In‑Person Breakouts
Chart your course through the in‑person breakout sessions at Converge 2026, complete with dates and times for each mission. Use the filters to find the sessions that best fit your trajectory and expertise.
Additional breakout sessions will be added in the coming weeks. Stay tuned!
| Automating Device Quarantine for Critical Risks: From Manual Isolation to Scalable Response | ||||
|---|---|---|---|---|
IT Ops regularly needs to isolate endpoints posing critical risk — severe vulnerabilities, unpatched systems beyond remediation, theft, or loss — with isolated devices then requiring physical shipment or direct technician follow-up. Tanium's quarantine capability was the natural mechanism to enforce isolation, but on peak days hundreds of devices can need quarantining at once, making manual handling impractical and error-prone. The team is automating the quarantine workflow so it scales reliably without sacrificing response time or accuracy. | Alberto Rodriguez Frias - JLL Jose Luis Ruiz Ruiz - JLL Miguel Keane Cañizares - JLL | |||
| Behind the Terminal Walls: IT and OT Convergence | ||||
| The airport environment was never designed as a single, unified technology ecosystem, and the evolving threat landscape, growing reliance on interconnected systems, and rapid rise in connected devices have made that gap impossible to ignore. Having already used Tanium to build a more current and actionable view of its IT environment, the team is now extending that same visibility and context into Operational Technology — identifying not just an IP address, but what a device does, who owns it, what it talks to, and the impact if it's compromised. Next: one unified view spanning both IT and OT. | Brent Walls - Indianapolis Airport Authority | |||
| Governing at Machine Speed: How Avanade Automated Tanium with Azure Arc for a Global Philanthropic Nonprofit | ||||
Across this global philanthropic non-profit's server fleet, the goal was simple: one process, one tool. The organization is extending Azure Arc across its hybrid estate spanning Azure, on-premises infrastructure, and other environments to bring every machine under one governance model. As a design partner in Tanium's Azure Arc extension private preview, Avanade pioneered a native path for deploying the Tanium Client directly through that same Arc control plane, validating it end-to-end on Windows and Linux with the core agent installing in about five minutes. Where bootstrapping once meant a mix of manual installs, Group Policy, and custom extensions, the team is now automating with Azure Policy's DeployIfNotExists so every newly registered Arc machine is enrolled in Tanium, joins its dynamic groups, and inherits the patching, compliance, and configuration policies already defined. The result: Azure Arc adoption becomes an accelerant for Tanium coverage rather than a separate process to manage. | Allan Bernardo - Avanade on assignment at a Global Philanthropic Nonprofit | |||
| Integrating Companies without Risk: How Canal+ Leverages Tanium to Accelerate M&A | ||||
As WSUS approached retirement and Canal+'s acquisition-driven growth added new subsidiaries, each with its own patching process, the media group needed a single tool to unify patching and visibility. After an RFP, a four-person team deployed Tanium in France first, then expanded module by module, using it as an onboarding accelerator so new subsidiaries get instant infrastructure visibility before patching fully moves to Tanium. Tanium Provision handled Windows 10-to-11 migration without USB redeployment, and Tanium Perf countered "it's slow" complaints with real data. Results: 6+ subsidiaries onboarded in a year, 95–98% automatic patch success, and 400+ custom packages built. | Julien Billard - Canal + Thomas Herbin - Canal + | |||
| Logs to Live Hunts: Creating a Telemetry Foundation to Unlock Autonomous SecOps | ||||
Most endpoint tools identify what process executed. Tanium Recorder goes further, continuously capturing process, file, registry, and network telemetry — showing not just what happened, but how it unfolded across an endpoint. U.S. Bank and Tanium's HuntIQ teams will demonstrate how organizations can build and maintain a strong telemetry foundation through an ongoing process of data collection, retention, and investigation. This depth of telemetry unlocks techniques like pivoting from a single indicator to a full process lineage, confirming blast radius through network and file-write telemetry alone, and identifying which telemetry categories consistently drive successful investigations versus those that just add cost. More importantly, this session will prove how building that foundation & a corresponding process to review saves organizations critical time & delivers sharpened investigative results. | Bryan Hall - U.S. Bank Chris Kulawiak - Tanium Ken Cheung - U.S. Bank | |||
| Tanium Beyond the GUI: From a Homegrown MCP to Shaping Tanium's Own | ||||
Common tasks — pulling logs, building packages by hand, uninstalling apps at scale — take more manual effort than they should. Eager to put MCPs to work early, SimCorp built its own: pairing the Tanium API with Claude to automate package builds from Winget and GitHub, uninstall software agnostically, and handle edge cases and log pulls in seconds. An hour-long packaging process converted to a single prompt, and cleanup projects once needing hundreds of packages now need just one. Since that innovation, Tanium has launched its own Atlas MCP & SimCorp was among the early preview participants. Next: SimCorp is adapting to the Atlas MCP - uncovering additional efficiencies across the enterprise | Ivan Malinovski - SimCorp | |||
| Threat Hunting with Tanium: Tracking Attacks at Scale | ||||
As a global web hosting provider, Newfold Digital is an attractive target for threat actors abusing its infrastructure for malware distribution and large-scale campaigns — and identifying affected servers used to be slow, manual work. With Tanium Live Response, the security team combines threat intelligence with rapid endpoint visibility to identify compromised systems and assess attack scope in minutes. YARA rules deployed at scale surface malware tied to emerging campaigns, and Live Response lets analysts collect forensic evidence and accelerate containment — enabling investigation without engineering or after-hours support. Result: response times cut from days to minutes. | Robbie Abraham - Newfold Digital | |||
| 2:15 PM - 2:45 PM (PST) | ||
|---|---|---|
| Behind the Terminal Walls: IT and OT Convergence | Brent Walls - Indianapolis Airport Authority | |