IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.
Tanium Cloud Release Notes Core ADQuery Content
Important
Any Scheduled Actions running the Collect Active Directory Info package need to be recreated or updated to recognize the updated package. These Scheduled Actions must be run with a Distribute Over Time (DoT) value in order to offset LDAP queries to Domain Controllers - the recommended DoT is 3 hours. Core AD Query supports on-premise Domain Controllers only. Azure AD is not supported with Core AD Query.
Release Date: April 2nd, 2026
Improvements
- Updated a third-party dependency.
Release Date: March 31st, 2026
Improvements
- Improved endpoint metadata queries to increase performance
- Improved the Solution uninstall process to include deletion of Packages and Saved Questions used by AD Query
- Improved Primary User detection logic to increase accuracy.
- Decreased default log level for Collect AD Info to save disk I/O
- Removed the deprecated Core Content - AD Query - Tools Version sensor
- Removed support for legacy operating system versions
- Prevented registration of AD Query - Last Logged In User sensors with TDS to mitigate excessive load on endpoints
- Added metadata to improve interactions between AD Query and Tanium Ask.
Resolved Issues
- Fixed Unicode handling to allow the presence of various characters in group names
Release Date: January 3, 2024
Fixes
- Fixes an issue where the solution updates the "Is Windows" sensor to use PowerShell instead of VBS.
Release Date: November 16, 2023
Improvements
- Miscellaneous bug fixes, performance, and supportability improvements
Release Date: April 25, 2023
Improvements
- Upgraded various third-party libraries to newer versions
Release Date: February 17, 2023
Fixes
- Checks to see if NameWellKnown.xml is populated before checking for renames
- Minor Bug fixes
Release Date: January 10, 2023
Improvements
- Deleted pre-XML dat legacy files from old occurrences of AD Query
- Improved file removal for AD Query import updates
- Increased user attribute collection for users discovered by Group Inventory
- Runs Azure data collection by default
- Added link to AD Query documentation to Solutions page
- Increased number of Well Known SIDs
- Improve user name and domain detection during initial phase of user inventory
Fixes
- NameWellKnown.xml is now more accurate
- Non-English sensors now show correct decimal separator for sensor version
- Standardized error messages
- Corrected internal files
Release Date: November 15, 2022
Important
- The Collect Active Directory Info package is now delivered via ECF. Please review the documentation for migration instructions. This change means the package no longer needs to be recreated or updated after each solution update.
Improvements
- Build updates to reduce solution size
- Updated to the most recent version of the endpoint tool builder
Fixes
- The AD Query - Last Logged in User Name now raises an error instead of returning the error as sensor results
Release Date: July 20, 2022
Fixes
- Corrected a variable declaration error in domain SID to name resolution
Release Date: July 5, 2022
Improvements
- When searching for a domain controller, any responding domain controller is now valid instead of only a primary domain controller
Fixes
- AD Query - Local Administrators sensor is now case insensitive
- Collect Active Directory Info package has improved safeguards against incorrect domain names on objects in inventory
- AD Query - Local Administrators and AD Query - Local Group Membership sensors no longer misreport the name of a member if the member was not found in inventory
- Improved error handling for date strings
- Duplicate domain entries are now removed
Release Date: February 9, 2022
Improvements
- improvements to cmd.exe usage
Fixes
- Last Logged in User sensor no longer fails on non en-US machines
- Last Run Status now correctly reports failed message
Release Date: October 22, 2021
Fixes
- Corrected a case sensitivity issue in "AD Query Computer Group Memberships" and "AD Query Computer Has Group Membership" sensors.
- Corrected an issue with the "AD Query - Has Stale Results" sensor not returning True/False results
- Corrected an issue causing users in trusted domains from being reported correctly
- Corrected an issue causing the inventory process to abruptly fail
- Corrected an issue causing unresolvable SIDs to incorrectly be identified as a user or group
- Corrected an issue causing unresolved SIDs to display an empty string instead of their SID
- Corrected a typo in the "AD Query - Has Stale Results" sensor
Enhancements
- Reduced the max age limit of user profiles limit to reduce the number of outdated profiles being processed
- Improved handling of "Not enough time has elapsed" messages in the AD Query - Last Run Status sensor
- The inventory process has added checks to verify failed inventory actions are not re-run
- The inventory process no longer uses the last modified date of a user profile to determine the last logon date for a user
- Added an ability to pre-stage domain info
- Event Log data is now used to supplement certain user and domain data. *Requires the Event Log to be configured to record successful user logon events
- Improved inventory run time reporting
Known Issues
- The "AD Query - Last Run Status" sensor will incorrectly return "Script failed for unknown reasons" if a prior inventory run completes without error and the following inventory run is too soon.
Release Date: February 8, 2021
Fixes
- Fix "AD Query - Has Stale Results" results on non-English Windows installs.
Release Date: February 5, 2021
NOTE: As always any scheduled actions that push the "Collect Active Directory Info" package need to be recreated in order for the collected data to match the current version of this solution.
Bug Fixes
- Corrected an issue allowing certain domain group types to be included in local group inventory on Domain Controllers.
- Corrected an issue in the AD Query - User Has Group Membership sensor that caused it to incorrectly return a True result if a searched name was part of another group having a longer name that contained the searched name.
- Corrected an issue causing the AD Query - Has Stale Result sensor to fail user inventory age.
- Corrected an issue preventing xml elements in the inventory file to be updated if an additional computer or user attribute had its character case changed when new inventory collection actions were run.
Enhancements
- Added an inventory cleanup process to remove objects that have not been inventoried in more than 45 days.
- Improved Primary User detection to no longer include secondary logons.
- The AD Query - Has Stale Results sensor now includes an additional check to verify the inventory file was last updated by the current content version. This helps customers determine if they are running outdated scheduled actions that reference a out of date Collect Active Directory Info package version.
Other
- Removed support for reporting results from legacy inventory files (compAttr.xml, localGroups.xml, and userAttr.xml) which were left remaining on endpoints when Core ADQuery Content version 3 was released. Leaving these files in place provided the following benefits:
- Sensors were still able to return valid results in the time period following the upgrade to the version 3 content and the next time an endpoint ran the version 3 Collect Active Directory Info package.
- Any customers who had custom content were granted a time window to migrate their custom content that referenced the legacy inventory files to now reference the new version 3 inventory file.
Notes
- The legacy inventory files will be removed the next time an endpoint runs the Collect Active Directory Info package version 3.1.2.
- Sensors in this release will now only return results from the new version 3 inventory file. This provides customers better notification of any endpoints which are not completing their inventory cycle.
Release Date: November 24, 2020
Improvements
- Improve handling of Azure AD based users
Fixes
- Correct an issue causing the inventory process to fail when the Event Log query returns a large amount of data.
- Correct an issue causing the name resolution randomization to fail and having name resolution occur for all objects every time the inventory process ran.
Product Documentation and Resources
- Please work with your Tanium TAM in order to most effectively use this content.
- ADQuery Documentation
- Tanium Product Documentation
- Tanium User Research
- Software Updates and Announcements Signup