoft Intune: Step-by-step documentation covering how to enable the Intune integration in the Integrations Gallery, connect one or more Intune tenants, and begin synchronizing mobile device data into the Tanium console.
- Introducing the Tanium Integrations Gallery and entity provider capabilities: Technical reference covering the Integrations Gallery, including how the new entity provider model and "from all entities" query syntax support multiple provider types alongside the Tanium client.
