In‑Person Breakouts
Chart your course through the in‑person breakout sessions at Converge 2026, complete with dates and times for each mission. Use the filters to find the sessions that best fit your trajectory and expertise.
Additional breakout sessions will be added in the coming weeks. Stay tuned!
| 500 Hours Saved in Two Months: Atlas, AI, and Automation | ||||
|---|---|---|---|---|
The goal: move faster, safer, and more predictably by combining Tanium Atlas, AI, and automation. In two months, one developer saved over 500 hours across analysis, investigation, and programming work. Atlas extends the team's capabilities by migrating playbooks and scheduled actions when someone leaves the organization, searching for sensor or package usage across scheduled actions and playbooks to assess the impact of changes before making them, and answering detailed questions about Tanium's API access and functionality. The takeaway: Atlas doesn't just support the team's Tanium usage — it multiplies it. | Edward Duarte - SAP Robert Flores - SAP | |||
| Automating Device Quarantine for Critical Risks: From Manual Isolation to Scalable Response | ||||
IT Ops regularly needs to isolate endpoints posing critical risk — severe vulnerabilities, unpatched systems beyond remediation, theft, or loss — with isolated devices then requiring physical shipment or direct technician follow-up. Tanium's quarantine capability was the natural mechanism to enforce isolation, but on peak days hundreds of devices can need quarantining at once, making manual handling impractical and error-prone. The team is automating the quarantine workflow so it scales reliably without sacrificing response time or accuracy. | Alberto Rodriguez Frias - JLL Jose Luis Ruiz Ruiz - JLL Miguel Keane Cañizares - JLL | |||
| Behind the Terminal Walls: IT and OT Convergence | ||||
The airport environment was never designed as a single, unified technology ecosystem, and the evolving threat landscape, growing reliance on interconnected systems, and rapid rise in connected devices have made that gap impossible to ignore. Having already used Tanium to build a more current and actionable view of its IT environment, the team is now extending that same visibility and context into Operational Technology — identifying not just an IP address, but what a device does, who owns it, what it talks to, and the impact if it's compromised. Next: one unified view spanning both IT and OT. | Brent Walls - Indianapolis Airport Authority | |||
| Beyond the Blind Spot: Automating Linux Patch Compliance at Scale | ||||
CBRE rolled Tanium out fleet-wide within two months, and Windows patching went smoothly — but most of its Linux estate runs Amazon Linux, whose repo/snapshot model wasn't supportable by Tanium Scan for Linux, blocking repo-based patching against a 14-day vulnerability SLA. Working with Tanium's ACE team and a Linux SME, CBRE proved out Ubuntu patching first, then built custom compliance sensors for snapshot-level visibility into Amazon Linux. Rather than a separate Linux playbook, the team extended its ring-based Windows/browser automation model to Linux, fitting reboot timing inside change-management workflows — a common blind spot at scale. | Andrew Valeriane - CBRE Eric Wagner - CBRE Jimi White - CBRE | |||
| Change Management with Tanium: Earning Adoption Across Autonomous IT Groups | ||||
At the University of Utah, standardizing endpoint management across dozens of colleges and hospitals was never technical — it was political. Departments ran their SCCM instances, and a Tanium rollout drew pushback over resource overhead and fear of losing control. Rather than mandating adoption, the Information Security Office engineered it: running Tanium as a service with low cost, letting the Software Package Gallery sell itself, building a cross-department community, and drawing one line — Threat Response stays with ISO, everything else is open. Result: ~16,000 endpoints on tag-based patching and 275+ department-run deployment jobs, with one holdout department retiring SCCM. | Hayden Waters - University of Utah | |||
| Compliance That Holds: Enforced Policy, Continuous Validation | ||||
An assessment tells you where you stand. It was never designed to keep you there — which is why the findings list gets worked control by control, re-scanned, then worked again after the next drift. This session shows a cleaner division of labor on one platform. The benchmark becomes enforced policy, applied to your endpoints and reapplied when they drift, while an independent assessment of those same endpoints proves the enforcement held. One job sets the state, the other verifies it — and the findings list becomes evidence instead of a worklist. Tanium Atlas sits over the top: ask in plain language whether the policy applied, rank what's left, and approve remediation with a human in the loop. | Annie Ballew - Tanium Drake Sumner - Tanium | |||
| Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next | ||||
The full Core & AI Services roadmap spans governance (Autonomous MSP's multi-tenant model, Agentic Policy Enforcement, and Intelligent Control's Global Maintenance Windows and Change Approval), the Atlas experience (Collaborative Pages, a Research Agent, persistent Memory), and extensibility (the Tanium MCP Server, Automate's expanding API, a next-gen Tanium Script Language). Each item ties back to Atlas's Speed, Scale, and Safety commitments. | Jason Ellison - Tanium Steven Yang - Tanium | |||
| DEX Workflows in Tanium Atlas: Reducing Help Desk Tickets and Closing the Loop | ||||
Most DEX tools stop at a dashboard, leaving diagnosis and proof of improvement to someone else's ticket. Tanium Engage paired with Performance streams live telemetry into a DEX Score tying endpoint health to real user experience. AI-Driven Root Cause Analysis lets Atlas trace a degraded device to its root cause in moments, then resolve it via self-service or a ring-gated Automate playbook, with human approval throughout. A re-scan confirms the fix held, Connect writes the outcome to ServiceNow, and Action Oversight keeps an audit trail. See DEXOps as one Atlas-orchestrated workflow, with Background Agents watching 24/7 for 75% MTTR reduction and 95% patching efficiency gains customers are already seeing. | Jason Stough - Tanium Shivani Parikh - Tanium | |||
| Endpoint Management Roadmap: From Windows to Linux to OT | ||||
A roadmap tour across device classes: Windows Patch Modernization (Autopatch, Hotpatch, air-gapped support), Zero-Touch & DEX (task-sequence provisioning, a cloud-connected performance and RCA agent), expanded Linux support (PatchCX, repo management, snapshots/rollback, CIS for Linux), broader ChromeOS/Android/Intune coverage, Confidence Score, and new OT protocols (BACnet, Modbus). See how Tanium Atlas ties Windows, Linux, and OT into one interface instead of three consoles. | Aaron Sipe - Tanium Andrew Hecox - Tanium Sergey Belous - Tanium Tim Mintner - Tanium | |||
| Engineering Trust in AI Systems: How We Validate Atlas Before It Acts | ||||
Every AI feature that reasons over endpoint data and acts in a cybersecurity environment lives or dies on trust. Trust gets engineered into Tanium Atlas from the ground up — grounding reasoning in live endpoint truth, adding real-time web research, and building evaluation discipline at global-enterprise scale. A Tanium benchmark in development measures whether Atlas's AI does the right thing before that claim ever reaches a customer. You'll leave with a concrete picture of the engineering and evaluation work behind Atlas's Safety commitment, more than marketing language around 'trustworthy AI,' the actual mechanics of how it's tested and proven. | Aidan Allchin - Tanium Dan Ballance - Tanium | |||
| Every Lap Counts: Keeping Your Tanium Deployment Reporting Accurately at Scale | ||||
A race car doesn't stay competitive because of one good build; it stays competitive because a crew touches it on a fixed schedule, whether anything looks wrong or not. Tanium deployments work the same way: most degraded environments didn't fail from a bad implementation; they drifted, one skipped review at a time. This session covers the maintenance practices that keep a Tanium deployment reporting accurately at scale, agent coverage and health verification, sensor performance review, computer group and scheduled action hygiene, role and permission audits, module-level upkeep for Patch and Deploy, and platform upgrade cadence, and leaves attendees with a daily, weekly, monthly, and quarterly maintenance schedule mapped to owners they can put into practice as soon as they get home. | Jeff Smith - Chuco Nathan Forrester - Chuco | |||
| Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response | ||||
This combined roadmap closes the loop from all sides: External Attack Surface Management and Attack Path Mapping on exposure; Enhanced Vulnerability Scanning and Autonomous Remediation closing the fix gap; Insights Engine, Federated SOC Architecture, Agentic Threat Hunting powered by Google Threat Intelligence, and early Endpoint Vectoring/Anomaly Detection work on response. See confirmed findings route through Tanium Atlas for fleet-wide action without manual handoffs. | Brent Midwood - Tanium David SooHoo - Tanium Laura Iliescu - Tanium | |||
| From Intel to Action: Agentic Threat Hunting with Tanium & Google Threat Intelligence | ||||
Proactive threat hunting is high-value and rare, demanding expertise and hours per hunt. Agent-Guided Threat Hunting lets a hunter describe a hypothesis in plain language while Tanium Atlas runs the hunt autonomously, mapping findings to MITRE ATT&CK. Paired with Google Threat Intelligence (private preview) — the same intelligence behind Google's own incident response, validated across 36M+ endpoints. From intel to live hunt to fleet-wide action in minutes, not days. | Aaron Smith - Tanium Brent Midwood - Tanium Duncan Miller - Tanium | |||
| From Reactive to Autonomous: AI-Driven Patch Management with Tanium Atlas | ||||
Patch management has historically meant reactive triage by searching, clicking, and context-switching after something's already gone wrong. This session shows the shift to proactive operational hygiene: building Patch Lists and Deployments in Tanium Patch, then layering in Ambient Agents that continuously observe the patch surface and proactively flag, or even kick off, closed-loop remediation when new CVEs or failed deployments demand attention. We'll map this to the Confidence Score roadmap, which lets you safely accelerate change instead of waiting on manual review. | Adam Gogal - Tanium Ryan Long - Tanium Tim Brooks - Tanium | |||
| Governing at Machine Speed: How Avanade Automated Tanium with Azure Arc for a Global Philanthropic Nonprofit | ||||
Across this global philanthropic non-profit's server fleet, the goal was simple: one process, one tool. The organization is extending Azure Arc across its hybrid estate spanning Azure, on-premises infrastructure, and other environments to bring every machine under one governance model. As a design partner in Tanium's Azure Arc extension private preview, Avanade pioneered a native path for deploying the Tanium Client directly through that same Arc control plane, validating it end-to-end on Windows and Linux with the core agent installing in about five minutes. Where bootstrapping once meant a mix of manual installs, Group Policy, and custom extensions, the team is now automating with Azure Policy's DeployIfNotExists so every newly registered Arc machine is enrolled in Tanium, joins its dynamic groups, and inherits the patching, compliance, and configuration policies already defined. The result: Azure Arc adoption becomes an accelerant for Tanium coverage rather than a separate process to manage. | Allan Bernardo - Avanade on assignment at a Global Philanthropic Nonprofit | |||
| How AI Is Transforming Endpoint Management on the Ground: Reaching What Was Previously Out of Reach with Tanium Atlas | ||||
With asset visibility and patch management already established company-wide, several tasks still relied on manual effort: separating licensed from free software, prioritizing an overwhelming volume of vulnerability findings, and tracking operating systems nearing end of support. The team applied Tanium Atlas, Tanium's AI console, to all three — narrowing remediation targets by priority, classifying paid versus free software and flagging unregistered assets, and checking OS end-of-support status from real-time endpoint data. Work long deferred as a "someday" problem is now moving. Next: completing the module rollout across Deploy, Comply, and Enforce, and building an AI-embedded operating model. | Kosuke Ohata - ITOCHU Techno-Solutions Corporation Sayako Miyamura - ITOCHU Techno-Solutions Corporation Shunto Teraoka - ITOCHU Techno-Solutions Corporation | |||
| How Tanium Uses Tanium: Running Atlas on Our Own Estate | ||||
Tanium runs Tanium, and this session pulls back the curtain on what that looks like day to day. Tanium's own CIO and CISO run Atlas, Automation, and the Core platform to manage and secure Tanium's global workforce in production - while also embracing key technologies from partners like Microsoft and ServiceNow to drive efficiency, rigor and capability across every endpoint. | Jake McClean - Tanium Paul Black - Tanium | |||
| Integrating Companies without Risk: How Canal+ Leverages Tanium to Accelerate M&A | ||||
As WSUS approached retirement and Canal+'s acquisition-driven growth added new subsidiaries, each with its own patching process, the media group needed a single tool to unify patching and visibility. After an RFP, a four-person team deployed Tanium in France first, then expanded module by module, using it as an onboarding accelerator so new subsidiaries get instant infrastructure visibility before patching fully moves to Tanium. Tanium Provision handled Windows 10-to-11 migration without USB redeployment, and Tanium Perf countered "it's slow" complaints with real data. Results: 6+ subsidiaries onboarded in a year, 95–98% automatic patch success, and 400+ custom packages built. | Julien Billard - Canal+ Thomas Herbin - Canal+ | |||
| Logs to Live Hunts: Creating a Telemetry Foundation to Unlock Autonomous SecOps | ||||
Most endpoint tools identify what process executed. Tanium Recorder goes further, continuously capturing process, file, registry, and network telemetry — showing not just what happened, but how it unfolded across an endpoint. U.S. Bank and Tanium's HuntIQ teams will demonstrate how organizations can build and maintain a strong telemetry foundation through an ongoing process of data collection, retention, and investigation. This depth of telemetry unlocks techniques like pivoting from a single indicator to a full process lineage, confirming blast radius through network and file-write telemetry alone, and identifying which telemetry categories consistently drive successful investigations versus those that just add cost. More importantly, this session will prove how building that foundation & a corresponding process to review saves organizations critical time & delivers sharpened investigative results. | Bryan Hall - U.S. Bank Chris Kulawiak - Tanium Ken Cheung - U.S. Bank | |||
| One Platform, Many Owners: Using Tanium RBAC to Fund a Company-Wide Security Investment | ||||
Securing budget for an enterprise security platform is rarely a single team decision, especially inside a large financial services organization with dozens of cost centers and competing priorities — a challenge Corebridge Financial faced head-on when evaluating Tanium. Rather than asking one team to absorb the full cost, they found the answer inside the platform itself: Tanium's Role-Based Access Control. By mapping Tanium's RBAC model to Corebridge's internal team structure, they carved the platform into distinct, scoped environments, each giving a different business unit ownership over its own endpoints, data, and workflows — and a clear line of sight between budget contribution and value received. IT Operations, Security, and Compliance each became stakeholders in the purchase rather than passengers on someone else's procurement. This session tells that story: how RBAC became not just a security control but a commercial strategy, turning a single vendor negotiation into a multi-team win. | Keith Lethbridge - Corebridge Financial | |||
| Seeing Beyond the Firewall: External Attack Surface Management | ||||
Most organizations see their attack surface only from the inside while attackers see it from the outside. Tanium's External Attack Surface Management now discovers every Internet-facing host, service, web property, and certificate, every 6–8 hours instead of quarterly, feeding Tanium Atlas for unified internal/external reasoning and connecting to Attack Path Mapping, which shows exactly which exposures reach your crown jewels first. The result: a single, continuously-updated picture of the full attack surface, inside and out. | David SooHoo - Tanium Lucas Lyon - Tanium | |||
| Shadow AI: Hunting Unauthorized AI Tools with Tanium Atlas & Guardian | ||||
Shadow AI is now a board-level risk. Unauthorized agent tools with real CVE exposure: Guardian Spotlight detects it, Exposure Management scores it against policy, and Endpoint Management enforces the fix, all orchestrated by Tanium Atlas's Background Agents watching 24/7 with human approval gating every action. You get a multi-day investigation collapsed into a governed, minutes-long workflow. | Maayan Sela - Tanium Tyler Schultz - Tanium | |||
| Sharper Detection, Safer at Scale: Insights Engine & Federated SOC Architecture | ||||
False positives and one-size-fits-all suppression are big reasons SOC analysts stop trusting their own alerts. This new session introduces two Security Operations capabilities landing together: Insights Engine, catching techniques like process injection with far fewer false positives, and Federated SOC Architecture, with suppression rules and response actions scoped to each team's own profile. Combine that with existing features like Threat Navigator, MITRE ATT&CK mapping, and AI enrichment for alerts and see how confirmed findings surface directly in Tanium Atlas. You'll leave with a model for higher-fidelity detection that scales cleanly across multiple autonomous SOC teams. | Brent Midwood - Tanium Tyler Schultz - Tanium | |||
| Tanium Atlas for Everyone: Putting Autonomous IT in Every Stakeholder's Hands | ||||
Tanium Atlas puts the answers and reach of an entire team into one operator's hands. In front of a mixed technical/non-technical audience, plain-language questions prompt Atlas to assemble dynamic pages and surface next-step recommendations, every action gated by human approval. See Atlas's Speed, Scale, and Safety commitments in action today, with Background Agents, persistent Memory, Collaborative Pages, with MCP-based extensibility into Slack, ServiceNow, and Copilot arriving next. | Kat Ale - Tanium Michelle Zhang - Tanium | |||
| Tanium Beyond the GUI: From a Homegrown MCP to Shaping Tanium's Own | ||||
Common tasks — pulling logs, building packages by hand, uninstalling apps at scale — take more manual effort than they should. Eager to put MCPs to work early, SimCorp built its own: pairing the Tanium API with Claude to automate package builds from Winget and GitHub, uninstall software agnostically, and handle edge cases and log pulls in seconds. An hour-long packaging process converted to a single prompt, and cleanup projects once needing hundreds of packages now need just one. Since that innovation, Tanium has launched its own Atlas MCP & SimCorp was among the early preview participants. Next: SimCorp is adapting to the Atlas MCP - uncovering additional efficiencies across the enterprise | Ivan Malinovski - SimCorp | |||
| Tanium: Developers Unite – APIs, Agents, and the Tanium MCP Server | ||||
Get ready to explore the future of agentic integrations with Tanium. This session covers two ways to extend the platform: proven APIs for established workflows, and the new Tanium MCP Server to unlock the power of Atlas for your agents. Whether you're new to Tanium or a long-time developer, this session is for you. See it live, connect with the community, and leave ready to build what's next. | Ajendra Joshi - Tanium Kathy Church - Tanium Tim Brooks - Tanium | |||
| The AI Security Team Member Who Hallucinates (but Still Gets Invited to Meetings) | ||||
LLM-based tools are now embedded across cybersecurity operations — triaging alerts, summarizing threat intelligence, drafting incident reports — and are fast, cheap, and useful. They also hallucinate: per the SANS 2024 Security Operations Survey, 76% of teams use AI-assisted tools daily, and 41% have hit AI-generated hallucinations in threat reports weekly. Practical, operations-focused guidance for managing that risk is largely missing, tending toward technical failure-mode analysis or policy ignoring under-resourced teams for whom imperfect AI beats no analysis. The takeaway: keep deploying AI, but only with skepticism, verification, and frameworks for logging, validating, and trust-tiering its output. | Simon Lundmark - Epiroc | |||
| The Flight Plan for Zero Blind Spots: How Air France-KLM Rewired Compliance in Real Time | ||||
SCCM left Air France-KLM with blind spots — unmanaged software, non-admin installs, a slow patch cycle, and stacked agents — on a fleet managed by an external partner. What began as a compliance project, run as a three-year journey across asset inventory, vulnerability management, license optimization, and lifecycle automation, uncovered a bigger opportunity. The airline joined Tanium Atlas's private preview, converting scripts and configs into lightweight sensors without an outside partner. Results: near-total endpoint coverage, recurring savings across licensing and hardware leasing, and several million euros in avoided exposure — plus a cultural shift to one trusted source of truth. | Djamel Akkouche - Air France KLM Nicolas Courbin - Air France KLM | |||
| Threat Hunting with Tanium: Tracking Attacks at Scale | ||||
As a global web hosting provider, Newfold Digital is an attractive target for threat actors abusing its infrastructure for malware distribution and large-scale campaigns — and identifying affected servers used to be slow, manual work. With Tanium Live Response, the security team combines threat intelligence with rapid endpoint visibility to identify compromised systems and assess attack scope in minutes. YARA rules deployed at scale surface malware tied to emerging campaigns, and Live Response lets analysts collect forensic evidence and accelerate containment — enabling investigation without engineering or after-hours support. Result: response times cut from days to minutes. | Robbie Abraham - Newfold Digital | |||
| Zero Downtime, Zero Touch: Rebuilding Endpoint Operations Across a Health System | ||||
Duke Health Technology Solutions legacy endpoint tooling required manual patch gating, physical media for provisioning, and a separate MBAM stack for BitLocker key management — all while supporting a clinical estate with no dependable maintenance window. The team migrated more than 61,000 endpoints to Tanium, retiring the legacy tooling outright rather than running parallel stacks, moved to zero-touch patching, replaced USB imaging with PXE network provisioning, and consolidated eight IT teams onto a single agent and console. The migration surfaced over 15,000 unmanaged devices, moved 30,000+ devices to Windows 11 with zero downtime, and automated the ServiceNow CMDB feed. Support case volume fell 64% as platform usage grew roughly fivefold, and the team is now building toward proactive DEX and automated security response on the same agent footprint. | Amanda Ciriello - Duke Health Technology Solutions Luis Avila - Duke Health Technology Solutions | |||
| 11:00 AM - 11:30 AM (PST) | ||
|---|---|---|
| From Reactive to Autonomous: AI-Driven Patch Management with Tanium Atlas | Adam Gogal - Tanium Ryan Long - Tanium Tim Brooks - Tanium | |
| 11:00 AM - 11:45 AM (PST) | ||
| Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next | Jason Ellison - Tanium Steven Yang - Tanium | |
| Endpoint Management Roadmap: From Windows to Linux to OT | Aaron Sipe - Tanium Andrew Hecox - Tanium Sergey Belous - Tanium Tim Mintner - Tanium | |
| Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response | Brent Midwood - Tanium David SooHoo - Tanium Laura Iliescu - Tanium | |
| 1:15 PM - 1:45 PM (PST) | ||
| Tanium: Developers Unite – APIs, Agents, and the Tanium MCP Server | Ajendra Joshi - Tanium Kathy Church - Tanium Tim Brooks - Tanium | |
| 1:15 PM - 2:00 PM (PST) | ||
| Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next | Jason Ellison - Tanium Steven Yang - Tanium | |
| Endpoint Management Roadmap: From Windows to Linux to OT | Aaron Sipe - Tanium Andrew Hecox - Tanium Sergey Belous - Tanium Tim Mintner - Tanium | |
| Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response | Brent Midwood - Tanium David SooHoo - Tanium Laura Iliescu - Tanium | |
| 2:15 PM - 2:45 PM (PST) | ||
| Behind the Terminal Walls: IT and OT Convergence | Brent Walls - Indianapolis Airport Authority | |
| Compliance That Holds: Enforced Policy, Continuous Validation | Annie Ballew - Tanium Drake Sumner - Tanium | |
| Engineering Trust in AI Systems: How We Validate Atlas Before It Acts | Aidan Allchin - Tanium Dan Ballance - Tanium | |
| From Intel to Action: Agentic Threat Hunting with Tanium & Google Threat Intelligence | Aaron Smith - Tanium Brent Midwood - Tanium Duncan Miller - Tanium | |
| How Tanium Uses Tanium: Running Atlas on Our Own Estate | Jake McClean - Tanium Paul Black - Tanium | |
| Shadow AI: Hunting Unauthorized AI Tools with Tanium Atlas & Guardian | Maayan Sela - Tanium Tyler Schultz - Tanium | |
| 3:15 PM - 3:45 PM (PST) | ||
| DEX Workflows in Tanium Atlas: Reducing Help Desk Tickets and Closing the Loop | Jason Stough - Tanium Shivani Parikh - Tanium | |
| 3:15 PM - 4:00 PM (PST) | ||
| Core & AI Services Roadmap: Where Tanium Atlas Is Headed Next | Jason Ellison - Tanium Steven Yang - Tanium | |
| Endpoint Management Roadmap: From Windows to Linux to OT | Aaron Sipe - Tanium Andrew Hecox - Tanium Sergey Belous - Tanium Tim Mintner - Tanium | |
| Exposure Management & Security Operations Roadmap: Closing the Loop from Exposure to Response | Brent Midwood - Tanium David SooHoo - Tanium Laura Iliescu - Tanium | |
| 4:15 PM - 4:45 PM (PST) | ||
| Change Management with Tanium: Earning Adoption Across Autonomous IT Groups | Hayden Waters - University of Utah | |