Managing endpoint policies at enterprise scale has long meant juggling multiple separate configurations, manually recreating group policies, and spending weeks translating CIS benchmark findings into enforceable settings.
Tanium Enforce was built to address these challenges, but even capable tools carry onboarding friction, particularly for organizations moving from on-premises Active Directory environments to cloud-based Entra ID, or for teams that have accumulated years of group policies they now need to migrate.
In this episode, Tanium Director, Product Management, Enforce Tim Mintner walks through a set of new capabilities designed to fundamentally change how organizations create, import, and manage endpoint policies.
Tim covers two primary goals driving this release: making it significantly easier for new and existing Enforce customers to get up and running, and dramatically accelerating the process of remediating CIS benchmark findings. He demonstrates how what previously required three to four weeks of manual work (translating a new CIS benchmark into actual enforced policies) can now be accomplished through direct import of CIS build kits downloaded straight from the CIS website. Tim also covers the import of Microsoft security baselines and application-level CIS benchmarks, such as Google Chrome hardening settings, all within the same workflow.
Beyond the import capabilities, Tim walks through practical improvements including a dual application method that helps reduce long-standing compliance scan discrepancies between IT operations and compliance teams, extra registry settings that are continuously enforced and cleanly removed when a policy is retired, and a new policy flyout view that lets administrators preview settings without opening the editor.
If your team manages endpoint policy at any scale, this episode covers capabilities you'll want to see in action. Watch the full video below.
Key takeaways
- Consolidated policy creation: Rather than creating 5, 6, 7, 8 separate policies—one each for machine administrative templates, user administrative templates, security settings, BitLocker, and firewall—customers can now combine all of these into a single policy, with the option to consolidate or keep them separate based on organizational standards.
- Keyword search within policy creation: A new search capability inside the policy creation workflow lets administrators search by keyword or registry value to find specific settings across policy types, eliminating the need to manually browse every available option.
“The other thing we're really looking to do with this release is make it very easy for customers to remediate findings for CIS benchmarks... that's a really painful process for many of our customers... So we wanna take that from weeks of time down to seconds of time.”Tanium Director, Product Management, Enforce Tim Mintner
- Extra registry settings enforcement: A new extra registry settings area allows administrators to define custom registry key values that Enforce continuously reevaluates on the endpoint, correcting drift if a value changes, without the setting persisting after the policy is removed.
“Beauty of this is like, it's not tattooed, it means it doesn't stick around if this policy goes away. If this policy goes away, then we will remove that registry setting from that endpoint as well.”Tanium Director, Product Management, Enforce Tim Mintner
- Dual application method for compliance accuracy: A new checkbox allows administrators to apply policy settings via both CSP and LGPO simultaneously, helping compliance scan tools that check only one method more accurately reflect the endpoint's policy state, resolving the finger-pointing that previously occurred between compliance teams and IT operations teams.
- Service management under security settings: Administrators can now manage Windows services directly within a security settings policy, including adding custom services not in the default list, and set them to disabled to help align with CIS recommendations, such as disabling Xbox services on Windows 11 endpoints.
- Direct import of CIS build kits and group policy backups: The import capability in Enforce has been expanded to accept CIS build kits downloaded directly from the CIS website, as well as Microsoft security baseline backups and application-level CIS benchmarks such as Google Chrome hardening settings, helping administrators create configured policies much faster through a streamlined import workflow.
“Our internal IT department said that like it takes them four weeks to do what we just did in like 15 seconds.”Tanium Director, Product Management, Enforce Tim Mintner
- Policy flyout preview: A new flyout view on the policy list lets administrators see the rules and enforcement details for any policy without having to open and edit it, a quality-of-life improvement that reduces time spent navigating policies, especially in environments with inconsistent naming conventions.
- Upcoming—custom ADMX import and nested policies: Two committed future capabilities include the ability to import custom ADMX templates for managing third-party applications, and support for nested policies, the ability to layer firewall policies, app blocker, or other policy types on top of each other into a single set of policy items.
Additional resources
- Ten ways to make endpoint configuration management more effective: A deeper look at how organizations can approach endpoint configuration management at scale, including best practices for policy consolidation and drift remediation.
- Tanium Enforce user guide—policy types, settings, and targeting: The official Tanium Enforce technical home page, with links to documentation on creating and deploying endpoint policies, supported policy types, configuration settings, and targeting options.
