IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.
Release Notes Active Directory Query (Version 2.0.1.0022)
Thank you for choosing Tanium. This document is intended to document changes between releases of Active Directory Query.
Active Directory Query 2.0.1.0022
Release Date: January 30th, 2018
This is the initial release of Active Directory Query to Tanium labs. For information on the contents of this solution, please see here.
Updates
- Supports local user and local group data collection for workgroup based systems. *Note:* The available data from workgroup based systems is limited and in a different format than data collected from domain joined systems.
- Supports collecting data for local users. Previous versions only collected data for domain based users.
- Logging has been centralized into <Tanium Client Installation Folder>\Tools\ADQuery\collectAdInfo.?.log
- Collects all local groups and their memberships.
- The adminGroups.xml file has been replaced with localGroups.xml.
- Best effort has been taken to normalize into English all user and group names who are Well Known SIDs.
- Members of groups now include indicator of whether the member is local or domain based. If domain based, the member’s domain name is included in the output.
- A new memberOf_ShortName attribute has been added to user and computer attributes. This is the group’s short name. For example: CN=Domain Admins,CN=Users,DC=<domain>,DC=<suffix> is shortened to Domain Admins.
- Computer and user group memberships now include the object’s Primary Group.
Bug Fixes
- Fixed an issue around user profiles that contain a null value for the last used time.
Additional Information
Known Issues and Workarounds
Any Saved Questions, Scheduled Actions, or Computer Group memberships that were targeting non-English names may need to be updated.
Additional Information
The package Collect Active Directory Info should be ran with a Distribute Over Time value in order to offset LDAP queries to Domain Controllers.