Tanium Cloud Release Notes Enforce
Tanium Cloud Release Date: 7 August 2026
Dependency updates
- Dependency updates.
Resolved Issues
- Fixed an issue where uninstalling a module left its configuration behind in ECF which could cause a removed module's tools to still be deployed.
Tanium Cloud Release Date: 7 August 2026
Dependency updates
- Dependency updates.
Resolved Issues
- Fixed a critical bug that could cause the Enforce service to crash-loop and go fully offline when a Windows Security policy contained a malformed setting.
- Fixed an issue where an enforcement could no longer be saved or edited if one of its targeted computer groups had been deleted. Deleted computer groups are now clearly flagged on the enforcement details page so they can be removed.
- Fixed an issue where the AppLocker Warnings chart on the Enforce homepage would time out with an error instead of loading.
- Fixed an issue where the Enforce service could get stuck in a restart loop when it failed to register with the endpoint configuration service.
- Fixed an issue where the Enforcements page could return an error and fail to load for the whole environment when a policy's stored data did not match its policy type (which could happen when changing an existing Windows policy to a single-type policy such as SRP in place). Enforce now blocks changing a policy's type after creation, writes policy data scoped to its type, and safely skips a single unreadable policy instead of failing the entire list.
- Fixed an issue where uninstalling a module left its configuration behind in ECF, causing removed modules to still be deployed to newly installed clients.
- Fixed the AppLocker policy editor to display specific, actionable validation messages when an invalid path value is entered, replacing the previous generic error.
- Improved Enforce service startup reliability by adding a timeout to an internal MDM availability check, preventing the entire service from hanging if the MDM service is unresponsive.
Tanium Cloud Release Date: 28 July 2026
Dependency updates
- Dependency updates.
Resolved Issues
- Fixed an issue where the AppLocker Warnings chart on the Enforce homepage would time out with an error instead of loading.
- Fixed an issue where the Enforce service could get stuck in a restart loop when it failed to register with the endpoint configuration service.
- Fixed an issue where the Enforcements page could return an error and fail to load when a policy's stored data did not match its policy type (which could happen when changing an existing Windows policy to a single-type policy such as SRP in place). Enforce now blocks changing a policy's type after creation, writes policy data scoped to its type, and safely skips a single unreadable policy instead of failing the entire list.
Tanium Cloud Release Date: 23 July 2026
Dependency updates
- Dependency updates.
Tanium Cloud Release Date: 15 July 2026
Dependency updates
- Dependency updates.
Resolved Issues
- Fixed an issue where the Enforcements page could return an error and fail to load when a policy's stored data did not match its policy type (which could happen when changing an existing Windows policy to a single-type policy such as SRP in place). Enforce now blocks changing a policy's type after creation, writes policy data scoped to its type, and safely skips a single unreadable policy instead of failing the entire list.
Tanium Cloud Release Date: 1 July 2026
Improvements
- Added a new "Superseded" enforcement status that appears across the Enforce API, metrics, and trends dashboards alongside applied, error, and unsupported counts. Superseded status is now reported consistently whether a policy was applied through a legacy or current enforcement path, and Windows Firewall enforcement now correctly indicates when a policy has been superseded by another.
- Windows Firewall policies can now be applied through Local Group Policy Object. This allows the firewall settings to be recognized by Compliance scanning engines looking for CIS Benchmark compliance.
- Added the latest Windows Server 2025 October ADMX templates, including Windows AI, Secure Boot, and Internet Explorer policy settings.
- Windows Firewall rules now validate IP addresses in real time, flagging invalid addresses immediately rather than when saving.
- Policies can now be targeted based on endpoint client version, letting administrators scope enforcement to endpoints that meet the required capabilities.
- The policy-type search filter now returns results instantly, without waiting on a network request.
- Added a search filter to the GPO backup import list, making it easier to locate a specific backup entry.
- Added health alerts for periodic background tasks, such as Defender definition downloads.
- Increased the maximum length of GPO Security Settings text fields from 1,023 to 2,048 characters to support DISA STIG and similar compliance frameworks.
- This release includes security and dependency updates.
- Dependency updates.
Resolved Issues
- Fixed an issue where the Applied Policy Settings diagnostic sensor could fail and return no results for an endpoint when a policy item had not yet been verified.
- Fixed an issue where the IPv6-Opts and IPv6-NoNxt protocols were misapplied as HOPOPT; these protocols and the "Any" option now import and apply correctly, and the interface labels now match the labels shown in Windows.
- Fixed an issue where IPv6 address ranges were not accepted in firewall rules.
- Fixed an issue where setting the GPO log size limit to 0 was incorrectly displayed as "Not Configured."
- Fixed an issue where setting the GPO log size limit to its maximum of 32 MB caused an error on endpoints.
- Fixed an issue where policy status displayed incorrectly when disabling GPO enforcement.
- Fixed an issue where firewall rules containing RemoteAddress keywords failed to update.
- Fixed an issue where invalid port numbers were not clearly flagged during port configuration.
- Fixed an issue where the rule import preview displayed only one rule instead of all rules.
- Fixed an issue where invalid rules imported from endpoints were not flagged for easy identification.
- Fixed an issue where a "Policy priorities file is out of date" warning could linger for up to 30 minutes after a Linux Firewall policy was first enforced.
- Fixed an issue where adding a new policy type to an existing policy hid the newly added settings.
- Fixed an issue where category filters were not applied correctly when switching from the ADMX detail view back to the list view.
- Fixed an issue where policy priority could not be set.
- Fixed an issue where the enforcement details panel displayed outdated targeting rules when navigating between enforcements.
- Fixed an issue where the AppLocker import interface did not disable the Save button when an XML parsing error occurred.
- Fixed an issue where AppLocker script labels were inconsistent between the console and Windows endpoints.
- Fixed an issue where BitLocker policy dialogs showed inaccurate reboot messaging when "skip hardware test" was enabled.
- Fixed an issue where images in BitLocker policies could cause display problems on endpoints; SVG image support has been removed from BitLocker policies.
- Fixed an issue where Recovery Keys table labels for removable drives were inconsistent.
- Fixed an issue where the Enforce Overview remediation chart counts did not match the underlying data.
- Fixed an issue where policy-list action buttons shifted position while permission checks were running.
- Fixed an issue where the Target Hive dropdown in Windows remediation tasks showed both a selected value and a required-field error at the same time.
- Fixed an issue where the search filter in the Select Policy Types modal did not clear when switching platforms.
- Fixed an issue where the left and right panel filters in policy details did not stay in sync.
- Fixed an issue where policy name validation rejected forward slashes.
- Fixed an issue where importing a device-actions policy produced an error in the Policy Configurations section.
- Fixed an issue where invalid registry values, such as decimals, negative numbers, or out-of-range numbers, were accepted and could silently fail to enforce; these values are now rejected with a clear error.
- Fixed an issue where validation indicators did not display correctly for incomplete security policy settings.
- Fixed an issue where the background processing service did not recover correctly after its initial retry attempts.
Tanium Cloud Release Date: 23 June 2026
Dependency updates
- Dependency updates.
Resolved Issues
- Fixed an issue where the Applied Policy Settings diagnostic sensor could fail and return no results for an endpoint when a policy item had not yet been verified.
Tanium Cloud Release Date: 23 June 2026
Resolved Issues
- Fixed an issue where the Applied Policy Settings diagnostic sensor could fail and return no results for an endpoint when a policy item had not yet been verified.
Tanium Cloud Release Date: 18 June 2026
Improvements
- Added a new "Superseded" enforcement status that appears across the Enforce API, metrics, and trends dashboards alongside applied, error, and unsupported counts. Superseded status is now reported consistently whether a policy was applied through a legacy or current enforcement path, and Windows Firewall enforcement now correctly indicates when a policy has been superseded by another.
- Windows Firewall policies now support choosing the policy application method.
- Added the latest Windows Server 2025 October ADMX templates, including Windows AI, Secure Boot, and Internet Explorer policy settings.
- Windows Firewall rules now validate IP addresses in real time, flagging invalid addresses immediately rather than when saving.
- Policies can now be targeted based on endpoint client version, letting administrators scope enforcement to endpoints that meet the required capabilities.
- The policy-type search filter now returns results instantly, without waiting on a network request.
- Added a search filter to the GPO backup import list, making it easier to locate a specific backup entry.
- Added health alerts for periodic background tasks, such as Defender definition downloads.
- Increased the maximum length of GPO Security Settings text fields from 1,023 to 2,048 characters to support DISA STIG and similar compliance frameworks.
- This release includes security and dependency updates.
Resolved Issues
- Fixed an issue where the IPv6-Opts and IPv6-NoNxt protocols were misapplied as HOPOPT; these protocols and the "Any" option now import and apply correctly, and the interface labels now match the labels shown in Windows.
- Fixed an issue where IPv6 address ranges were not accepted in firewall rules.
- Fixed an issue where setting the GPO log size limit to 0 was incorrectly displayed as "Not Configured."
- Fixed an issue where setting the GPO log size limit to its maximum of 32 MB caused an error on endpoints.
- Fixed an issue where policy status displayed incorrectly when disabling GPO enforcement.
- Fixed an issue where firewall rules containing RemoteAddress keywords failed to update.
- Fixed an issue where invalid port numbers were not clearly flagged during port configuration.
- Fixed an issue where the rule import preview displayed only one rule instead of all rules.
- Fixed an issue where invalid rules imported from endpoints were not flagged for easy identification.
- Fixed an issue where a "Policy priorities file is out of date" warning could linger for up to 30 minutes after a Linux Firewall policy was first enforced.
- Fixed an issue where adding a new policy type to an existing policy hid the newly added settings.
- Fixed an issue where category filters were not applied correctly when switching from the ADMX detail view back to the list view.
- Fixed an issue where policy priority could not be set.
- Fixed an issue where the enforcement details panel displayed outdated targeting rules when navigating between enforcements.
- Fixed an issue where the AppLocker import interface did not disable the Save button when an XML parsing error occurred.
- Fixed an issue where AppLocker script labels were inconsistent between the console and Windows endpoints.
- Fixed an issue where BitLocker policy dialogs showed inaccurate reboot messaging when "skip hardware test" was enabled.
- Fixed an issue where images in BitLocker policies could cause display problems on endpoints; SVG image support has been removed from BitLocker policies.
- Fixed an issue where Recovery Keys table labels for removable drives were inconsistent.
- Fixed an issue where the Enforce Overview remediation chart counts did not match the underlying data.
- Fixed an issue where policy-list action buttons shifted position while permission checks were running.
- Fixed an issue where the Target Hive dropdown in Windows remediation tasks showed both a selected value and a required-field error at the same time.
- Fixed an issue where the search filter in the Select Policy Types modal did not clear when switching platforms.
- Fixed an issue where the left and right panel filters in policy details did not stay in sync.
- Fixed an issue where policy name validation rejected forward slashes.
- Fixed an issue where importing a device-actions policy produced an error in the Policy Configurations section.
- Fixed an issue where invalid registry values, such as decimals, negative numbers, or out-of-range numbers, were accepted and could silently fail to enforce; these values are now rejected with a clear error.
- Fixed an issue where validation indicators did not display correctly for incomplete security policy settings.
- Fixed an issue where the background processing service did not recover correctly after its initial retry attempts.
Tanium Cloud Release Date: 16 June 2026
Dependency updates
- Dependency updates.
Resolved Issues
- Fixed an issue preventing users from setting policy priority in Enforce.
Tanium Cloud Release Date: 14 May 2026
Improvements
- Enhanced Enforce Guide notifications, helping administrators investigate host firewall, antivirus, and automatic update issues.
Tanium Cloud Release Date: 13 May 2026
Resolved Issues
- Fixed a GPO import failure that occurred when importing GPO backups containing REG_BINARY registry values, which previously caused an invalid UTF-8 marshaling error.
- Fixed a bug where Security Settings User Rights Assignment policies silently failed to enforce when SIDs were entered using semicolons as delimiters.
- Fixed an issue where editing ADMX policies with certain checkbox settings, such as Windows Update notifications and BITS bandwidth controls, would fail with a ‘Failed to save policy’ error.
Tanium Cloud Release Date: 29 April 2026
Dependency updates
- Dependency updates.
Improvements
- Automatically set the content set when importing policies based on policy type, eliminating manual selection.
Resolved Issues
- Fixed an issue where updating policies could inadvertently remove valid configuration items for non-v2 policy types.
- Fixed an issue where users lost the ability to prioritize policies due to an overly restrictive permission check on the All Computers group.
- Fixed incorrect ADMX setting counts displayed when using the search filter.
- Fixed security user rights assignments verification failures caused by mismatched representations between policy friendly names and endpoint SIDs.
- Restored missing Username/Wildcard section in HKEY_USERS registry remediation actions.
- Restored policy prioritization access for users with read-only permissions to the All Computers group.
Tanium Cloud Release Date: 14 April 2026
Improvements
- Dependency updates.
- Improved policy type setting filters to match on setting metadata in addition to setting names, making it easier to find relevant settings.
Resolved Issues
- Fixed a bug where AppLocker policies with path conditions starting with a wildcard character failed to save.
- Fixed a bug where creating or modifying an enforcement did not immediately sync the changes to the endpoint configuration framework (ECF), requiring a background sync to bring changes into alignment.
- Fixed a bug where the DisableLocalAdminMerge setting could migrate incorrectly, causing the enforcement policy to behave unexpectedly after upgrade.
- Fixed a bug where updating an enforced policy could create duplicate configuration items, causing unexpected policy behavior on endpoints.
- Fixed an issue where upgrading from Enforce 2.10 to Enforce 3 left orphaned BitLocker V2 ECF items that could interfere with policy enforcement.
Tanium Cloud Release Date: 6 April 2026
Improvements
- Dependency updates.
- Fixed an ECF sync failure caused by duplicate local IDs in legacy enforcement data.
- Improved ADMX setting search to include results matching setting hashes and category paths.
- Improved reliability of enforcement service authentication by retrying token acquisition against both the platform and system user service when a token cannot be obtained.
- Removed the dependency on the system-user service (SUS) when Enforce fires alerts, improving reliability as SUS is being retired.
- Enforce API documentation is now available in the developer portal at developer.tanium.com. The Help menu in the Enforce workbench now includes a link to the Enforce API documentation.
Resolved Issues
- Fixed ADMX policy validation incorrectly rejecting settings that configure the same registry key and value to the same value.
- Fixed ADMX policy validation incorrectly rejecting valid policies that contained duplicate registry entries across different category paths.
- Fixed a bug where AppLocker policies were incorrectly shown as out of sync with the Default AppLocker Template after syncing.
- Fixed an issue where OR logic was not correctly saved when configuring sensor-based targeting criteria in enforcements.
- Fixed misleading Network Selection option descriptions in Windows Firewall policies when not using GPO-based enforcement.
- Removed a misleading log message that falsely indicated failures when updating enforcement status counts.
Tanium Cloud Release Date: 23 March 2026
Improvements
- Dependency updates.
- Enforce API documentation is now available in the developer portal at developer.tanium.com. The Help menu in the Enforce workbench now includes a link to the Enforce API documentation.
Resolved Issues
- Fixed a bug where AppLocker publisher rules configured with a 'version and below' condition displayed an empty version field in the local security policy editor.
Tanium Cloud Release Date: 17 March 2026
Improvements
- Dependency updates.
Resolved Issues
- Fixed a bug where enforcement target types could incorrectly be overwritten during background update cycles, causing enforcement configurations to become malformed.
- Fixed a bug where enforcements with malformed targeting configurations failed to apply correctly on startup.
Tanium Cloud Release Date: 12 March 2026
Improvements
- Dependency updates.
Resolved Issues
- Fixed an issue where content sets associated with Enforce policies could be accidentally deleted, orphaning policy configurations.
- Fixed the 'Applied Machine Policies' diagnostic sensor failing to return results when policy names contain multi-byte characters.
Tanium Cloud Release Date: 11 March 2026
Improvements
- Dependency updates.
- Improved RBAC enforcement by hiding the policy Prioritize button from users who do not have permission to update policy priorities.
Resolved Issues
- Fixed an issue that could cause a service startup failure on upgrade.
- Fixed a bug where enforcement target types were being incorrectly overwritten during background update cycles which could cause enforcement configurations to become malformed.
- Fixed an issue that caused the workbench to crash that when viewing or editing enforcements with malformed question targeting.
- Fixed an issue where duplicate entries could be added to ADMX list box fields without displaying a validation error.
- Fixed an issue where importing a GPO backup into Enforce would silently drop certain policy values, causing enforced settings to be applied incorrectly.
- Fixed the 'Applied Machine Policies' diagnostic sensor failing to return results when policy names contain Japanese or other multi-byte characters.
Tanium Cloud Release Date: 3 March 2026
Improvements
- Dependency updates.
Resolved Issues
- Fixed a service startup crash that could occur when an Enforce-managed Saved Question was moved to a different content set.
Tanium Cloud Release Date: 24 February 2026
Improvements
- Dependency updates.
- Improved service handing for bad request data.
Resolved Issues
- Fixed an issue that could prevent the editing of enforced policies.
- Fixed an issue that could prevent the editing of enforcements that use question based targeting.
- Fixed an issue that could cause the service to crash on startup.
Tanium Cloud Release Date: 19 February 2026
Improvements
- Dependency update.
Tanium Cloud Release Date: 12 January 2026
Improvements
- Added API support for rotating FileVault keys on device management-managed devices.
- Enabled FileVault key rotation button in Enforce GUI for device management keys.
- Improved BitLocker legacy policy status reporting when superseded by non-legacy policies.
- Dependency updates.
Resolved Issues
- Fixed server errors when policies contain unknown fields.
- Fixed AppLocker hash rule import and enforcement for rules without file sizes.
- Fixed remediation enforcement status data retrieval failures due to missing computer group permissions.
- Fixed BitLocker policy enforcement status cycling between Applied and Not Applied states.
Known Issues
Issue 1
An issue has been identified that prevents the editing of enforced policies for the following policy types:
- AppLocker
- Device Control - All Devices - Windows
- Device Control – Removable Storage - Windows
- Tanium Removable Storage Access Control
A fix for this issue has been identified and will be implemented in an upcoming release. Until that time, use this workaround to make changes to these policy types.
- Clone the current affected policy.
- Enforce the cloned policy with a higher priority than the current policy enforcement.
- Delete the old enforcement.
- Edit the newly enforced policy as needed.
Note that this issue will be resolved automatically in an upcoming release. If no policy updates are needed for the impacted policies, no action is required.
Issue 2
An issue has been identified that prevents the editing of enforcements that use question based targeting. A fix for this issue has been identified and will be implemented in an upcoming release. Until that time, use this workaround to make changes to these enforcements.
- Edit the enforcement.
- Clear out the question targeting.
- Add back the same question targeting that was there before it was cleared.
- Save the enforcement
Note that this issue will be resolved automatically in an upcoming release. If no enforcement updates are needed for the impacted enforcements, no action is required.
Tanium Cloud Release Date: 9 January 2026
Improvements
- Fixed issue that prevented saving of ADMX based policies.
Tanium Cloud Release Date: 6 January 2026
Improvements
- Added API support for rotating FileVault keys on device management-managed devices.
- Enabled FileVault key rotation button in Enforce GUI for device management keys.
- Dependency updates.
Resolved Issues
- Fixed 403 permission errors when enforcement status updates use sensors from non-Enforce content sets.
- Fixed FileVault key escrow to properly update creation timestamps when keys are rotated.
- Fixed server errors when policies contain unknown fields.
- Increased SID input field width in Local Policies configuration.
Tanium Cloud Release Date: 15 December 2025
Improvements
- Multi-type policy support
- Tanium Enforce now includes a major improvement to policy management with the introduction of multi-type policy support, enabling you to configure multiple policy types within a single unified policy object.
- Group Policy Object (GPO) import
- Tanium Enforce bridges the gap between traditional Group Policy and modern endpoint management with comprehensive GPO import capabilities, enabling you to migrate your existing Windows policy infrastructure without starting from scratch. This powerful migration toolset eliminates weeks of manual policy recreation and allows you to import industry standards like the CIS Build Kits or the Microsoft Security Baselines.
- Dual CSP and LGPO enforcement
- Tanium Enforce introduces flexible enforcement capabilities with simultaneous Configuration Service Provider (CSP) and Local Group Policy Objects (LGPO) support for Windows policies. This dual enforcement approach resolves compliance scanning discrepancies which minimizes false negatives in compliance reporting
- Extend beyond standard ADMX templates
- Configure additional registry settings alongside standard ADMX template mappings, giving you the flexibility to address organization-specific requirements and edge cases that fall outside predefined administrative templates while maintaining a unified policy structure.
- Configure Policies on Windows Services
- The startup behavior of Windows Services can now be configured in Windows Security Settings. You can configure the default Windows Services and add additional services.
- Policy management
- Improved policy creation workflow with better organization and clearer user guidance.
- Improved policy validation with enhanced error messaging and real-time feedback.
- Improved policy list and search capabilities for better policy discovery.
- Improved support for configuring content sets for policies so that you can associate policies with specific content sets and custom RBAC roles to limit policy visibility.
- Improved policy import and export functionality for seamless policy migration between environments.
- Windows CIS compliance
- Enhanced GPO import functionality for Windows security settings.
- Enforcement status
- Improved enforcement status reporting accuracy and performance.
Resolved Issues
- Policy enforcement
- Fixed an issue where the Join Microsoft MAPS setting failed to apply on Windows endpoints.
- Fixed an issue where BitLocker policies failed to enforce correctly on certain Windows configurations.
- Fixed an issue where Security Settings policies failed to enforce on domain-joined Windows endpoints.
- Fixed an issue that prevented policy enforcement on endpoints when ECF item creation exceeded timeout limits.
- Enforcement status
- Fixed an issue where enforcement status updates failed to reflect current policy state on endpoints.
- Fixed an issue that prevented enforcement status updates from completing within expected time intervals.
- Fixed an issue where enforcement status reporting displayed incorrect computer group compliance percentages.
- API and backend
- Fixed an issue where background job processing failed for large-scale enforcement operations.
- Fixed an issue where database migration scripts failed when upgrading from earlier Enforce versions.
- Firewall policies
- Fixed an issue where Linux firewall rules with LOG targets failed to validate correctly.
- Fixed an issue where Windows Firewall policies did not apply rule configurations as expected.
- Fixed an issue that prevented firewall policy import from GPO backups.
- Security and compliance
- Fixed an issue where Security Settings policies failed to apply on endpoints after policy modification.
- Device control
- Fixed an issue where USB device control policies failed to block devices as configured.
- Fixed an issue where device control sensors reported incorrect device status information.
- Performance and stability
- Fixed an issue where WMI queries consumed excessive CPU resources on Windows endpoints.
- Fixed an issue where endpoint tool duplication caused unnecessary network traffic.
- Fixed an issue where database queries for policy list retrieval performed poorly with large policy sets.
Known Issues
Issue 1
An issue has been identified that prevents the editing of enforced policies for the following policy types:
- AppLocker
- Device Control - All Devices - Windows
- Device Control – Removable Storage - Windows
- Tanium Removable Storage Access Control
A fix for this issue has been identified and will be implemented in an upcoming release. Until that time, use this workaround to make changes to these policy types.
- Clone the current affected policy.
- Enforce the cloned policy with a higher priority than the current policy enforcement.
- Delete the old enforcement.
- Edit the newly enforced policy as needed.
Note that this issue will be resolved automatically in an upcoming release. If no policy updates are needed for the impacted policies, no action is required.
Issue 2
An issue has been identified that prevents the editing of enforcements that use question based targeting. A fix for this issue has been identified and will be implemented in an upcoming release. Until that time, use this workaround to make changes to these enforcements.
- Edit the enforcement.
- Clear out the question targeting.
- Add back the same question targeting that was there before it was cleared.
- Save the enforcement
Note that this issue will be resolved automatically in an upcoming release. If no enforcement updates are needed for the impacted enforcements, no action is required.
Tanium Cloud Release Date: 1 December 2025
Improvements
- Dependency updates.
- Added integration between Enforce and Device Management.
Resolved Issues
- Fixed an issue in the Enforce recovery key grid that caused only the first 100 keys to be displayed.
Tanium Cloud Release Date: 19 November 2025
Improvements
- Dependency updates.
Resolved Issues
- Fixed an issue where the Cluster Policy edit screen automatically added unwanted requirements to policy selectors when editing existing cluster policies.
- Fixed an issue where Device Control - Removable Storage policy details displayed incorrect information for write-denied devices.
- Fixed an issue that could cause the Enforce service to crash on startup.
- Fixed an issue that caused exported Enforce Policies to be missing data that then prevented these policies from being importable.
Tanium Cloud Release Date: 24 October 2025
Improvements
- Added support for Windows 11 2025H2 templates, ensuring compatibility with the latest Windows operating system features and security requirements.
- Updated the Remove Enforce Firewall Rules Package to improve firewall rule management capabilities.
- Dependency updates.
Resolved Issues
- Fixed UI performance issues and policy validation errors that were causing slow response times and policy duplication problems.
- Optimized API responses for enforcements to reduce data transfer and improve performance.
- Improved BitLocker encryption method handling to ensure registry keys are set and deleted together, matching Windows behavior and preventing configuration drift.
- Fixed an error that occurred when creating BitLocker policies with "Recovery Key Rotation: Never" setting. The system now properly handles the recovery key expiration configuration.
- Fixed a permissions issue for users assigned to the “All Computers” group when editing enforcements
- Resolved an issue with AppLocker that failed to return results for very large Applocker policies.
Tanium Cloud Release Date: 29 September 2025
Resolved Issues
- Fixed an issue that could cause a Device Control - Removable Storage Policy to be incorrectly configured.
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
- Dependency updates.
Tanium Cloud Release Date: 16 September 2025
Resolved Issues
- Fixed an issue that caused Device Actions created outside of the Enforce Content set to fail to create necessary Scheduled Actions.
Tanium Cloud Release Date: 2 September 2025
Resolved Issues
- Fixed an issue that could cause the Enforcement Status presented in the Enforce Workbench to be stale.
- Fixed an issue that could cause the Recovery Key Portal to fail to load in the Console.
Tanium Cloud Release Date: 20 August 2025
Resolved Issues
- Removed unnecessary validation for BitLocker recovery information settings.
Tanium Cloud Release Date: 19 August 2025
Improvements
- Fixed an issue that could cause Access Denied errors during Anti-Tamper preview operations.
- Improved Policy List page performance, reducing response payload sizes and improving load times for policy management operations.
- Dependency updates.
Resolved Issues
- Resolved issue where the Enforce - Suspend BitLocker package wasn't creating the required bl-suspended file, preventing BitLocker from recognizing intentional suspension.
- Resolved issue where bitlocker-volumes.json files were left behind after failed encryption attempts, preventing proper BitLocker processing.
- Resolved firewall rule positioning problem where Linux firewall rules with multiple source addresses were incorrectly placed below default chain rules, preventing proper rule evaluation on CentOS 7 and RHEL 7 systems.
- Resolved policy configuration page loading issue that occurred when the total size of all policies exceeded 67MB, enabling proper policy list display.
- Resolved Policy List crashes that occurred when Device Control - All Devices policies were displayed, fixing an issue where the interface would crash when attempting to load policy data.
- Resolved an issue where priorities would not be prioritized correctly if reprioritized in the workbench.
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 8 July 2025
Resolved Issues
- Fixed an issue that could cause policy enforcement to fail.
- Dependency updates
Tanium Cloud Release Date: 1 July 2025
Resolved Issues
- Dependency updates
Tanium Cloud Release Date: 19 June 2025
Improvements
- BitLocker policies have been redesigned and are applied using an improved process
- With this release, existing BitLocker policies become Legacy BitLocker policies. For more information on working with both policy types, see "Important notes for working with BitLocker and legacy BitLocker policies" in the Enforce User Guide.
- BitLocker policies are now applied using the EnforceCX for greater resiliency
- Keys will no longer automatically rotate if a BitLocker policy is reapplied
- Additional BitLocker settings are now available to configure more advanced settings
- Enforcement status will now only show success if encryption is completed
- Password/Pin requirements now honor complexity rules
- Non-Tanium Administrators can view BitLocker Keys for machines that are not currently registered in TDS (requires Tanium Client 7.7 or later)
- Microsoft Defender Exclusions for Tanium Client were updated to reflect Tanium Client changes
- Linux Firewall policy now supports SUSE Linux Enterprise Server
- New Enforce Observations are now available in Tanium Guide (Firewall, AV, BitLocker)
Resolved Issues
- Fixed an issue where AppLocker policies attempted to apply on Windows Core. AppLocker policies will now not be applied on Windows Core
- Windows firewall rules filtering is now case insensitive
- Fixed an issue that prevented Distribute Over Time from functioning on Defender scans
- Fixed an issue that prevented using the status filter in the Recovery Portal
- Fixed an issue where the logging was not clear in firewall policies
- Fixed an issue where multiple rule firewall policies would fail to apply on RHEL9
- Fixed an issue where setting a policy start time as endpoint local time was not properly calculated
- Fixed an issue where creating an exception does not work when configuring AppLocker global settings
- Fixed an issue where editing a Stream profile setting might not show properly in the user interface
- Dependency updates
Tanium Cloud Release Date: 5 June 2025
Resolved Issues
- Fixed and issue that caused the Power Management setting view to be incorrect.
- Fixed an issue that could cause Tanium Packages managed by Enforce to fail to be created in airgapped environments.
- Fixed an issue that caused Microsoft Defender metadata tracked by Enforce to be incorrect.
Tanium Cloud Release Date: 19 May 2025
Resolved Issues
- Fixed an issue that could caused upgrade errors for on premises installations of Tanium Enforce.
Tanium Cloud Release Date: 29 April 2025
Resolved Issues
- Dependency updates.
- Fixed an issue that could enforcement information in the UI to be missing.
- Fixed an issue that could cause the "Enforce - Diagnostic - Applied Policy Settings" sensor to return an error.
- Fixed an issue that could cause Machine Administrative Template Policies to be corrupted on upgrade of Tanium Enforce to version 2.9.488.
- Fixed an issue that could cause delays in Enforce configuration application to endpoints.
- Fixed an issue that could cause Enforcements to fail when the combination of Policy and Enforcement exceeded 256 characters.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 7 April 2025
Resolved Issues
- Dependency updates
- Fixed an issue that could delay Enforce configuration deployment to endpoints.
- Fixed an issue that could cause high rates of read errors on Enforce saved questions.
Tanium Cloud Release Date: 17 March 2025
Resolved Issues
- Dependency updates
- Fixed an issue where the path for Windows Defender exclusions for the Tanium Client would not exclude the correct path
- Fixed an issue where updating AppLocker default settings was not reflected in existing AppLocker policies
Tanium Cloud Release Date: 27 Feb 2025
Resolved Issues
- Resolved an issue that could prevent priorities to work correctly for Remediation Actions
Tanium Cloud Release Date: 19 Feb 2025
Improvements
- Added support for Tanium Client 7.7
Resolved Issues
- Fixed an issue that prevented Defender definition updates if the /tmp directory was missing
- Fixed an issue that caused upgrades to fail if a policy had a null description
- Fixed an issue that did not allow "Always install with elevated privileges" to be set for both User and Machine ADMX policies
Tanium Cloud Release Date: 31 Jan 2025
Important Notes
- With this release, enforcing policies on endpoints running the following versions of Windows is no longer supported:
- Windows 7
- Windows 8
- Windows 8.1
- Windows Server 2008
- Windows Server 2008 R2
- Windows Server 2012
- Windows Server 2012 R2
- For detailed information about endpoint requirements, see Enforce User Guide: Endpoints.
- The Enforce - Tools Versions sensor is now deprecated. Use the Endpoint Configuration - Tools Status sensor instead.
- Using Microsoft System Center Endpoint Protection (SCEP) with anti-malware policies is no longer supported.
Improvements
- Endpoint Encryption:
- Refactored encryption architecture to improve application resiliency
- Encryption status now provides reporting for offline devices
- Reporting enhancements, including adding rotation requests to audit history
- Encryption Key Recovery Portal:
- Recovery Portal now supports Tanium Cloud integration
- Installation is supported on RHEL, CentOS, Rocky, Amazon, Ubuntu, Windows
- Identity Provider configuration updates to support multiple recovery portals
- Encryption Key Recovery Portal:
- Application Control policies:
- Default rules can now be pushed to existing AppLocker policies
- Anti-malware policies:
- Updated the Tanium exclusions list
- Set the grace period minimum to 1 day
- Multiple policy enhancements:
- Improved validation for values entered in the policy
- Improved RBAC of policy content sets and policy types
- Improved error messaging and workflows for policy content sets
- Improved AppLocker audit/block reports
- Editable Remediation policy tasks titles
- Improved policy priority reporting
Resolved Issues
- Policies:
- Machine Administrative Templates:
- Fixed an issue where Chrome extensions failed to be blocked properly
- Fixed an issue where the status might erroneously report "Not Applied" due to anti-malware settings
- Fixed an issue where old ADMX templates were no longer showing as recognized
- Fixed an issue where enabling anti-malware settings persisted if the policy was imported
- Fixed an issue where specific Defender registry key/values could impact Windows Update rollback actions
- Additional minor fixes
- Application Control:
- Fixed an issue where AppLocker policies erroneously attempted application on Windows Core Servers
- Fixed an issue where an empty field would prevent saving an AppLocker policy
- Fixed an issue where background processes could cause update counts to fail for AppLocker/SRP
- Fixed an issue where multiple AppLocker policies targeted to an endpoint could cause multiple applications despite prioritization
- Additional minor fixes
- Security Policies:
- Fixed an issue with empty field validations
- Fixed an issue with categorization headings
- Fixed an issue with security policy application when using SIDS
- Device Actions:
- Fixed an issue with column sorting
- Fixed an issue that erroneously generated a "No Results" message when first navigating to the Remediations tab on the Device Actions page
- Fixed an issue where a second enforcement on a remediation package failed to update the schedule of the remediation action
- Endpoint Encryption:
- Fixed an issue where enabling password complexity could prevent policy creation
- Updated values for key deletion
- Anti-malware:
- Fixed an issue where Enforce - Anti-malware Scan Results might show duplicate actions in Tanium's Action History (Console).
- Additional minor fixes
- Firewall:
- Fixed an issue where Windows Firewall Rules did not respect case sensitivity
- Fixed an issue where statuses did not distinguish between Linux distributions for firewall policies
- Fixed an issue where the firewall service on Linux endpoints did not provide enough information when an error occurred
- Additional minor fixes
- Cloud Workloads:
- Fixed an issue with the Cluster Policy Content Set
- Additional minor fixes
- Tanium Removable Storage Access Control:
- Fixed an issue with policy creation resulting in a validation error
- Policies:
- Fixed an issue where RBAC information was missing from Policy Details
- Fixed minor UI issues for multiple policy types
- Additional minor fixes
- Enforcements:
- Additional minor fixes
- Service:
- API:
- Fixed an issue where the API would provide improperly formatted JSON in the response.
- Additional minor fixes
- Settings:
- Fixed an issue where an erroneous success message displayed when entering unsupported values
- Fixed an issue where the reissue interval could be set shorter than the package expiration default (60 mins)
- Additional minor fixes
- Endpoint Encryption:
- Fixed several UI issues
- Fixed an RBAC issues where a Recovery Key User/Viewer did not have permission to view/export recovery keys from Enforce
- Fixed an issue where having a large number of keys could cause filtering to fail
- Fixed an issue where the Recovery Portal installation file would fail to download
- Additional minor fixes
- Statuses:
- Additional minor fixes
- API:
- Machine Administrative Templates:
Tanium Cloud Release Date: 22 Jan 2025
Resolved Issues
- Fixed issue with the application of Windows policy list value settings which could result in lower priority settings to be applied instead of the higher prioirity settings.
Tanium Cloud Release Date: 13 Jan 2025
Resolved Issues
- Fixed issue with default setting with the "Replace Values" option for ADMX policy settings.
- Fixed issue that caused error in the Endpoint Encryption landing page.
Tanium Cloud Release Date: 4 Dec 2024
Improvements
- Adds support for Tanium Guide including observations for Firewall configuration and Defender Platform Updates.
Tanium Cloud Release Date: 25 Nov 2024
Resolved Issues
- Fixed issue Windows Firewall Rules status sensor; was causing rules to incorrectly report as not applied.
- Fixed issue which preventer delivery of Defender definition updates for ARM based systems.
Tanium Cloud Release Date: 7 Oct 2024
Improvements
- Updated exclusions for Microsoft Defender for Endpoint.
Resolved Issues
- Fixed issue with application of AppLocker policies; updating of group policy will only occur once per application no matter the number of policies.
- Fixed issue that prevented importing of firewall policies that were exported from a console with the Japanese character set in use.
- Fixed issue with "network socket disconnected" error when trying to edit the Windows Defender platform settings in top rail.
Tanium Cloud Release Date: 16 Sep 2024
Improvements
- Improved the manner in which defender exclusions are removed from an endpoint; there is now an option that allows the user to specify that Enforce applied settings to be removed from the machine when the policy is removed from Enforce.
Resolved Issues
- Fixed issue in how AutomaticRestartSignOn setting is handled by Enforce to accommodate vendor changes.
Tanium Cloud Release Date: 3 Sep 2024
Resolved Issues
- Fixed issue that could result in AppLocker policies being applied to Windows Server Core endpoints; may result in endpoint being unable to execute VB Script on affected machines.
- Fixed issue with inconsistent status report for ADMX settings; status has been updated to return 'Not Applied' in these scenarios.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 19 Aug 2024
Resolved Issues
- Fixed issue that prevented creation of BitLocker policies with "Enforce Password Complexity".
- Fixed issue that prevented user from disabling "Anti-Malware" configuration when editing a policy.
- Fixed issue with AppLocker policy creation that would error on creation when option file size field left empty.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 5 Aug 2024
Resolved Issues
- Fixed issue with Anti-Malware Policy that prevented the policy from being disabled after being enabled.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 29 July 2024
Resolved Issues
- Fixed issue that prevents setting Device Installation Restrictions in a Machine Administrative Template.
Tanium Cloud Release Date: 17 July 2024
Resolved Issues
- Fixed issue with remediation creation that would result in the remediation action being overwritten when a non-unique name is used.
- Fixed issue that could result in deletion of remediation actions if a user renames the enforcement.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tools Versions
- Endpoint tool versions are now managed through Endpoint Configuration and the Endpoint Configuration Toolset manifests.
Tanium Cloud Release Date: 26 June 2024
Resolved Issues
- Fixed issue that would prevent service from starting after upgrade.
- Fixed issue to resolve selection of content set for policies when a user has different content set permissions that the creator of the policy.
Tanium Cloud Release Date: 25 June 2024
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 14 June 2024
Improvements
- Endpoint Encryption
- Keys now respect management rights when viewing / auditing encryption keys.
- Improvements in Endpoint Encryption reporting
- Multiple policy enhancements
- Well known SIDs are now pre-populated in Security policies
- Anti-Malware scans provide a preview prior to deployment
- Improved validation for values entered in the policy.
- Improved RBAC of policy content sets and policy types
- Improved error messaging and workflows for policy content sets
- Improved AppLocker audit/block reports enhancements
- Editable Remediation policy tasks titles
- Improved policy priority reporting
Resolved Issues
- Resolved Policy issues
- Fixed issue with “Join Microsoft MAPS” settings failed to apply.
- Fixed issue with “Turn off automatic learning” failed to apply.
- Fixed issue where missing configurations would show up as extra settings.
- Fixed issue with case insensitivity of input fields allowed for duplicate firewall rules.
- Fixed issue with Device Actions would fail to create if a content set was selected
- Fixed issue with Device Actions failing to apply if a “Start Time” was selected
- Fixed issue where viewing the details of a firewall rule cause all rules to expand
- Fixed issue where AppLocker may intermittently fail to update block results
- Fixed issue where Device Actions failed to run if corrupt USER profiles were found in the Registry
- Fixed issue with Linux Firewall drop down options
- Fixed issue with the following ADMX templates would show up as extra settings:
- AppHVSI, AppPrivacy, AppxPackageManager, CloudContent, ControlPanel, and ControlPanelDisplay
- Endpoint Encryption
- Fixed localization issue in TPM sensor
- Fixed issue with column sorting dates
- Anti-Malware
- Fixed issue where “Anti-Malware scan settings” required additional management rights
- Fixed issue where Defender definitions failed to download
- Fixed issue with Anti-Malware Threat Details sensor returned “Unknown”
- Enforcements
- Fixed issue with sorting table on Enforcements page.
- Fixed issue with shortcuts on Enforcement creation page.
- Fixed issue where Enforce erroneously syslog messages on TanOS
Tools Versions
- Endpoint tool versions are now managed through Endpoint Configuration and the Endpoint Configuration Toolset manifests.
Tanium Cloud Release Date: 12 May 2024
Improvements
- Third-party dependency updates.
Tanium Cloud Release Date: 18 April 2024
Resolved Issues
- Fixed issue with sensors reporting "tools out of date".
- Fixed issue with Firewall policy resulting in validation error when using "LocalSubnet".
- Fixed issue with population of the AppLocker dashboard.
Tools Versions
- Endpoint tool versions are now managed through Endpoint Configuration and the Endpoint Configuration Toolset manifests.
Tanium Cloud Release Date: 4 April 2024
Improvements
- Updated ADMX policies definitions for Windows 11 23H2, Mozilla Firefox, Microsoft Office, Google Chrome, and FSLogix.
- Updated the predefined exclusions for Defender.
- Added Linux support the "Host Firewall Enabled" sensor.
Resolved Issues
- Fixed issue that prevented defender updates when using a custom location; improved logging to support troubleshooting.
- Fixed several issues related to permissions for editing policies and enforcements.
- Fixed issue with remediation service configuration when making a service startup "Delayed" when not supported; would result in timeout.
- Fixed issue with reporting of AppLocker audit events.
- Fixed issue that prevented enforcements to be updated when targeting was changed.
- Fix issue with editing a container policy, the "Always Pull" option would always show selected regardless of the actual value.
- Fixed issue with targeting for antimalware scans, when specifying computer names the computer group option was not respected.
- Fixed End User Notification PIN entry for BitLocker recovery, limits the code length to the allowed length.
Tools Versions
- Endpoint tool versions are now managed through Endpoint Configuration and the Endpoint Configuration Toolset manifests.
Tanium Cloud Release Date: 22 January 2024
Resolved Issues
- Fixed several issues related to cloud workloads configuration and policy application.
Tools Versions
- Includes Enforce Tools: 2.7.192
- Includes Enforce CX binary: 2.11.555
- Includes Recorder Tool (Installer): 3.14.28
- Includes Recorder binary: 2.11.1583
- Includes Driver Tool (Installer): 3.14.28
- Includes Driver binary: 3.3.27
- Includes Stream: 2.0.955
Tanium Cloud Release Date: 11 January 2024
Improvements
- Adds support for container workloads.
Resolved Issues
- Fixed issue with remediation policy to start windows service; now the status is correctly displayed after enforcement.
- Fixed issue with multiple End User Notifications being displayed when encrypting FileVault.
- Fixed issue with application of permissions for content sets; no longer requires explicit permission to "Enforce Windows" content if created as custom content.
- Fixed issue with single recovery key view copy; it now let's you copy the key.
- Fixed issue with Policy Configuration view, some fields were not wrapping correctly.
- Fixed issue with BitLocker recovery keys where keys may be deleted when selecting all then deselecting an item.
Tools Versions
- Includes Enforce Tools: 2.7.186
- Includes Enforce CX binary: 2.11.555
- Includes Recorder Tool (Installer): 3.14.28
- Includes Recorder binary: 2.11.1583
- Includes Driver Tool (Installer): 3.14.28
- Includes Driver binary: 3.3.27
- Includes Stream: 2.0.955
Tanium Cloud Release Date: 28 November 2023
Improvements
- Export of encryption keys will now be reported as an "Export" in the audit log.
- Added ability to "unlock" a user account for MDM endpoints.
- Added the ability to un-delete a recovery key from the workbench.
- Includes support for Tanium Endpoint Change Management.
Resolved Issues
- Fixed issue with targeting for Windows Machine Administrative template causing SCEP to be installed on non-targeted endpoints.
- Fixed issue where Antimalware aggregate results were not created in the Enforce Antimalware content set; with action approvals turned on this would require the user to approve changes to the policy / targeting.
- Fixed issue with editing of an Enforcement; existing computer groups will be maintained when editing computer group targeting.
- Fixed issue with rotation of recovery keys, previously some keys may have been duplicated if the rotation fails.
- Fixed issue with remote recovery key database when using SSL connection.
- Fixed WBEM error when applying Remote Assistance configuration via Machine Administrative Templates.
- Fixed issue related to "Enable Headless UI Mode", the AllowUserUIAccess value will now be set correctly.
Other
- The Purge Remediation actions have been deprecated; customers should use the Device Retirement capabilities available in Provision. Existing customers will be able to continue to use the purge policies.
Tools Versions
- Includes Enforce Tools: 2.7.141
- Includes Enforce CX binary: 2.11.555
- Includes Recorder Tool (Installer): 3.14.28
- Includes Recorder binary: 2.11.1583
- Includes Driver Tool (Installer): 3.14.28
- Includes Driver binary: 3.3.27
- Includes Stream: 2.0.955
Tanium Cloud Release Date: 26 October 2023
Resolved Issues
- Fixed issue that caused error when synchronizing enforcements with endpoint configuration. This could occur when different policies were created in different content sets with different user permissions.
Tools Versions
- Includes Enforce Tools: 2.6.72
- Includes Enforce CX binary: 2.11.555
- Includes Recorder Tool (Installer): 3.14.28
- Includes Recorder binary: 2.11.1583
- Includes Driver Tool (Installer): 3.14.28
- Includes Driver binary: 3.3.27
- Includes Stream: 2.0.955
Tanium Cloud Release Date: 14 September 2023
Resolved Issues
- Fixed an issue where the anti-malware workbench would fail to load in air-gapped configurations.
- Upgraded various third-party libraries to newer versions.
Tools Versions
- Includes Enforce Tools: 2.6.62
- Includes Enforce CX binary: 2.11.552
- Includes Recorder Tool (Installer): 3.14.28
- Includes Recorder binary: 2.11.1583
- Includes Driver Tool (Installer): 3.14.28
- Includes Driver binary: 3.3.27
- Includes Stream: 2.0.949
Tanium Cloud Release Date: 5 September 2023
Upgrade Notes
With this upgrade, Mac Device Configuration Profile policies include macOS password settings. Separate Mac Password Profile policies and base policies are no longer needed after this upgrade. If you created Mac Password Profile policies or base policies in an earlier release, those policies are migrated to a Mac Device Configuration Profile policy type during this upgrade.
After this upgrade, review the enforcements and prioritization for all Mac Device Configuration Profile policies to ensure that the priorities and enforcements are set appropriately for your environment. For more information, see Update Mac Device Configuration Profile policy priorities and enforcements.
Improvements
- Mac Device Configuration Profile policies now apply policy settings as multiple profiles. This update will migrate all existing policies from a single configuration profile and single password profile to individual profiles separated by the payload identifier.
- Mac Password Profile policies are now part of the Mac Device Configuration Profiles policy type.
- Mac Device Management page merges "Profile Status" into one column.
- Mac Device Configuration Profile policies no longer support base policies. Please evaluate policies for targeting.
- Tanium Privacy Preferences and Control settings are automatically applied to Tanium MDM enrolled endpoints for the following:
- Tanium Client
- Tanium Client Extensions
- Tanium End User Notifications
- Mac Device Configuration Profile policies no longer rollback to previous policy when they fail to apply.
Resolved Issues
- Fixed issue where metrics may erroneously spam log files.
- Fixed issue where anti-malware results graph may have different results when drilled down.
Tools Versions
- Includes Enforce Tools: 2.5.124
- Includes Enforce CX binary: 2.11.550
- Includes Recorder Tool (Installer): 3.14.27
- Includes Recorder binary: 2.11.1583
- Includes Driver Tool (Installer): 3.14.27
- Includes Driver binary: 3.3.27
- Includes Stream: 2.0.949
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 9 August 2023
Resolved Issues
- Fixed issue with policy configuration for Internet Explorer Zones settings.
- Fixed issue with creating a Windows Firewall policy; adding a rule may result in a error message.
- Fixed issue related to providing IPv6 addresses when creating Firewall Rules.
- Fixed issue within the enforcements page with environments containing more than several thousand computer groups.
- Updated the default sort order to "rotated at last" for the endpoint encryption admin recovery portal.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 31 July 2023
Features
- Includes support for Windows ARM endpoints.
Improvements
- Improved reporting of security policy audit settings, these settings will now show status for individual audit settings rather than aggregate reporting.
- Improved sorting and filtering in the background processes view of system settings.
Resolved Issues
- Fixed issue that may result with incorrect status counts after having changed the targeting criteria of an enforcement.
- Fixed issue when setting value for Windows Policy for Internet Explorer > Internet Control Panel > Security Page Enabled > Medium Low.
- Fixed issue with status reporting for SCEP scans; the updated results were not being shown timely in the console in some cases.
- Fixed issue in delete dialog for device control settings; previously some special characters may not show up correctly in the delete confirmation.
- Fixed issue with configuration of device control devices; devices will no longer be displayed when removed from the list.
Tools Versions
- Includes Enforce Tools: 2.4.213
- Includes Enforce CX binary: 2.11.548
- Includes Recorder Tool (Installer): 3.14.19
- Includes Recorder binary: 2.11.1576
- Includes Driver Tool (Installer): 3.14.19
- Includes Driver binary: 3.3.18
- Includes Stream: 1.9.0
- Includes core-python: 3.1.43
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 24 July 2023
Resolved Issues
- Fixed issue in the enforcement details page that prevented you from selecting a single item from the list; previously the row item selects acted as a select all.
- Fixed issue with exporting of bitlocker keys with larger key sets resulting in a error generating the keys.
Tanium Cloud Release Date: 17 July 2023
Enhancements
- Enabled support for Windows AppLocker functionality on workstation operating systems. Previously AppLocker was only available for Server and Enterprise editions of Windows.
- Content sync operations now includes endpoint configuration items; previously items were only synced via endpoint configuration when they were created / edited and items that may have been deleted would not get re-created until the user edits the policy / enforcement.
Resolved Issues
- Defender platform updates will now bypass action approval. The associated content was moved to a new Content set with the permission to bypass action approvals.
- Fixed issue with Tanium Removable Storage Access Control where two parent instance paths in the same rule may result in devices to being blocked as expected.
- Fixed issue with AppLocker Policy where the publisher deny rule may not retain the file version when editing.
Security Updates
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tools Versions
- Includes Enforce Tools: 2.3.184
- Includes Enforce CX binary: 2.11.546
- Includes Recorder Tool (Installer): 3.14.19
- Includes Recorder binary: 2.11.1576
- Includes Driver Tool (Installer): 3.14.19
- Includes Driver binary: 3.3.18
- Includes Stream: 1.9.0
- Includes core-python: 3.1.43
Tanium Cloud Release Date: 03 May 2023
Resolved Issues
- Removed application of BitLocker policies via CSP to avoid conflicts with non-CSP bitlocker settings. Only partial settings are supported w/ CSP and may result in unexpected results.
Tools Versions
- Includes Enforce Tools: 2.3.162
- Includes Enforce CX binary: 2.11.536
- Includes Recorder Tool (Installer): 3.12.16
- Includes Recorder binary: 2.10.829
- Includes Driver Tool (Installer): 3.12.16
- Includes Driver binary: 3.2.63
- Includes Stream: 1.7.11
- Includes core-python: 3.1.43
Tanium Cloud Release Date: 20 Apr 2023
Enhancements
- Added support Windows User Policy settings; allows for configuration user specific policies to machines using Windows CSP.
- Added support for Distribute Over Time configuration settings Windows policy enforcements.
Resolved Issues
- Fixed issue that prevented BitLocker management to work with pre-provisioned endpoints.
Tools Versions
- Includes Enforce Tools: 2.3.143
- Includes Enforce CX binary: 2.11.533
- Includes Recorder Tool (Installer): 3.12.16
- Includes Recorder binary: 2.10.829
- Includes Driver Tool (Installer): 3.12.16
- Includes Driver binary: 3.2.63
- Includes Stream: 1.7.11
- Includes core-python: 3.1.43
Tanium Cloud Release Date: 13 Apr 2023
Resolved Issues
- Fixed issue with endpoint encryption keys pages; in some cases paging of results would not scroll.
- Fixed issue with enforce tool that may result in error when attempting to read AvSignuare when dependent file is not present.
- Fixed endpoint encryption database connection for MS SQL Server.
Tools Versions
- Includes Enforce Tools: 2.2.251
- Includes Enforce CX binary: 2.9.1137
- Includes Recorder Tool (Installer): 3.12.16
- Includes Recorder binary: 2.10.829
- Includes Driver Tool (Installer): 3.12.16
- Includes Driver binary: 3.2.63
- Includes Stream: 1.7.11
- Includes core-python: 3.1.43
Tanium Cloud Release Date: 11 Apr 2023
Resolved Issues
- Fixed CSP enforcement of Attach Surface Rule Exclusions.
- Fixed issue with CSP enforcement of "Browser AllowAutofill".
- Fixed issue with CSP enforcement of "Specify threat alert levels at which default action should not be taken when detected" and "Configure Attack Surface Reduction rules" settings.
- Fixed issue with Machine Policy setting "Display Error Notification", previously users where unable save due to invalid error message.
- Updated the version definition support for BitLocker, now includes PRODUCT_IOTENTERPRISE (Windows IoT Enterprise) and PRODUCT_IOTENTERPRISE_S (Windows IoT Enterprise LTSC).
- Fixed installation issues with various upgrade paths from older versions of Enforce to the latest version.
- Fixed issue which may result in End User Notification dialog not be presented when requested.
Tools Versions
- Includes Enforce Tools: 2.2.248
- Includes Enforce CX binary: 2.9.1134
- Includes Recorder Tool (Installer): 3.12.16
- Includes Recorder binary: 2.10.829
- Includes Driver Tool (Installer): 3.12.16
- Includes Driver binary: 3.2.63
- Includes Stream: 1.7.11
- Includes core-python: 3.1.43
Tanium Cloud Release Date: 28 Mar 2023
Resolved Issues
- Fixed issue with End User Notification when applying BitLocker policies.
- Fixed issue with setting security policy settings and their dependent values for LockoutDuration, AccountLockoutThreshold, and ResetAccountLockoutCounterAfter.
Tools Versions
- Includes Enforce Tools: 2.2.238
- Includes Enforce CX binary: 2.9.1134
- Includes Recorder Tool (Installer): 3.12.16
- Includes Recorder binary: 2.10.829
- Includes Driver Tool (Installer): 3.12.16
- Includes Driver binary: 3.2.63
- Includes Stream: 1.7.11
- Includes core-python: 3.1.43
Security Update
- This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 16 Mar 2023
Enhancements
- Add support for Oracle Linux ARM 8/9.
Resolved Issues
- Fixed issue with some CSP settings not honoring line separators for multi-line values.
- Fixed issue where leading / trailing spaces could cause policy to not report status properly.
- Fixed issue where the wrong value for "DisableWindowsConsumerFeatures" setting would be applied for CSP-enabled machines.
- Fixed issue for setting "Application Default Association Configuration" via CSP-enabled machines.
Tools Versions
- Includes Enforce CX binary: 2.9.1134
- Includes Recorder Tool (Installer): 3.12.16
- Includes Recorder binary: 2.10.829
- Includes Driver Tool (Installer): 3.12.16
- Includes Driver binary: 3.2.63
- Includes Stream: 1.7.11
- Includes core-python: 3.1.43
Tanium Cloud Release Date: 9 February 2023
Enhancements
- Adds Tanium Removable Storage Access Control; allows administrators to configure fine grained control of removable storage devices with the ability to restrict read and write operations. Includes Tanium Streams capability which allows for sending removable device events to enterprise log solutions.
Resolved Issues
- Fixed issue where ADMX policy may fail with mailbox timeout error.
- Fixed issue with device application failure on Windows 10 Portuguese.
- Fixed performance issue with MDM Device Page.
Tanium Cloud Release Date: 7 February 2023
Resolved Issues
- Fixed issue where ADMX policy updates resulted in "Scan Packed Executables" being removed from Machine Administrative Templates.
Tanium Cloud Release Date: 30 January 2023
Enhancements
- Added support for configuration service provider (CSP) to support device configuration settings in Windows client. This is a new way of setting policies that takes priority over domain policies. Settings that can be applied using CSP are annotated with a purple shield icon.
- Added support for "Security Settings" policy via CSP.
- Added CSP support for existing "Machine" ADMX policies and BitLocker policies.
- ADMX templates were updated from Windows 10 to Windows 11.
Resolved Issues
- Fixed Japanese encoding issue with "Purge Remediation" enforcement.
- Fixed French language encoding issue with BitLocker policy un-enforcement.
- Fixed issue that would not allow policies to be set with text longer than 255 characters.
- Fixed issue with Defender definition caused by proxy certificate issues.
- Fixed issue that caused console to error when changing the order of a remediation policy task.
Additional Information
- Includes [Recorder] to monitor windows policy events to perform validation of policy enforcements.
Tanium Cloud Release Date: 9 January 2023
Enhancements
- Improve policies loading behavior to prevent timeouts / errors.
- Improved MDM password policy application, it is now sent to the device in a separate policy to prevent causing users to update password.
Resolved Issues
- Fixed issue that caused AppLocker policy configuration page to fail when submitted incomplete.
- Fixed issue that caused remediation action from Threat Response to fail with a "Forbidden" error.
- Fixed issue in Endpoint Encryption where workbench would briefly display "Endpoint encryption must be enabled before data is displayed here".
- Fixed issue with filtering of Machine, User, and Security policy.
- Fixed issue with macOS Device Management Web Policy, previously only a single filter could be applied.
Tanium Cloud Release Date: 27 September 2022
Enhancements
- Enables integration with Tanium macOS Device Enrollment for MDM management of macOS Devices
- Mac Device Configuration Profiles can now be created if macOS Device Enrollment is configured
- Device Actions for Macs such as wipe and lock can now be completed if macOS Device Enrollment is configured
- Enforce now uses the RDB service for its module database and no longer uses SQLite
Resolved Issues
- Purge Remediation actions could fail on Japanese endpoints
- Policy values could not be entered over multiple lines when adding a policy
- Policies that required client-side extensions were not correctly set on the endpoint
- Changing the order of the remediation tasks in a Remediation policy would cause the workbench to crash
- When creating a policy in a different content set, an ECF config will not be created
- When updating Enforce, a plug-in creation is repeatedly called which can consume all resources on the Tanium Server
Tanium Cloud Release Date: 24 August 2022
Resolved Issues
The job that synchronizes the latest version of Windows Defender definition updates and Defender platform updates could fail.
Tanium Cloud Release Date: 9 August 2022
Improvements
Upgraded various third-party libraries to newer versions.
Tanium Cloud Release Date: 22 July 2022
Resolved Issues
- Enforce would not accept a Windows Defender process exclusion that had a wildcard at the end of the path.
- Enforce update packages could show that they completed even if the update failed.
- When new Windows Defender scans ran, the status of previous scans changed to “In progress.”
- A BitLocker policy could fail due to the error, “Invalid access to memory location.”
- BitLocker key rotation could remove a valid BitLocker key before the new key was escrowed.
Tanium Cloud Release Date: 18 July 2022
Resolved Issues
- Customers with a large number of enforcements could experience a memory leak with the Enforce service.
- When creating an enforcement, the RBAC error, “400 Bad Request – Forbidden,” appeared.
- Customers with a large number of enforcements could overwhelm the Tanium Server when updating enforcement statuses.
Tanium Cloud Release Date: 24 June 2022
Enhancements
- Enforce endpoint encryption database has been upgraded to RDB.
- Enforce now uses the System User Service.
Resolved Issues
- To reduce the performance impact on domain controllers, verification is now performed before a policy is applied to an endpoint. The policy is only applied if the verification determines that the policy application is needed to update settings.
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 6 June 2022
Enhancements
- Windows Defender Platform updates can now be applied through Enforce.
- Added the ability to remove files from quarantine in Windows Defender management.
- Additional settings for removable drives can now be configured in BitLocker.
- Enforcements and on-demand scans can now be configured to use endpoint local time.
- Machine Administrative Policy templates now use the latest Windows 10 templates.
Resolved Issues
- When trying to enable FileVault on a system that is already encrypted, we now correctly report that FileVault is already enabled.
- Disabling BitLocker for removable drives now cleans up the registry entries correctly.
- When changing targeting information for an enforcement, the Ask a Question bar now displays correctly.
- Importing firewall rules now waits to select a target.
- Viewing enforcement status now filters the list of endpoints correctly.
- Policy settings for MSPassport for Work/Windows Hello for Business now have the correct strings.
- Enforcement last modified date is now accurate.
- When viewing recovery keys for computers with long computer names, the display now shows the computer name correctly.
- Errors generated during BitLocker enforcements now provide more details.
- Linux firewall enforcements no longer report an error after successfully applying the firewall rules.
- BitLocker key rotation now occurs regardless of whether a user is logged on.
Tanium Cloud Release Date: 9 May 2022
Resolved Issues
This release resolves an issue where BitLocker enforcement failed with the message, "BitLocker policy failed to apply due to Mailbox timeout."
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
Tanium Cloud Release Date: 29 April 2022
Resolved Issues
This release resolves an issue where filters and search were not functioning when looking at recovery keys.
Tanium Cloud Release Date: 12 April 2022
Resolved Issues
This release includes:
- Resolved an issue that caused aggregate results to fail on Windows servers with WMI errors.
- BitLocker recovery keys can now be retrieved from Microsoft SQL Server 2019.
- Implemented logic to immediately roll back a BitLocker key rotation if the DEC service cannot communicate with the Tanium Module Server.
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
TaaS Release Date: 25 February 2022
Resolved Issues
This release includes:
- An Enforce process could hang and prevent Defender Managed Definitions from updating.
- If an existing Camera class was manually added prior to upgrading to Enforce 1.9.210, the Enforce service would crash and fail to start.
- Editing an Enforce Remediation Policy targeting did not change the scheduled action targeting.
- Viewing Enforcements in Interact could show incorrect data.
- An AppLocker Policy would not be applied if the hash value included 0x.
TaaS Release Date: 24 January 2022
Enhancements
This release includes:
- Provide Enforce Settings to modify Distribute Over Time and Reissue Action Interval times for Anti-virus definition distribution
- Added Camera Devices to the pre-defined device classes
Resolved Issues
This release includes:
- Fixed an issue where enforcements were not applied due to an incorrect limiting group
- Reduced the time for a Direct Endpoint connection timeout for BitLocker recovery key backup
- Added timeouts to Enforce jobs so that a job cannot hang indefinitely, causing the need to restart the service
- Fixed validation errors when creating a BitLocker policy with TPM and PIN
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
TaaS Release Date: 8 December 2021
Enhancements
This release includes:
- Redesigned workflow for Policies, Prioritization, and remediation actions
- All charts are now visible on the Enforce Overview page
- Enforcements now have a limiting group that will limit the results of a targeted enforcement
- Enforcements can now be configured with an end time. After the end time is reached, the policy is unenforced.
- When importing firewall rules from another endpoint, you can now filter down to an individual computer
- When adding a Freeze action, you can now configure user account lockout (UAL) independently
Resolved Issues
This release includes:
- Fixes an issue where enforcements to individual computers were not applied
- Fixes an issue where the firewall policies were not correctly applying to Oracle Linux endpoints
- Fixes an issue where Windows Defender Anti-malware events were not collected if the animalware.dat file was not already created
- Removed extraneous 255.255.255.255 firewall rule when building a firewall policy from another firewall policy
- Fixed validation errors when creating AppLocker policies
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
TaaS Release Date: 3 November 2021
Resolved Issues
This release includes:
- Fixed an issue that can cause all policies to stop processing if a unicode character is included in the BitLocker notification
TaaS Release Date: 8 October 2021
Resolved Issues
This release includes:
- Fixed issue where purge tools were installing to incorrect directory
- Fixed issue the caused service to continually restart due to incompatibility with DEC version
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
TaaS Release Date: 16 September 2021
Resolved Issues
This release includes:
- Changed BitLocker TPM + Pin Requirement to 4 instead of 6
- Fixed unicode issue in "Enforce - Anti-Malware Threat Counts Last X Days" sensor
- Fixed enforcement issues on Oracle Linux
- Fixed managed definition targeting sensor issue when more than 1 ADMX policy is enforced
TaaS Release Date: 8 September 2021
Resolved Issues
This release includes:
- Fixed an issue where user customization of the Quick Links and the Enforce Overview pages did not persist
TaaS Release Date: 19 August 2021
Resolved Issues
This release includes:
- Fixed an issue where list items in Administrative Template policies were not applied correctly after modification
- Modified the firewall-enabled sensor to support Ubuntu 18.04 and later, and to properly report if the firewalld service was started but not actively filtering
- Enabled several additional Machine Administrative policy settings that were getting filtered by the Enforce Service
- Google Chrome has deprecated whitelist/blacklist policies; those settings are now migrated to the new Allow/Deny policy settings
- Remediation policies that have had a deleted enforcement now correctly delete the scheduled action
TaaS Release Date: 15 July 2021
Important Notes
This release of Tanium Enforce uses Tanium Client Management and Tanium Endpoint Configuration (provided by Tanium Client Management) to deliver tools and policies centrally. For details about Tanium Client Management and Tanium Endpoint Configuration, see the Tanium Endpoint Configuration User Guide.
Enhancements
This release includes:
- Enforce policies are now delivered through Tanium Endpoint Configuration
- Enforcements can now be targeted using Interact ad-hoc questions
- Bitlocker policies now support Fixed Data Drives and allow for separate policies for Operating System Drives, USB Devices, and Fixed Data Drives
- RBAC support has been improved by allowing Policies to be created in specific content sets at the time of policy creation
- Updated Chrome ADMX policies
- Added support for FS Logix ADMX policies
- From the Enforcement details page, you can now view the results in Interact
Resolved Issues
This release includes:
- Fixed an issue where some Chrome policy settings could not be deleted
- Improved validations when creating Firewall Rules
- Windows Firewall policies can now revert back to the previous policy if there is an error while applying policy
- Removed the 255-character limit in Windows Firewall rules
- Fixed several policy settings that were setting the wrong registry key type
- Remediation Registry tasks can now handle values with a backslash (\)
- Fixed an issue where remediation enforcements failed to apply if the distribute over time was greater than 60 minutes
- Improved detection of the health of Windows Defender Services when applying policies
- Fixed an issue where Bitlocker policies would apply with the wrong encryption type if a domain controller could not be contacted
- Filtering on the endpoint encryption page now works as expected
TaaS Release Date: 5 May 2021
Resolved Issues
This release includes:
- Fixed issues where non-English languages were unable to view results for Anti-malware and AppLocker events
- Fixed an issue when a Unicode character was used in a Device Control policy
- Updated the Enforce Tools Trends Chart to correctly report tools installation
- Fixed an issue where some policy settings were setting the wrong registry value
- Reduced the memory usage of the Enforce service by filtering unneeded AppLocker events
- Fixed several issues with the Protect to Enforce migration
- Fixed an issue with path and process exclusions for Windows Defender to properly exclude Tanium End-User Notifications
- Fixed issue where Enforce tools did not properly upgrade in certain conditions
Known Issues
- In some cases, an endpoint might that report anti-malware definitions are out of date when they are current. To work around this issue, go to Settings > Anti-Malware and click Save
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
TaaS Release Date: 11 March 2021
Enhancements
This release includes:
- New Windows Remediation Actions that can wipe all non essential files, freeze an endpoint, or recover a frozen endpoint
- Improved performance of charting components and enhanced drill-down options for the overview charts and metrics
- Added TPM Status Sensor
- Added Microsoft Edge policy settings
Resolved Issues
This release includes:
- Fixed an issue with Windows Defender rules where adding Tanium exclusions overwrote existing settings
- Policies can now be enforced to Manual Computer Groups
- Fixed an issue where moving Remediation tasks too many times could crash the workbench
- Fixed issue where Enforce tools would not properly upgrade under certain conditions
Security Update
This release includes security updates. Details of the issue, including affected versions and mitigation information, can be obtained within Tanium Resource Center, or by contacting Tanium Support.
TaaS Release Date: 11 February 2021
Features
This release includes:
- Common module import was updated to allow a platform setting to override the configured computer group
TaaS Release Date: 4 February 2021
Features
This release includes:
- Improved enforcement workflow
- Surface action lock condition in enforcement status
- Show configured policy settings by default when editing a policy
- Localized Machine Template policy settings
- Improved filtering capability for Machine Template policy settings
- Target column added to enforcements table
- Inform users when target no longer exists for enforcement
- Firewall rules filter bar are now case insensitive
Bug Fixes
- Editing an existing BitLocker policy doesn't retain previous end user notifications text for Reboot Computer
- Not correctly applying "Configure Automatic Updates" GPO setting
- Unable to edit Machine Template policies
- AggregateResults saved action does not get updated with new package
- Endpoint Encryption auditing report shows wrong Accessed From source
- Enforce Action Group uses "AND" instead of "OR" to combine Computer Groups
- Save button grayed out when deleting Firewall Rule
- End-User Notification for BitLocker PIN\Password reset not working
- Enforcement saved actions don't reoccur
- Defender ODS Scans created with a reissue interval
- Enforce - Rotate Bitlocker Recovery Keys package not working
TaaS Release Date: 29 December 2020
Features
This release includes:
- Several new policy types:
- BitLocker
- FileVault
- Linux remediations
- Mac remediations
- BitLocker support for USB devices
- Ability to import & export policies (within Enforce only)
- An enforcement targeting preview
- Settings page moved to top rail
- "Health" pages for policies, anti-malware, and endpoint encryption
- New and improved policy creation workflow
- More detailed support bundles
- Ability to bypass action locks on anti-malware policies
- Alert users when Core Content solution is not yet imported
- Added API documentation
- Added anti-malware version column to anti-malware health page
Bug Fixes
- Enforcement status icons in table view now update automatically
- Dates now render correctly in FireFox
- Importing AppLocker rules from XML now works without errors
- Configuration section is now hidden when complete
- Corrected targeting for SCEP installs
TaaS Release Date: 19 November 2020
Features
- Ability to create and enforce Windows AppLocker policies
- Ability to create and enforce Windows SRP policies
TaaS Release Date: 26 October 2020
Features
- This release includes Windows Remediation
TaaS Release Date: 13 October 2020
Features
- This release includes a refreshed user experience, bringing more reporting, consistency, and configurability to the forefront.
- Ability to manage Linux Firewall rules
- Ability to manage USB Device restrictions and restrict USB Storage devices
- Added Mozilla Firefox to Machine Administrative Templates
- Create On demand Windows Defender Scans
TaaS Release Date: 31 August 2020
Features
This first release introduces several features, including:
- Ability to manage Windows Administrative policy settings including other applications like Google Chrome and Microsoft Office
- Ability to manage Windows Defender Anti-Malware settings
- Ability to manage Windows Firewall rules