Beyond the Blind Spot: Automating Linux Patch Compliance at Scale

CBRE rolled Tanium out fleet-wide within two months, and Windows patching went smoothly — but most of its Linux estate runs Amazon Linux, whose repo/snapshot model wasn't supportable by Tanium Scan for Linux, blocking repo-based patching against a 14-day vulnerability SLA. Working with Tanium's ACE team and a Linux SME, CBRE proved out Ubuntu patching first, then built custom compliance sensors for snapshot-level visibility into Amazon Linux. Rather than a separate Linux playbook, the team extended its ring-based Windows/browser automation model to Linux, fitting reboot timing inside change-management workflows — a common blind spot at scale.

Additional details
Session Type
In-Person, Breakout
Session Tag
Endpoint Management
Role
IT Operations Managers, Systems Administrator, Systems Architect