IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.

Tanium Cloud Release Notes Device Management

From Tanium Knowledge Base
Jump to navigation Jump to search

Note: Tanium Device Management is part of the Tanium™ Endpoint Management for Mobile solution.

Tanium Cloud Release Date: October 7, 2026

Apple Device Management

New Features

  • Added new settings categories for Apple devices: App Deployment and Home Screen Layout.
  • 802.1X EAP authentication is now available in both Wi-Fi and Wired Network settings, limited to the EAP types that can actually be configured.

Improvements

  • The Certificates category now supports the ACME credential type in the console.
  • The Certificates category now supports the Identity (PKCS #12) credential type on iOS and macOS. Devices download a password-protected identity from an HTTPS URL, which can include a device variable such as the serial number so each device gets its own document.
  • Settings can now repeat a key across multiple dictionaries of the same payload type.
  • You can now edit nested values directly inside a list row cell.
  • The System Extensions category is now Background Services and Extensions.

Bug Fixes and Maintenance

  • Fixed an issue where the Classroom and Parental Controls time-limit range type did not save correctly.
  • Management rights are now checked before automated unenrollment settings can be changed.
  • Secrets in settings are now detected and masked correctly when they appear as bare items in a list with a single sub-key.
  • Saving is now blocked, instead of silently allowed, when every key in an "at least one of" group is off. The redundant alert restating that requirement has been removed.
  • Fixed an issue where a setting's payload did not load correctly when opened from a collection.
  • Deleting one row in a list no longer discards unapplied edits in other rows.
  • Fixed an issue where a hidden fixed key could block Save without showing an error.
  • Fixed an issue that could create duplicate collections and VPP apps during Apple Business Manager (ABM) import.
  • Imported VPP apps are now named after the collection they were imported from.
  • Apple Import targeting filters are now normalized correctly, and filters with no content are rejected.
  • Software Update Enforcement settings now reject a target OS version that isn't a currently published Apple version for the setting's platform.

Google Android Device Management

Improvements

  • Added an Android Policies grid for Atlas, letting you browse Android policies.
  • Android policies now show a clear no-access message when you lack management rights, instead of failing silently.

Tanium Cloud Release Date: September 29, 2026

Apple Device Management

New Features

  • Added eleven new settings categories for Apple devices:
    • Accessibility - Configure Zoom, display, VoiceOver, audio, Sticky Keys, Slow Keys, and Mouse Keys options on macOS.
    • App Extensions - Control which app extensions can run on Macs and how apps use File Provider syncing.
    • Apple Intelligence - Control Apple Intelligence features, external AI provider integrations, and Siri on supervised iOS and macOS devices (iOS and macOS 26.4 and later).
    • Classroom and Parental Controls - Configure web content filtering, computer time limits, Dictionary restrictions, and Game Center on macOS.
    • Custom App Preferences - Manage any macOS app's preferences by preference domain.
    • Desktop and Dock - Configure the Dock, desktop picture, Finder, screen saver, menu bar extras, and System Settings panes on macOS.
    • Directory Services - Bind Macs to Active Directory, request Active Directory certificates, and configure mobile account and guest account options on macOS.
    • Login Window - Configure login window appearance and behavior, login and logout scripts, managed login items, and auto-logout on macOS.
    • Relay - Configure network relay servers that proxy traffic for matching domains on iOS 17 and later and macOS 14 and later.
    • Screen Sharing - Define managed screen-sharing connections, connection groups, and host restrictions on macOS 14 and later.
    • Single Sign-On - Configure generic and Kerberos SSO app extensions and Platform SSO for identity provider login on iOS and macOS.
  • Added a Devices tab and an install status donut to the App Store (VPP) app detail page, so you can see which devices are targeted by an app and how many are pending or managed.

Improvements

  • The Certificates category now supports the ACME credential type, enabling certificate enrollment with hardware-bound device attestation.
  • The Safari category now supports managed bookmark folders (iOS 26 and later) and a default extension policy with denied domains (iOS 18 and later).
  • The System Extensions category is now Background Services and Extensions. It adds kernel extension policy and managed login and background items, which prevent users from disabling management agents, including the Tanium Client, in System Settings on macOS 13 and later.
  • The App Store (VPP) app Overview tab now shows Notes and Created by / Updated by attribution, matching Enterprise Applications and Web Apps.

Bug Fixes and Maintenance

  • Fixed the "Install on Apple Silicon Mac" option for App Store apps so it is available for iOS apps that run on Apple silicon Macs. Previously the option was unreachable for most of them.
  • Fixed an issue where switching the enabled section of a single-section Screen Sharing or Apple Intelligence setting could change the declaration type under an existing identifier.
  • New settings in multi-section categories no longer send payloads for sections you did not configure.
  • Required fixed-value keys for Apple payload types are now filled in server-side, so settings created through the API no longer produce profiles that are missing keys Apple requires.
  • Decimal fields in the Apple setting editor now step in increments of 0.1 instead of 1, so the full range (for example, 0.0 to 1.0) is reachable from the stepper.
  • Expanded automated test coverage for Device Management module-service scheduled tasks and onboarding.

Google ChromeOS Device Management

Bug Fixes and Maintenance

  • Numeric fields nested inside ChromeOS policy settings now enforce their allowed ranges with an inline error message, instead of accepting out-of-range values and failing on save.

Google Android Device Management

Improvements

  • Added an Enrollment Tokens grid for Atlas, letting you browse enrollment tokens, see which policy each enrolls into and when it expires, open token details, and delete tokens.
  • Added an Enrollment Token editor for Atlas, letting you create a token (optionally cloned from an existing one) and view its QR code, zero-touch payload, and enrollment instructions.

Tanium Cloud Release Date: September 22, 2026

Apple Device Management

New Features

  • Added new settings categories for Content Filter, DNS, Wired Network 802.1X, Security and Gatekeeper, Cellular, Notifications, Content Caching, Printing, Energy and Time

Improvements

  • Restrictions settings expanded to cover the remaining catch-all applicationaccess keys

Bug Fixes and Maintenance

  • Wi-Fi Hotspot 2.0 keys are now reachable and aligned with Apple's schema.
  • FileVault, Software Update Enforcement, and Web Clips schemas aligned with Apple's current device-management schema
  • Time Machine schema now includes targets and clearer descriptions
  • Domains settings now accept any spaceless bundle identifier in the relaxed-apps list
  • Settings that decode into unexpected shapes are no longer quarantined from the UI — they now decode reliably into the schema
  • Wide integer values (beyond 32-bit) can now be read and written correctly
  • Large profile uploads now complete successfully end to end
  • Profile viewer now loads its data when opened, not when the component mounts
  • The UI now warns before a platform change would silently drop existing setting values
  • Cleared optional number fields stay empty instead of snapping back to a minimum value
  • Fixed list-rendering issue in the Apple settings list
  • File-contents viewer moved to the standard dialog component (visual/behavioral consistency only)
  • Made improvements to responsiveness of single endpoint view details.
  • Collection targeting now correctly respects "all values" and "max age" advanced filter options

Tanium Cloud Release Date: September 14, 2026

Apple Device Management

New Features

  • Added Kiosk and Single App Mode, Domains, AirPlay, Time Machine, and Setup Assistant settings categories for Apple devices, letting you configure app locking, domain and Safari settings, Time Machine backups, and Setup Assistant skip panes for iOS and macOS.
  • Added Lockable, Allow Downloads Over Cellular, and Install on Apple Silicon Mac toggles to VPP app configuration, giving you more control over how volume-purchased apps install and behave on managed iOS and macOS devices.
  • Added "Apple Software Update Status" and "Apple Beta Enrollment" sensors, so you can see each Apple device's pending OS update state, target version, failure details, and beta enrollment status.
  • Added Install State and Deadline Status breakdown reports to the Device Management Overview dashboard, showing counts of Apple devices by software update state and by how close they are to their update deadline.
  • You can now browse all Apple device collections from the Apple Device Status page, with sortable columns for settings, applications, targeting, and last-updated date, and drill in to view or edit any collection.
  • The Apple Device Status page now includes a read-only view of Apple Business Manager (ABM) device inventory and enrollment status, so you can check enrollment progress without leaving the console.

Improvements

  • Clicking a setting or application inside an Apple collection now opens a read-only detail view — showing device install status and which collections deploy it — instead of opening the setting editor.

Bug Fixes and Maintenance

  • The Tips and Tap to Setup options have been removed from the Automated Device Enrollment Setup Assistant skip keys, and the Accessibility option now correctly appears for macOS instead of iOS. Neither removed option ever had any effect; if your enrollment profile had either option selected, the selection is removed the next time you save that profile.
  • Fixed an issue where uploading a certificate file or a web clip icon in the Apple setting editor would fail.

Tanium Cloud Release Date: September 9, 2026

Apple Device Management

New Features

  • Added four new Automated Device Enrollment (ADE) Setup Assistant skip screens: Accessibility & Appearance, Device Features Tour, Liquid Glass, and Wallpaper.

Improvements

  • Added a “Hideable” toggle (iOS 18.1 and later) to the App Store app configuration for Volume Purchase Program (VPP) apps.
  • Added an “Included in Backup” toggle to the App Store app configuration for VPP apps; not available on macOS 26 and later.
  • The Apple setting editor now shows an inline validation message explaining why saving is blocked, instead of silently disabling Save with no explanation.
  • Cleaned up the Apple collection approval screen: removed a duplicated title and field labels, and clarified why Approve is disabled when no settings or apps are selected.

Bug Fixes and Maintenance

  • Fixed mislabeled “Apple Business Manager” text to correctly read “Apple Business” in the App Store category tile and the Apps & Books portal type column.
  • Reordered the Applications page so the App Store category card appears before the Enterprise Application card.
  • Restored column sorting on the Apps & Books organizational unit list.

Google Android Device Management

Improvements

  • Enabling automatic device deletion as a security posture action now requires an additional high-impact permission, since it factory-resets a device without further confirmation.
  • Automatic device deletion for security-policy violations is now limited to once per device per 24-hour period, preventing a repeated wipe-and-re-enroll loop for a device whose problem survives a factory reset.
  • The Enrollment Restrictions form now validates entries (notification emails, brand/model text, list length limits) inline as you type, and shows a clear message if the installed Device Management module is too old, instead of only failing on Save.

Bug Fixes and Maintenance

  • Fixed the Enrollment Restrictions form so editing one setting no longer silently corrupts brand/model entries that contain commas or discards configuration values it doesn’t recognize.
  • Fixed the Enrollment Restrictions tab so a configuration containing a security action the console doesn’t recognize no longer blocks saving, and now clearly shows which setting is unsupported.
  • Fixed several issues on the Sign-In Configurations tab where saving while the list was still loading, deleting entries in quick succession, or leaving an edit form open too long could unintentionally delete or resurrect sign-in configurations.
  • Improved concurrency handling for sign-in configuration updates to reduce the risk of one admin’s changes silently overwriting another admin’s concurrent changes.
  • Fixed the Android signup-verification status getting stuck on “Pending” for certain enterprise ID formats, and improved input validation on related sign-in setup APIs.
  • Expanded the list of recognized personal email domains during Android enterprise signup so admins signing in from more consumer email providers aren’t locked out of completing signup; also fixed a mismatch between the signup status toast and status indicator.
  • Corrected the Enrollment Restrictions tab description, which previously stated every device is always evaluated, to note a device may be admitted without evaluation during a service outage.
  • Documented that security posture enforcement (blocking or deleting non-compliant devices) requires the device’s assigned Android policy to have status reporting enabled; devices on policies without it are not enforced.
  • Fixed an issue where a long-enrolled Android device that stopped and resumed reporting could re-trigger duplicate enforcement events and admin notifications for a security status that hadn’t changed.

Tanium Cloud Release Date: August 26, 2026

Apple Device Management

New Features

  • Added the "Apple Device User" sensor which behaves comparable to the "Android Device User" sensor. Returns the email when available and the "display name" when not.

Bug Fixes and Maintenance

  • Fixed issue with Custom Tags that could result in tags being lost due to a sync race condition. (MEM-1204)
  • The Apple Custom Tags settings tab was removed from the workbench. Custom tags are now applied via the platform “Custom Tagging” content as of the prior release.
  • File upload retry handling improved: Fixes were made to the error / retry handling for file uploads.
  • Fixed an issue with the Automated Device Enrollment (ADE) Welcome screen; prevents a blank welcome screen.

Google ChromeOS Device Management

Improvements

  • Added a “Zero-Touch Portal” to the Android Enrollment Tokens page
  • Added a data grid to list connected workspaces with sync status, device count, and sync now capability.
  • Made improvements to the Atlas facing panel for policy changes.

Bug Fixes and Maintnenance

  • Minor bug fixes and dependency updates.

Google Android Device Management

New Feature

  • Add "Lost Mode" handling for Android devices. Includes:
    • Durable audit trail
    • Keeps only the latest session location history, prior sessions are purged.
    • "Android Lost Mode State" sensor reutrns the status (REQUESTED, ACTIVE, INACTIVE)
    • Added a tile on home page lost mode devices.
    • Updated Single Endpoint View
  • Added enrollment restrictions to the enterprise registration page.

Bug Fixes and Maintnenance

  • Fixed reporting of action status targeting Android devices; will report more failure specifics vs a generic failed message.
  • Fixed an issue with the posture decision engine; it may have not been weighing all reported flags.

Tanium Cloud Release Date: August 19, 2026

New Features

  • Tanium Endpoint Management for Mobile has added support for Apple's Volume Purchase Program.
    • Managed both MacOS and iOS store applications for devices managed by Tanium Device Management.
    • Create and configure applications for use within your enterprise.
    • Use collections to deploy Apple store applications to MacOS and iOS devices.

Improvements

  • Multiple improvements related to enhancing the Atlas experience for Apple, Chrome, and Android devices.
  • General improvements and refinements for the Android settings experience.
  • Added support for custom tags, use the same packages / actions for mobile endpoint management devices as we do for all other platforms. Accordingly, we have removed the top rail settings option for tagging devices.

Bug Fixes and Maintenance

  • Minor updates and tooling fixes.

Tanium Cloud Release Date: July 30, 2026

New Features

  • Tanium Endpoint Management for Mobile now includes support for Android devices. Enroll devices with ease with all supported management modes, take advantage of the fully integrated platform capabilities, and manage policy configurations and applications. Tanium Device Management Support for Android includes:
    • Management Modes - Tanium Endpoint Management for Mobile (EMM) supports enrollment of Android devices for all use cases: personally-owned (BYOD), corporate-owned with a work profile (COPE), corporate-owned (Fully Managed) and corporate-owned, dedicated (kiosk mode).
    • Full Platform Support - Take full advantage of native Tanium platform capabilities with your Android devices, including Interact questions, Data Explorer, Reporting and Dashboards, Asset, Machine Rights and Groups, Automate, Packages and Actions, and Single Endpoint View.
    • Policy Management - Full Android Management API support with configuration experience and custom policies.
    • Application Management - Silently install, update, uninstall, and ban applications. Use a curated organization-branded store with private, public, and web applications in a unified catalog.


Tanium Cloud Release Date: July 20, 2026

Improvements

  • Device actions: actions sent to Google-managed devices (lock, wipe, reboot, etc.) are now limited to 100 devices per action to prevent overly broad requests from exceeding Google API limits.

Bug Fixes and Maintenance

  • Fixed an issue where the Device Management content set summary failed to load on the Solutions page.
  • Fixed an issue where targeting on some Apple collections displayed blank instead of the configured computer group or sensor.

Tanium Cloud Release Date: July 7th, 2026

Bug Fixes and Maintenance

  • Fixed an issue where a newly enrolled device could wait up to an hour before resolving into collections that target devices with a negated custom-tag condition (e.g. "Custom Tags does not contain X").

Tanium Cloud Release Date: June 16, 2026

New Features

Tanium Device Management now extends visibility and control to ChromeOS devices. Connecting directly to Google Workspace. Device Management brings Chromebooks, including ChromeOS Flex devices, into the same console used to manage Windows, Linux, macOS, and iOS, and iPadOS. Inventory, Chrome policy enforcement, and remote device actions are available from a single integrated solution.

  • Google Workspace Integration - Connect Device Management to your Google Workspace tenant using a Google Cloud Platform service account with OAuth 2.0 and domain-wide delegation.
  • ChromeOS Inventory - Sync ChromeOS and ChromeOS Flex device data directly from Google Workspace.
  • Chrome Policy Management - View, apply, and reset Chrome policies across Organizational Units (OUs) and Groups directly from the Tanium console. Covers User and Browser, Device, and Managed Guest Session policy types.
  • Remote Device Actions - Take action on ChromeOS and respond to incidents without switching consoles.
  • Unified and Google Overview Dashboards - Monitor ChromeOS devices alongside iOS and iPadOS endpoints on the Device Management Overview dashboard, including Total Devices, ChromeOS Devices, Registered Devices by Type, Devices Checked in by Day, and Inactive Devices.
  • Single Endpoint View for Chrome - Drill into any ChromeOS device for status, platform details, quick actions, system and storage details, primary user, network and workspace details, action history, and client health, consistent with the existing Single Endpoint View pattern.

Bug Fixes and Maintenance

  • Fixes and improvements for enterprise applications, most notable for improving large file uploads and installation reporting.

Tanium Cloud Release Date: May 13, 2026

Bug Fixes and Maintenance

  • Minor updates and tooling fixes.

Tanium Cloud Release Date: April 27, 2026

Bug Fixes and Maintenance

  • Minor updates and tooling fixes.

Tanium Cloud Release Date: April 14, 2026

Bug Fixes and Maintenance

  • Fixed issue that could result in devices moving in and out of targeting results; seeing revolving settings applied to some devices.

Tanium Cloud Release Date: April 9, 2026

Bug Fixes and Maintenance

  • Fixed issue that could result in large files failing to upload.

Tanium Cloud Release Date: March 17, 2026

New Features

  • Enterprise Applications - Install and manage an entrprise application for macOS devices.
  • Tanium Client Installation - The Tanium Client will be installed on all macOS machines when enrolled.
  • Web Clips Support - Create a web clip on the Home screen of the users device for iOS devices.
  • Custom Tag Support - Add or remove custom tags for apple devices; use these tags for targeting, reporting, and grouping devices.
  • New curated settings include:
    • Certificates - Configure SCEP and certificate security assets.
    • Disk Management - Configure restrictions for external and network storage on the device.
    • Privacy Policies - Configure privacy policies for macOS features such as accessibility, camera, and more.
    • Safari Settings - Configure Safari settings.
    • System Extensions - Configure System Extensions for all endpoints
    • Wi-Fi Extensions - Configure iOS and macOS Wi-Fi settings

Bug Fixes and Maintenance

  • Security updates quality of life updates are included.

Tanium Cloud Release Date: December 19, 2025

  • Minor update to support changes in entitlements.

Tanium Cloud Release Date: December 3, 2025

  • Fixed Wifi Settings error "Failed to install profile...".

Tanium Cloud Release Date: November 25, 2025

  • Bug fixes and maintenance.

Tanium Cloud Release Date: November 10, 2025

Tanium Device Management brings Apple devices into the AEM ecosystem, enabling real-time telemetry, automation, and policy enforcement across macOS, iOS, and iPadOS. Mobile data becomes actionable within the same platform used for other endpoints, supporting investigations, compliance, and remote actions from a single, integrated solution.

Product Documentation and Resources