In-Person Labs

Peruse the list of In-Person Labs being offered at Converge 2023 below and use the filters to narrow down which best fit your needs and expertise.

More information about In-Person Labs can be found here.

Description Difficulty Modules More Info
Better Together: Unleash the Power of Tanium and ServiceNow with the ITAM Service Graph Connector

Gain hands-on experience with Tanium Asset and Discover and practice how to make the ServiceNow Configuration Management Database (CMDB) accurate and complete.

This topic becomes increasingly more important, as security and business processes, in addition to IT, are relying more and more on the CMDB. This is the backbone of Tanium’s strategic partnership with ServiceNow: to improve data, automation, and remediation for ServiceNow workflows.

In this lab, you will use the ServiceNow Service Graph connector for Tanium and Tanium Connect as the standard integration methods for Tanium Asset and Discover data. You will also learn how Tanium fully supports ServiceNow’s Common Services Data Model (standardized way of organizing and storing information about IT services and their components). Let’s aim for a 100% complete and accurate CMDB so work will flow more smoothly in ServiceNow!

Pre-Req(s): Administrative knowledge of Tanium; basic administrative knowledge of ServiceNow. Attendees will need to have access to a ServiceNow developer instance, which can be requested at developer.servicenow.com prior to Converge. It is also recommended to also install in your ServiceNow dev instance the Service Graph connector for Tanium via All>Available applications.

IntermediateAsset, Connect, Core, Discover
Building Custom Solutions With Tanium Reporting

Learn how to use Tanium's Reporting dashboards to create user interfaces for Tanium-powered workflows. In the first part of the lab, you will learn how to create an example Dashboard tracking usage of specific expensive software suites and connecting Tanium Actions to clean up those products where unused. In the second part, you will learn the tips, tricks, and best practices for developing your own custom workflows within Tanium.

Pre-Req(s): Basic understanding of Tanium and Tanium Custom Content (WBT Course Registration Link)

AdvancedPlatform
Certificate Manager - Making Sure Your Secure Communications are Secure

Keeping track of all the certificates in your enterprise can be laborious and time-consuming. It is often hard to know how strong or trustworthy those certificates even are. Tanium Certificate Manager speaks to all those problems. In this lab, you’ll learn how to quickly install, configure, and use Certificate Manager to gain true visibility over your certificate estate. You will understand how the module works, what information you can gather and distribute, and how to remediate uncovered problems.

Pre-Req(s): Basic understanding of Tanium and modules. General knowledge of SSL/TLS certificates.

IntermediateConnect, Discover, Reporting, Certificate Manager
Creating Custom Content to Solve Those Complex Business Challenges

Tanium was built to run code across vast numbers of endpoints at global scale in seconds, with the flexibility to solve the difficult problems unique to your organization by being highly customizable. Tanium is pretty comprehensive but can't predict EVERY question you might want to ask or make EVERY change to your endpoints you might need to. By writing your own sensors and packages, you can take advantage of Tanium's speed and scale to solve the unique challenges that your business faces.

But what happens when you take on increasingly complex business problems that require increasingly complex solutions? In this lab, you will learn advanced techniques for creating custom content, to help you take advantage of the Tanium platform to solve these more complex business challenges. If you've been developing content for Tanium for a while, this lab takes it to the next level!

Pre-Req(s): Basic understanding of Tanium; asking questions and deploying actions. Some prior experience of building custom code and having attended last year’s “Code Your Way to Freedom” is ideal

AdvancedPlatform
Enough With the T.P.S. Reports, Let's Patch It!

IT operations can be difficult with the lack of visibility and trust in what is actually problematic, to prioritizing actions to remediate the issues, to lacking tools to rapidly fix the identified issues, and real-time reporting on status and meaningful comparisons to industry standards. This lab will guide you to quickly identify problems and prioritize your IT operations remediation actions, leveraging Tanium's speed and scale. You will then deploy actions to solve the identified issues and reports on the progress all in real time while skipping red tape.

You will learn how Tanium automates and streamlines these steps as well as provide guidance to win hearts and minds in your organization. Doing more with less is easy through the power of the integrated Tanium platform.

Pre-Req(s): Basic understanding of Tanium Comply and Patch

IntermediateComply, Deploy, Patch, Benchmark
Hidden Exposures: Unmasking Vulnerabilities and Software Ingredients With Tanium SBOM and Comply

Software Bill of Materials helps identify libraries that exist on endpoints, likely shipped with other software. Customers need a readily available way to show which assets are most vulnerable due to the software and its' supporting libraries that are installed.

You may already be familiar with Tanium Comply which scans for compliance and operating system vulnerabilities, Comply can now make sense of the Bill of Materials and determine which libraries are vulnerable. In this lab you will learn best practices for efficiently scanning your enterprise for vulnerabilities. You will identify vulnerable libraries that you may not have known existed within products you commonly use. Once the systems are identified, you will apply updates to the affected products to remediate the vulnerabilities. Finally, you will use Asset and Reporting to showcase vulnerable versions and the remediation efforts you have completed.

Pre-Req(s): Working knowledge of Tanium functions; asking questions, saving questions and building reports. Understanding of vulnerability and Patch management concepts. Working knowledge of Tanium Patch and Deploy modules

IntermediateComply, Deploy, Patch, Reporting, SBOM
Home on the IP Range: What to do When you get More Cowmputers

Leverage Tanium's built-in automation to simplify and speed up expanding your Tanium footprint, improving your organization's security posture, and providing accurate compliance and vulnerability data. New site, new customer, or another floor of the office? In this lab, you will learn to create a re-usable framework, so you don't have to reinvent the wheel.

Pre-Req(s): Basic understanding of Tanium and Modules

Intermediate/AdvancedAsset, Comply, Deploy, Direct Connect, Discover, Impact, Patch, Reporting, SBOM, Client Management
How to Operate Tanium Like a Pro for Patching and Software Maintenance

In this lab you will learn how to take your Tanium operations for patching and 3rd party updates to the next level. This lab will focus on Tanium Patch, Deploy, and Comply being used in a stepped maturity program designed to move organizations towards a mature automated approach, maximizing control and effective use of manpower.

Pre-Req(s): None

IntermediateAsset, Comply, Deploy, Discover, Patch
Integrate Tanium Digital Employee Experiences and ServiceNow Total Experiences to Get a Complete and Accurate 360-Degree Overview

In this lab, you will first discover the capabilities of Tanium Engage; how to get the technical insights, provide automated self-service workflows and measure employee sentiment. Secondly, you will integrate with ServiceNow to provide valuable DEX information for the Total Experience overview. Lastly, you will create process tickets in ServiceNow, based on Tanium engage survey answers, which will close the loop for IT processes.

Pre-Req(s): Administrative knowledge of Tanium and basic ServiceNow administrative knowledge. Prior to the event, attendees will need to gain access to a ServiceNow developer instance and we recommend to request one UTAH Personal Development Instance at developer.servicenow.com.

IntermediateConnect, Interact, Reporting, Engage, Reports
Mastering Interact

This lab will dive deep into the functionality available in Tanium Interact for gathering targeted information from endpoints. You will learn various techniques for building questions that can be used to get the exact data you need and for targeting specific endpoints for changes. You will then apply that knowledge in the lab to extend typical use cases beyond built-in module capabilities.

While you will use the Tanium Patch, Reveal, and Impact modules in the lab as examples, the techniques you will learn to apply are universal, and can be applied to any Tanium Module.

Pre-Req(s): 6 months experience with Tanium. Tech Talk Episode #62 – Mastering Interact

IntermediateImpact, Interact, Patch, Reveal
Monitor and Improve Employee Satisfaction With Engage - The Next Frontier

This lab will focus on the Tanium DEX (Digital Employee Experience) solution which consists of Performance and Engage. You will gain an understanding of and get hands on experience with the new Performance score feature, Engage sentiment surveys, Engage triggers and remediation tasks. Key take aways are:

  • Improve the end-user digital experience
  • End user self-remediation workflows and capabilities
  • Create basic and advanced survey trigger conditions using sensors
  • Performance score – how it is measured and how improvement over time improves DEX.

Pre-Req(s): Basic understanding of the Tanium Platform

Intermediate/AdvancedPerformance, Platform, Engage
No Capes Required: Single Endpoint View and Screen Sharing Helps You Save the Day as a Help Desk Hero

In this lab, you will learn how Tanium can help you boost your efficiency troubleshooting and improve your end-user productivity with faster time resolution. This lab will cover the in-and-outs of Single Endpoint View (file browser, screen sharing with ScreenMeet, Direct Connect, Deploy actions, endpoint details, installed applications). You will also learn how to take the solution from fixing one issue on an endpoint and deploy the fix it for all affected endpoints, proactively helping you address potential help tickets! This lab is designed for a help desk audience.

Pre-Req(s): None

Beginner/IntermediateDirect Connect, Single Endpoint View
PART 1: Incident Response - Examine the Enemy

This lab is Part 1 of a 2-part lab series that focuses on the entire incident response lifecycle. This lab starts with hunting and examining evidence in an environment to find the enemy within. You will leave understanding Tanium capabilities to help identify and scope an incident.

Pre-Req(s): Basic understanding of Tanium and Modules

Note: PART 1: Incident Response - Examine the Enemy and PART 2: Incident Response - Expel the Enemy are scheduled to be taken on the same day. During registration once you select PART 1: Incident Response - Examine the Enemy you will automatically be registered for PART 2: Incident Response - Expel the Enemy.

Intermediate/AdvancedAsset, Comply, Impact, Interact, Performance, Threat Response, Reporting, SBOM
PART 2: Incident Response - Expel the Enemy (included with PART 1)

This lab is Part 2 of a 2-part lab series that focuses on the entire incident response lifecycle. This lab will utilize the evidence examined from the previous lab to determine the best ways to isolate and then expel the enemy. You will leave understanding Tanium capabilities to contain and remediate an incident.

Pre-Req(s): Basic understanding of Tanium and Modules

Note: PART 1: Incident Response - Examine the Enemy and PART 2: Incident Response - Expel the Enemy are scheduled to be taken on the same day. During registration once you select PART 1: Incident Response - Examine the Enemy you will automatically be registered for PART 2: Incident Response - Expel the Enemy.

Intermediate/AdvancedAsset, Comply, Deploy, Enforce, Impact, Interact, Patch, Performance, Threat Response, Reporting, SBOM
Playing Nice With Others in a Shared Deploy Sandbox

Tanium Deploy is a powerful tool for installing, updating, and removing software throughout an enterprise. But when you're working in a large enterprise with clear support boundaries between organizations or departments, you can unintentionally make choices which negatively affect machines your colleagues are managing.

In this lab you will learn strategies for working in a shared environment (common for some of our State and Local Government customers) by leveraging custom tags, targeted deployments, computer groups, maintenance windows, self-service profiles, roles, permissions, and more. You will see in the lab environment how software deployed using these strategies reaches only the intended endpoints and simplifies the administrative burden for looking after your own deployments.

Pre-Req(s): Basic understanding of the Tanium Platform, RBAC roles, and Deploy

Intermediate/AdvancedDeploy
Say Goodbye to Policy Management and Device Enrollment Stress - Enforce Makes All OS Settings and Enrollment a Success

Mac, Windows, Linux, and Container Clusters all have unique settings and enrollment needs, but that doesn’t mean you need 4 separate tools. In this lab, you will learn how to get a unified control plane with Tanium. Whether it’s applying ADMX with CSP to take precedence over GPO on Windows, or setting estate wide USB removable storage policies, or making sure that no rogue container images are ever used in production, or finally managing those one-off Macs with a lightweight MDM, or remediating a CIS benchmark deviation, Tanium has got you covered.

Pre-Req(s): Working knowledge of the Tanium Platform

Intermediate/AdvancedComply, Enforce

Mac, Windows, Linux, and Container Clusters all have unique settings and enrollment needs, but that doesn’t mean you need 4 separate tools. In this lab, you will learn how to get a unified control plane with Tanium. Whether it’s applying ADMX with CSP to take precedence over GPO on Windows, or setting estate wide USB removable storage policies, or making sure that no rogue container images are ever used in production, or finally managing those one-off Macs with a lightweight MDM, or remediating a CIS benchmark deviation, Tanium has got you covered.

Pre-Req(s): Working knowledge of the Tanium Platform

Intermediate/AdvancedComply, Enforce
SOC Workflows Leveraging MSFT Sentinel and Tanium

This lab will show how to break silos and accelerate hunting and investigations through the use of structured workflows created by integrating Tanium & Microsoft Sentinel. You will learn how Tanium data can be ingested using Microsoft Sentinel Logic Apps, then use keyword query language (KQL) to analyze and visualize threats, incidents, or stages of investigations within a structured workflow.

Pre-Req(s): Basic understanding of Tanium, asking questions, using Tanium Threat Response. Familiarity of tactics, techniques, and procedures for threat hunting, investigations, and SOC workflows. Tanium Threat Response Analyst (WBT Course Registration Link) is ideal

Intermediate/AdvancedComply, Connect, Reveal, Threat Response, Benchmark
Starting from Zero, Getting to Zero Trust: Tanium and Entra ID

Zero Trust can be a difficult concept to communicate and implement across an entire enterprise, in this lab you will walk through the practical application of conditional access by linking Tanium to Azure Active Directory as the basis for a Zero Trust framework. The beauty of the Tanium platform is that Zero Trust doesn’t have to stop just at visibility and control. With Tanium, you can take Zero Trust one step further and proactively remediate Zero Trust conditions before they impact your users’ productivity.

Using the concepts in this lab, you will be able to implement the same concepts to test the configuration with your own Tanium dev/test environment. You will learn how simple the test environment can be to set up and demonstrate, even with only a M365 developer subscription.

Pre-Req(s): Working Knowledge of the Tanium Platform and familiarity with Azure Active Directory configuration

Intermediate/AdvancedEnforce
Tanium Basics: Leveraging the Power of Certainty

This lab introduces the Tanium Platform's unique architecture and core functions including questions, sensors, packages, saved questions, dashboards, categories, analyzing trends, actions, action groups, and more. This lab is appropriate for anyone looking to develop their Tanium knowledge of core Tanium features and functions.

Pre-Req(s): None

BeginnerPlatform
Tanium Gateway Treasures

Using the Tanium Gateway, you will learn how to extract valuable insights from the vast amount of information accessible through the Tanium Platform. Information used to make critical and informative decisions about your enterprise. Things like compliance and operational information will be available to you either directly or through ingest tools. Using the Tanium Gateway in this lab, you will learn the starting point to powerful integrations within your enterprise.

Pre-Req(s): Working knowledge of the Tanium Platform and Tanium Gateway

Beginner/IntermediateComply, Trends, Reporting
Tanium Vulnerability Terminator - Fully Automate a Safe Patching Strategy for Windows Systems

Learn how to fully automate a safe and reliable patching strategy that you can take back and implement at your organization. In this lab you will walk through the configuration of a fully automated patching strategy which you will then execute within the lab environment. As part of the lab you will also remediate any failure notifications, ensure patching compliance, and detect malicious user activity using Tanium Comply and Threat Response.

Pre-Req(s): None

Beginner/IntermediateComply, Deploy, Patch, Threat Response
Using Tanium to Deploy and Manage Microsoft Defender for Endpoint

In this lab, you will learn how to use Tanium to deploy and manage Microsoft Defender for Endpoint! This lab session will start with a quick presentation to get you familiar with Microsoft Defender for Endpoint, and the preparation steps necessary. Then the fun begins as we pivot to the lab where you will assess endpoints for Defender readiness, deploy and onboard Defender, and implement monitoring of the health and status of Defender in your environment. By the end of the session, you will be ready to modernize endpoint protection with Tanium and Microsoft Defender for Endpoint.

Pre-Req(s): Basic understanding of Tanium and Tanium Custom Content (WBT Course Registration Link)

Beginner-IntermediateDeploy, Enforce, Patch, Performance, Platform
Vulnerability Investigation and Remediation on Linux Systems

In this lab, you will learn how to perform full vulnerability management on Linux systems. From a vulnerability finding, you will learn how to create an efficient report, remediate and follow it.

Pre-Req(s): Understanding of vulnerability and patching concept as well as basic Linux expertise

Beginner/IntermediateComply, Patch
Workflows and Automation

Tanium Workflows and Automation provides an intuitive, no-code workflow builder that simplifies Tanium platform interactions into logical and repeatable actions to solve customers' key use cases.

In this lab, you will explore the features of Workflows and Automation with a specific focus on creating workflows, running playbooks, and discussing best practices for automation within the Tanium platform.

Pre-Req(s): None

Beginner/IntermediateDeploy, Patch, Platform, Workflows
Time Name More Info
Monday, November 13, 2023
10:30 AM - 12:00 PMBuilding Custom Solutions With Tanium Reporting
10:30 AM - 12:00 PMEnough With the T.P.S. Reports, Let's Patch It!
10:30 AM - 12:00 PMMastering Interact
10:30 AM - 12:00 PMNo Capes Required: Single Endpoint View and Screen Sharing Helps You Save the Day as a Help Desk Hero
10:30 AM - 12:00 PMPlaying Nice With Others in a Shared Deploy Sandbox
10:30 AM - 12:00 PMSOC Workflows Leveraging MSFT Sentinel and Tanium
10:30 AM - 12:00 PMTanium Basics: Leveraging the Power of Certainty
10:30 AM - 12:00 PMTanium Gateway Treasures
10:30 AM - 12:00 PMUsing Tanium to Deploy and Manage Microsoft Defender for Endpoint
10:30 AM - 12:00 PMWorkflows and Automation
1:00 PM - 2:30 PMBetter Together: Unleash the Power of Tanium and ServiceNow with the ITAM Service Graph Connector
1:00 PM - 2:30 PMHidden Exposures: Unmasking Vulnerabilities and Software Ingredients With Tanium SBOM and Comply
1:00 PM - 2:30 PMHow to Operate Tanium Like a Pro for Patching and Software Maintenance
1:00 PM - 2:30 PMMastering Interact
1:00 PM - 2:30 PMPART 1: Incident Response - Examine the Enemy
1:00 PM - 2:30 PMSay Goodbye to Policy Management and Device Enrollment Stress - Enforce Makes All OS Settings and Enrollment a Success
1:00 PM - 2:30 PMStarting from Zero, Getting to Zero Trust: Tanium and Entra ID
1:00 PM - 2:30 PMTanium Gateway Treasures
1:00 PM - 2:30 PMTanium Vulnerability Terminator - Fully Automate a Safe Patching Strategy for Windows Systems
1:00 PM - 2:30 PMVulnerability Investigation and Remediation on Linux Systems
3:00 PM - 4:30 PMCertificate Manager - Making Sure Your Secure Communications are Secure
3:00 PM - 4:30 PMCreating Custom Content to Solve Those Complex Business Challenges
3:00 PM - 4:30 PMHome on the IP Range: What to do When you get More Cowmputers
3:00 PM - 4:30 PMHow to Operate Tanium Like a Pro for Patching and Software Maintenance
3:00 PM - 4:30 PMMonitor and Improve Employee Satisfaction With Engage - The Next Frontier
3:00 PM - 4:30 PMPART 2: Incident Response - Expel the Enemy (included with PART 1)
3:00 PM - 4:30 PMSay Goodbye to Policy Management and Device Enrollment Stress - Enforce Makes All OS Settings and Enrollment a Success
3:00 PM - 4:30 PMSOC Workflows Leveraging MSFT Sentinel and Tanium
3:00 PM - 4:30 PMTanium Basics: Leveraging the Power of Certainty
3:00 PM - 4:30 PMWorkflows and Automation
Wednesday, November 15, 2023
1:30 PM - 3:00 PMHidden Exposures: Unmasking Vulnerabilities and Software Ingredients With Tanium SBOM and Comply
1:30 PM - 3:00 PMIntegrate Tanium Digital Employee Experiences and ServiceNow Total Experiences to Get a Complete and Accurate 360-Degree Overview
1:30 PM - 3:00 PMNo Capes Required: Single Endpoint View and Screen Sharing Helps You Save the Day as a Help Desk Hero
1:30 PM - 3:00 PMPART 1: Incident Response - Examine the Enemy
1:30 PM - 3:00 PMTanium Basics: Leveraging the Power of Certainty
1:30 PM - 3:00 PMUsing Tanium to Deploy and Manage Microsoft Defender for Endpoint
3:30 PM - 5:00 PMCertificate Manager - Making Sure Your Secure Communications are Secure
3:30 PM - 5:00 PMPART 2: Incident Response - Expel the Enemy (included with PART 1)
3:30 PM - 5:00 PMSOC Workflows Leveraging MSFT Sentinel and Tanium
3:30 PM - 5:00 PMStarting from Zero, Getting to Zero Trust: Tanium and Entra ID
3:30 PM - 5:00 PMVulnerability Investigation and Remediation on Linux Systems
3:30 PM - 5:00 PMWorkflows and Automation
Thursday, November 16, 2023
9:00 AM - 10:30 AMBuilding Custom Solutions With Tanium Reporting
9:00 AM - 10:30 AMCertificate Manager - Making Sure Your Secure Communications are Secure
9:00 AM - 10:30 AMCreating Custom Content to Solve Those Complex Business Challenges
9:00 AM - 10:30 AMEnough With the T.P.S. Reports, Let's Patch It!
9:00 AM - 10:30 AMHome on the IP Range: What to do When you get More Cowmputers
9:00 AM - 10:30 AMIntegrate Tanium Digital Employee Experiences and ServiceNow Total Experiences to Get a Complete and Accurate 360-Degree Overview
9:00 AM - 10:30 AMMastering Interact
9:00 AM - 10:30 AMNo Capes Required: Single Endpoint View and Screen Sharing Helps You Save the Day as a Help Desk Hero
9:00 AM - 10:30 AMPART 1: Incident Response - Examine the Enemy
9:00 AM - 10:30 AMPlaying Nice With Others in a Shared Deploy Sandbox
9:00 AM - 10:30 AMUsing Tanium to Deploy and Manage Microsoft Defender for Endpoint
11:00 AM - 12:30 PMBetter Together: Unleash the Power of Tanium and ServiceNow with the ITAM Service Graph Connector
11:00 AM - 12:30 PMBuilding Custom Solutions With Tanium Reporting
11:00 AM - 12:30 PMCreating Custom Content to Solve Those Complex Business Challenges
11:00 AM - 12:30 PMHidden Exposures: Unmasking Vulnerabilities and Software Ingredients With Tanium SBOM and Comply
11:00 AM - 12:30 PMHow to Operate Tanium Like a Pro for Patching and Software Maintenance
11:00 AM - 12:30 PMMonitor and Improve Employee Satisfaction With Engage - The Next Frontier
11:00 AM - 12:30 PMPART 2: Incident Response - Expel the Enemy (included with PART 1)
11:00 AM - 12:30 PMSay Goodbye to Policy Management and Device Enrollment Stress - Enforce Makes All OS Settings and Enrollment a Success
11:00 AM - 12:30 PMStarting from Zero, Getting to Zero Trust: Tanium and Entra ID
11:00 AM - 12:30 PMTanium Gateway Treasures
11:00 AM - 12:30 PMTanium Vulnerability Terminator - Fully Automate a Safe Patching Strategy for Windows Systems
11:00 AM - 12:30 PMWorkflows and Automation