Explore this year's sessions

In‑Person Breakouts

Chart your course through the in‑person breakout sessions at Converge 2026, complete with dates and times for each mission. Use the filters to find the sessions that best fit your trajectory and expertise.

Additional breakout sessions will be added in the coming weeks. Stay tuned!

500 Hours Saved in Two Months: Atlas, AI, and Automation
 

The goal: move faster, safer, and more predictably by combining Tanium Atlas, AI, and automation. In two months, one developer saved over 500 hours across analysis, investigation, and programming work. Atlas extends the team's capabilities by migrating playbooks and scheduled actions when someone leaves the organization, searching for sensor or package usage across scheduled actions and playbooks to assess the impact of changes before making them, and answering detailed questions about Tanium's API access and functionality. The takeaway: Atlas doesn't just support the team's Tanium usage — it multiplies it.

 
Automating Device Quarantine for Critical Risks: From Manual Isolation to Scalable Response
 

IT Ops regularly needs to isolate endpoints posing critical risk — severe vulnerabilities, unpatched systems beyond remediation, theft, or loss — with isolated devices then requiring physical shipment or direct technician follow-up. Tanium's quarantine capability was the natural mechanism to enforce isolation, but on peak days hundreds of devices can need quarantining at once, making manual handling impractical and error-prone. The team is automating the quarantine workflow so it scales reliably without sacrificing response time or accuracy.

 
Behind the Terminal Walls: IT and OT Convergence
 

The airport environment was never designed as a single, unified technology ecosystem, and the evolving threat landscape, growing reliance on interconnected systems, and rapid rise in connected devices have made that gap impossible to ignore. Having already used Tanium to build a more current and actionable view of its IT environment, the team is now extending that same visibility and context into Operational Technology — identifying not just an IP address, but what a device does, who owns it, what it talks to, and the impact if it's compromised. Next: one unified view spanning both IT and OT.

 
Beyond the Blind Spot: Automating Linux Patch Compliance at Scale
 

CBRE rolled Tanium out fleet-wide within two months, and Windows patching went smoothly — but most of its Linux estate runs Amazon Linux, whose repo/snapshot model wasn't supportable by Tanium Scan for Linux, blocking repo-based patching against a 14-day vulnerability SLA. Working with Tanium's ACE team and a Linux SME, CBRE proved out Ubuntu patching first, then built custom compliance sensors for snapshot-level visibility into Amazon Linux. Rather than a separate Linux playbook, the team extended its ring-based Windows/browser automation model to Linux, fitting reboot timing inside change-management workflows — a common blind spot at scale.

 
Change Management with Tanium: Earning Adoption Across Autonomous IT Groups
 

At the University of Utah, standardizing endpoint management across dozens of colleges and hospitals was never technical — it was political. Departments ran their SCCM instances, and a Tanium rollout drew pushback over resource overhead and fear of losing control. Rather than mandating adoption, the Information Security Office engineered it: running Tanium as a service with low cost, letting the Software Package Gallery sell itself, building a cross-department community, and drawing one line — Threat Response stays with ISO, everything else is open. Result: ~16,000 endpoints on tag-based patching and 275+ department-run deployment jobs, with one holdout department retiring SCCM.

 
Compliance That Holds: Enforced Policy, Continuous Validation
 

An assessment tells you where you stand. It was never designed to keep you there — which is why the findings list gets worked control by control, re-scanned, then worked again after the next drift. This session shows a cleaner division of labor on one platform. The benchmark becomes enforced policy, applied to your endpoints and reapplied when they drift, while an independent assessment of those same endpoints proves the enforcement held. One job sets the state, the other verifies it — and the findings list becomes evidence instead of a worklist. Tanium Atlas sits over the top: ask in plain language whether the policy applied, rank what's left, and approve remediation with a human in the loop.

 
Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next
 

The full Core & AI Services roadmap spans governance (Autonomous MSP's multi-tenant model, Agentic Policy Enforcement, and Intelligent Control's Global Maintenance Windows and Change Approval), the Atlas experience (Collaborative Pages, a Research Agent, persistent Memory), and extensibility (the Tanium MCP Server, Automate's expanding API, a next-gen Tanium Script Language). Each item ties back to Atlas's Speed, Scale, and Safety commitments.

 
DEX Workflows in Tanium Atlas: Reducing Help Desk Tickets and Closing the Loop
 

Most DEX tools stop at a dashboard, leaving diagnosis and proof of improvement to someone else's ticket. Tanium Engage paired with Performance streams live telemetry into a DEX Score tying endpoint health to real user experience. AI-Driven Root Cause Analysis lets Atlas trace a degraded device to its root cause in moments, then resolve it via self-service or a ring-gated Automate playbook, with human approval throughout. A re-scan confirms the fix held, Connect writes the outcome to ServiceNow, and Action Oversight keeps an audit trail. See DEXOps as one Atlas-orchestrated workflow, with Background Agents watching 24/7 for 75% MTTR reduction and 95% patching efficiency gains customers are already seeing.

 
Endpoint Management Roadmap: From Windows to Linux to OT
 

A roadmap tour across device classes: Windows Patch Modernization (Autopatch, Hotpatch, air-gapped support), Zero-Touch & DEX (task-sequence provisioning, a cloud-connected performance and RCA agent), expanded Linux support (PatchCX, repo management, snapshots/rollback, CIS for Linux), broader ChromeOS/Android/Intune coverage, Confidence Score, and new OT protocols (BACnet, Modbus). See how Tanium Atlas ties Windows, Linux, and OT into one interface instead of three consoles.

 
Engineering Trust in AI Systems: How We Validate Atlas Before It Acts
 

Every AI feature that reasons over endpoint data and acts in a cybersecurity environment lives or dies on trust. Trust gets engineered into Tanium Atlas from the ground up — grounding reasoning in live endpoint truth, adding real-time web research, and building evaluation discipline at global-enterprise scale. A Tanium benchmark in development measures whether Atlas's AI does the right thing before that claim ever reaches a customer. You'll leave with a concrete picture of the engineering and evaluation work behind Atlas's Safety commitment, more than marketing language around 'trustworthy AI,' the actual mechanics of how it's tested and proven.

 
Every Lap Counts: Keeping Your Tanium Deployment Reporting Accurately at Scale
 

A race car doesn't stay competitive because of one good build; it stays competitive because a crew touches it on a fixed schedule, whether anything looks wrong or not. Tanium deployments work the same way: most degraded environments didn't fail from a bad implementation; they drifted, one skipped review at a time. This session covers the maintenance practices that keep a Tanium deployment reporting accurately at scale, agent coverage and health verification, sensor performance review, computer group and scheduled action hygiene, role and permission audits, module-level upkeep for Patch and Deploy, and platform upgrade cadence, and leaves attendees with a daily, weekly, monthly, and quarterly maintenance schedule mapped to owners they can put into practice as soon as they get home.

 
Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response
 

This combined roadmap closes the loop from all sides: External Attack Surface Management and Attack Path Mapping on exposure; Enhanced Vulnerability Scanning and Autonomous Remediation closing the fix gap; Insights Engine, Federated SOC Architecture, Agentic Threat Hunting powered by Google Threat Intelligence, and early Endpoint Vectoring/Anomaly Detection work on response. See confirmed findings route through Tanium Atlas for fleet-wide action without manual handoffs.

 
From Intel to Action: Agentic Threat Hunting with Tanium & Google Threat Intelligence
 

Proactive threat hunting is high-value and rare, demanding expertise and hours per hunt. Agent-Guided Threat Hunting lets a hunter describe a hypothesis in plain language while Tanium Atlas runs the hunt autonomously, mapping findings to MITRE ATT&CK. Paired with Google Threat Intelligence (private preview) — the same intelligence behind Google's own incident response, validated across 36M+ endpoints. From intel to live hunt to fleet-wide action in minutes, not days.

 
From Reactive to Autonomous: AI-Driven Patch Management with Tanium Atlas
 

Patch management has historically meant reactive triage by searching, clicking, and context-switching after something's already gone wrong. This session shows the shift to proactive operational hygiene: building Patch Lists and Deployments in Tanium Patch, then layering in Ambient Agents that continuously observe the patch surface and proactively flag, or even kick off, closed-loop remediation when new CVEs or failed deployments demand attention. We'll map this to the Confidence Score roadmap, which lets you safely accelerate change instead of waiting on manual review.

 
Governing at Machine Speed: How Avanade Automated Tanium with Azure Arc for a Global Philanthropic Nonprofit
 

Across this global philanthropic non-profit's server fleet, the goal was simple: one process, one tool. The organization is extending Azure Arc across its hybrid estate spanning Azure, on-premises infrastructure, and other environments to bring every machine under one governance model. As a design partner in Tanium's Azure Arc extension private preview, Avanade pioneered a native path for deploying the Tanium Client directly through that same Arc control plane, validating it end-to-end on Windows and Linux with the core agent installing in about five minutes. Where bootstrapping once meant a mix of manual installs, Group Policy, and custom extensions, the team is now automating with Azure Policy's DeployIfNotExists so every newly registered Arc machine is enrolled in Tanium, joins its dynamic groups, and inherits the patching, compliance, and configuration policies already defined. The result: Azure Arc adoption becomes an accelerant for Tanium coverage rather than a separate process to manage.

 
How AI Is Transforming Endpoint Management on the Ground: Reaching What Was Previously Out of Reach with Tanium Atlas
 

With asset visibility and patch management already established company-wide, several tasks still relied on manual effort: separating licensed from free software, prioritizing an overwhelming volume of vulnerability findings, and tracking operating systems nearing end of support. The team applied Tanium Atlas, Tanium's AI console, to all three — narrowing remediation targets by priority, classifying paid versus free software and flagging unregistered assets, and checking OS end-of-support status from real-time endpoint data. Work long deferred as a "someday" problem is now moving. Next: completing the module rollout across Deploy, Comply, and Enforce, and building an AI-embedded operating model.

 
How Tanium Uses Tanium: Running Atlas on Our Own Estate
 

Tanium runs Tanium, and this session pulls back the curtain on what that looks like day to day. Tanium's own CIO and CISO run Atlas, Automation, and the Core platform to manage and secure Tanium's global workforce in production - while also embracing key technologies from partners like Microsoft and ServiceNow to drive efficiency, rigor and capability across every endpoint.

 
Integrating Companies without Risk: How Canal+ Leverages Tanium to Accelerate M&A
 

As WSUS approached retirement and Canal+'s acquisition-driven growth added new subsidiaries, each with its own patching process, the media group needed a single tool to unify patching and visibility. After an RFP, a four-person team deployed Tanium in France first, then expanded module by module, using it as an onboarding accelerator so new subsidiaries get instant infrastructure visibility before patching fully moves to Tanium. Tanium Provision handled Windows 10-to-11 migration without USB redeployment, and Tanium Perf countered "it's slow" complaints with real data. Results: 6+ subsidiaries onboarded in a year, 95–98% automatic patch success, and 400+ custom packages built.

 
Logs to Live Hunts: Creating a Telemetry Foundation to Unlock Autonomous SecOps
 

Most endpoint tools identify what process executed. Tanium Recorder goes further, continuously capturing process, file, registry, and network telemetry — showing not just what happened, but how it unfolded across an endpoint. U.S. Bank and Tanium's HuntIQ teams will demonstrate how organizations can build and maintain a strong telemetry foundation through an ongoing process of data collection, retention, and investigation. This depth of telemetry unlocks techniques like pivoting from a single indicator to a full process lineage, confirming blast radius through network and file-write telemetry alone, and identifying which telemetry categories consistently drive successful investigations versus those that just add cost. More importantly, this session will prove how building that foundation & a corresponding process to review saves organizations critical time & delivers sharpened investigative results.

 
One Platform, Many Owners: Using Tanium RBAC to Fund a Company-Wide Security Investment
 

Securing budget for an enterprise security platform is rarely a single team decision, especially inside a large financial services organization with dozens of cost centers and competing priorities — a challenge Corebridge Financial faced head-on when evaluating Tanium. Rather than asking one team to absorb the full cost, they found the answer inside the platform itself: Tanium's Role-Based Access Control. By mapping Tanium's RBAC model to Corebridge's internal team structure, they carved the platform into distinct, scoped environments, each giving a different business unit ownership over its own endpoints, data, and workflows — and a clear line of sight between budget contribution and value received. IT Operations, Security, and Compliance each became stakeholders in the purchase rather than passengers on someone else's procurement. This session tells that story: how RBAC became not just a security control but a commercial strategy, turning a single vendor negotiation into a multi-team win.

 
Seeing Beyond the Firewall: External Attack Surface Management
 

Most organizations see their attack surface only from the inside while attackers see it from the outside. Tanium's External Attack Surface Management now discovers every Internet-facing host, service, web property, and certificate, every 6–8 hours instead of quarterly, feeding Tanium Atlas for unified internal/external reasoning and connecting to Attack Path Mapping, which shows exactly which exposures reach your crown jewels first. The result: a single, continuously-updated picture of the full attack surface, inside and out.

 
Shadow AI: Hunting Unauthorized AI Tools with Tanium Atlas & Guardian
 

Shadow AI is now a board-level risk. Unauthorized agent tools with real CVE exposure: Guardian Spotlight detects it, Exposure Management scores it against policy, and Endpoint Management enforces the fix, all orchestrated by Tanium Atlas's Background Agents watching 24/7 with human approval gating every action. You get a multi-day investigation collapsed into a governed, minutes-long workflow.

 
Sharper Detection, Safer at Scale: Insights Engine & Federated SOC Architecture
 

False positives and one-size-fits-all suppression are big reasons SOC analysts stop trusting their own alerts. This new session introduces two Security Operations capabilities landing together: Insights Engine, catching techniques like process injection with far fewer false positives, and Federated SOC Architecture, with suppression rules and response actions scoped to each team's own profile. Combine that with existing features like Threat Navigator, MITRE ATT&CK mapping, and AI enrichment for alerts and see how confirmed findings surface directly in Tanium Atlas. You'll leave with a model for higher-fidelity detection that scales cleanly across multiple autonomous SOC teams.

 
Tanium Atlas for Everyone: Putting Autonomous IT in Every Stakeholder's Hands
 

Tanium Atlas puts the answers and reach of an entire team into one operator's hands. In front of a mixed technical/non-technical audience, plain-language questions prompt Atlas to assemble dynamic pages and surface next-step recommendations, every action gated by human approval. See Atlas's Speed, Scale, and Safety commitments in action today, with Background Agents, persistent Memory, Collaborative Pages, with MCP-based extensibility into Slack, ServiceNow, and Copilot arriving next.

 
Tanium Beyond the GUI: From a Homegrown MCP to Shaping Tanium's Own
 

Common tasks — pulling logs, building packages by hand, uninstalling apps at scale — take more manual effort than they should. Eager to put MCPs to work early, SimCorp built its own: pairing the Tanium API with Claude to automate package builds from Winget and GitHub, uninstall software agnostically, and handle edge cases and log pulls in seconds. An hour-long packaging process converted to a single prompt, and cleanup projects once needing hundreds of packages now need just one. Since that innovation, Tanium has launched its own Atlas MCP & SimCorp was among the early preview participants. Next: SimCorp is adapting to the Atlas MCP - uncovering additional efficiencies across the enterprise

 
Tanium: Developers Unite – APIs, Agents, and the Tanium MCP Server
 

Get ready to explore the future of agentic integrations with Tanium. This session covers two ways to extend the platform: proven APIs for established workflows, and the new Tanium MCP Server to unlock the power of Atlas for your agents. Whether you're new to Tanium or a long-time developer, this session is for you. See it live, connect with the community, and leave ready to build what's next.

 
The AI Security Team Member Who Hallucinates (but Still Gets Invited to Meetings)
 

LLM-based tools are now embedded across cybersecurity operations — triaging alerts, summarizing threat intelligence, drafting incident reports — and are fast, cheap, and useful. They also hallucinate: per the SANS 2024 Security Operations Survey, 76% of teams use AI-assisted tools daily, and 41% have hit AI-generated hallucinations in threat reports weekly. Practical, operations-focused guidance for managing that risk is largely missing, tending toward technical failure-mode analysis or policy ignoring under-resourced teams for whom imperfect AI beats no analysis. The takeaway: keep deploying AI, but only with skepticism, verification, and frameworks for logging, validating, and trust-tiering its output.

 
The Flight Plan for Zero Blind Spots: How Air France-KLM Rewired Compliance in Real Time
 

SCCM left Air France-KLM with blind spots — unmanaged software, non-admin installs, a slow patch cycle, and stacked agents — on a fleet managed by an external partner. What began as a compliance project, run as a three-year journey across asset inventory, vulnerability management, license optimization, and lifecycle automation, uncovered a bigger opportunity. The airline joined Tanium Atlas's private preview, converting scripts and configs into lightweight sensors without an outside partner. Results: near-total endpoint coverage, recurring savings across licensing and hardware leasing, and several million euros in avoided exposure — plus a cultural shift to one trusted source of truth.

 
Threat Hunting with Tanium: Tracking Attacks at Scale
 

As a global web hosting provider, Newfold Digital is an attractive target for threat actors abusing its infrastructure for malware distribution and large-scale campaigns — and identifying affected servers used to be slow, manual work. With Tanium Live Response, the security team combines threat intelligence with rapid endpoint visibility to identify compromised systems and assess attack scope in minutes. YARA rules deployed at scale surface malware tied to emerging campaigns, and Live Response lets analysts collect forensic evidence and accelerate containment — enabling investigation without engineering or after-hours support. Result: response times cut from days to minutes.

 
Zero Downtime, Zero Touch: Rebuilding Endpoint Operations Across a Health System
 

Duke Health Technology Solutions legacy endpoint tooling required manual patch gating, physical media for provisioning, and a separate MBAM stack for BitLocker key management — all while supporting a clinical estate with no dependable maintenance window. The team migrated more than 61,000 endpoints to Tanium, retiring the legacy tooling outright rather than running parallel stacks, moved to zero-touch patching, replaced USB imaging with PXE network provisioning, and consolidated eight IT teams onto a single agent and console. The migration surfaced over 15,000 unmanaged devices, moved 30,000+ devices to Windows 11 with zero downtime, and automated the ServiceNow CMDB feed. Support case volume fell 64% as platform usage grew roughly fivefold, and the team is now building toward proactive DEX and automated security response on the same agent footprint.

 
10:45 AM - 11:15 AM (PST)
Governing at Machine Speed: How Avanade Automated Tanium with Azure Arc for a Global Philanthropic NonprofitAllan Bernardo - Avanade on assignment at a Global Philanthropic Nonprofit
Integrating Companies without Risk: How Canal+ Leverages Tanium to Accelerate M&AJulien Billard - Canal+
Thomas Herbin - Canal+
One Platform, Many Owners: Using Tanium RBAC to Fund a Company-Wide Security InvestmentKeith Lethbridge - Corebridge Financial
Sharper Detection, Safer at Scale: Insights Engine & Federated SOC ArchitectureBrent Midwood - Tanium
Tyler Schultz - Tanium
The Flight Plan for Zero Blind Spots: How Air France-KLM Rewired Compliance in Real TimeDjamel Akkouche - Air France KLM
Nicolas Courbin - Air France KLM
Threat Hunting with Tanium: Tracking Attacks at ScaleRobbie Abraham - Newfold Digital
11:30 AM - 12:00 PM (PST)
Every Lap Counts: Keeping Your Tanium Deployment Reporting Accurately at ScaleJeff Smith - Chuco
Nathan Forrester - Chuco
Logs to Live Hunts: Creating a Telemetry Foundation to Unlock Autonomous SecOpsBryan Hall - U.S. Bank
Chris Kulawiak - Tanium
Ken Cheung - U.S. Bank
Tanium Atlas for Everyone: Putting Autonomous IT in Every Stakeholder's HandsKat Ale - Tanium
Michelle Zhang - Tanium
Tanium Beyond the GUI: From a Homegrown MCP to Shaping Tanium's OwnIvan Malinovski - SimCorp
The AI Security Team Member Who Hallucinates (but Still Gets Invited to Meetings)Simon Lundmark - Epiroc
Zero Downtime, Zero Touch: Rebuilding Endpoint Operations Across a Health SystemAmanda Ciriello - Duke Health Technology Solutions
Luis Avila - Duke Health Technology Solutions
3:45 PM - 4:15 PM (PST)
500 Hours Saved in Two Months: Atlas, AI, and AutomationEdward Duarte - SAP
Robert Flores - SAP
Automating Device Quarantine for Critical Risks: From Manual Isolation to Scalable ResponseAlberto Rodriguez Frias - JLL
Jose Luis Ruiz Ruiz - JLL
Miguel Keane Cañizares - JLL
Beyond the Blind Spot: Automating Linux Patch Compliance at ScaleAndrew Valeriane - CBRE
Eric Wagner - CBRE
Jimi White - CBRE
Seeing Beyond the Firewall: External Attack Surface ManagementDavid SooHoo - Tanium
Lucas Lyon - Tanium
4:30 PM - 5:00 PM (PST)
How AI Is Transforming Endpoint Management on the Ground: Reaching What Was Previously Out of Reach with Tanium AtlasKosuke Ohata - ITOCHU Techno-Solutions Corporation
Sayako Miyamura - ITOCHU Techno-Solutions Corporation
Shunto Teraoka - ITOCHU Techno-Solutions Corporation
11:00 AM - 11:30 AM (PST)
From Reactive to Autonomous: AI-Driven Patch Management with Tanium Atlas
11:00 AM - 11:45 AM (PST)
Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next
Endpoint Management Roadmap: From Windows to Linux to OT
Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response
1:15 PM - 1:45 PM (PST)
Tanium: Developers Unite – APIs, Agents, and the Tanium MCP Server
1:15 PM - 2:00 PM (PST)
Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next
Endpoint Management Roadmap: From Windows to Linux to OT
Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response
2:15 PM - 2:45 PM (PST)
Behind the Terminal Walls: IT and OT Convergence
Compliance That Holds: Enforced Policy, Continuous Validation
Engineering Trust in AI Systems: How We Validate Atlas Before It Acts
From Intel to Action: Agentic Threat Hunting with Tanium & Google Threat Intelligence
How Tanium Uses Tanium: Running Atlas on Our Own Estate
Shadow AI: Hunting Unauthorized AI Tools with Tanium Atlas & Guardian
3:15 PM - 3:45 PM (PST)
DEX Workflows in Tanium Atlas: Reducing Help Desk Tickets and Closing the Loop
3:15 PM - 4:00 PM (PST)
Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next
Endpoint Management Roadmap: From Windows to Linux to OT
Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response
4:15 PM - 4:45 PM (PST)
Change Management with Tanium: Earning Adoption Across Autonomous IT Groups