LICENSEWARE

Tanium endpoint counting and License Usage Terms

This article covers how Tanium counts Endpoints, OT Satellites and devices for licence purposes. For bundles see Tanium solutions and bundles; for AI usage see Tanium Atlas AI credits.

On This Page

The Tanium License Usage Terms set how Tanium licences are measured, tracked and reported. They are incorporated into any quote, schedule, order form or licence agreement that references them. They apply to all Tanium products and services, both on-premises and Tanium Cloud deployments, and the customer’s agreement governs if the two directly conflict.[1] The version retrieved for this article is dated 2026-09-21. It also contains the AI Credit rules for Tanium Atlas, which are covered in Tanium Atlas AI credits.[1]

Editions

The counting rules do not change between bundles. Every Endpoint-based offering, from Tanium Core Standard to Security Operations, uses the same Endpoint definition. Only the Endpoint Expansion offerings use different units: Device for mobile and OT Satellite for operational technology.[1][5] Bundle content is described in Tanium solutions and bundles.

Metrics

Endpoint (Managed OS Instance)

An Endpoint, also called a Managed OS Instance, is a physical or virtual hardware device where Tanium software can be installed and which can process data. The definition lists examples deliberately: mobile and smart phones, diskless, personal and networked workstations, homeworker and home-based systems, file, print and email servers, internet gateway devices, storage area network servers, terminal servers, and portable workstations connected to a server or network.[1] The test is that Tanium software can be installed, not that it is installed. In practice, though, the Console counts only devices whose Tanium Client has registered (see below).[2]

OT Satellite

An OT Satellite is an Endpoint the customer chooses to monitor OT Devices in the same network segment, such as a subnet or VLAN. An OT Device is a device in an industrial environment that monitors or controls physical processes or machinery, such as a programmable logic controller (PLC) or human-machine interface (HMI).[1] Tanium Core for Operational Technology and Tanium Exposure Management for Operational Technology are licensed per OT Satellite. Each satellite may monitor no more than 250 OT Devices.[5]

Device

Tanium Endpoint Management for Mobile covers iOS, iPadOS, ChromeOS and Android devices and is “Licensed by Device”.[5] Tanium publishes no separate definition of a Device. Catalog: Device; Endpoint Management for Mobile is licensed by Device.

Counting / floors

Standard and Ephemeral Endpoints

The Terms classify Endpoints by Total Uptime: the time between first registration with the Tanium Console and the most recent “Last Seen” time the Console reports. An Ephemeral Endpoint has Total Uptime of 24 hours or less. A Standard Endpoint exceeds 24 hours at any time in the Subscription Term.[1] Once an Endpoint passes 24 hours it is Standard for the rest of the term, because the test is “at any time during the Subscription Term”.[1] Catalog: Endpoints are classified as Standard or Ephemeral by Total Uptime.

The 30-day persistence rule

A Standard Endpoint keeps counting towards the licence total for 30 days after the last registration seen in the Tanium Console. This applies even if the Endpoint was re-imaged or wiped.[1] The Terms state this rule only for Standard Endpoints. They do not say how long an Ephemeral Endpoint counts. Customers with large short-lived populations should get that confirmed in the Schedule. Catalog: Standard Endpoints keep counting for 30 days after last registration.

The Console works on the same window. Tanium Cloud and the on-premises Tanium Server treat an endpoint as managed if its Tanium Client has registered in the past 30 days.[2][3] To see the tally used for the licence, an administrator opens Administration > Configuration > Client Status, sets the filter to systems that reported in the last 30 days, and keeps “Hide Duplicate Host Names” selected.[2] The documentation says the Environment Status total on the Tanium Home page is the most accurate count for purposes other than licence usage, so the two figures can differ.[2] Catalog: The Console counts an endpoint as managed if its Client registered in the past 30 days.

What does not count

  • Entity-provider devices. Endpoints managed through an entity provider, such as those ingested by the Tanium Connector for Microsoft Intune, have no Tanium Client and do not count towards licensed endpoint totals. The entity provider may need its own licence.[2] Catalog: Endpoints ingested through an entity provider do not count.
  • OT Devices. OT devices ingested by Tanium Endpoint Management for Operational Technology do not count against endpoint licensing totals. The Tanium Client runs on the satellite, not on the OT devices.[6] Catalog: OT devices do not count against endpoint totals.

What always counts

  • Disaster recovery. Endpoints in disaster recovery environments count, even if they are brought online only for testing. Tanium asks customers who need extra licensing for a cold failover environment to contact the account team.[1] Catalog: Disaster recovery endpoints count even when used only for testing.
  • Re-imaged devices. Re-imaging does not take a Standard Endpoint out of the count.[1] The Tanium Client guide’s sizing formula adds physical endpoints that are “added or reimaged” over a 30-day period on top of the existing estate. In practice, a hardware refresh or a rebuild campaign temporarily raises the licence requirement.[4]

Over-deployment

The on-premises licence file sets a Maximum Managed Endpoints figure. Solutions that are not licensed show zero on the Tanium License page.[3] If the managed count exceeds the maximum, Tanium Console shows a warning with the current count. Above 10 percent over, it also tells the administrator to contact Tanium Support, and the remedy is a new licence that covers more endpoints.[3] Tanium Cloud manages the licence automatically, and raising the maximum number of managed endpoints goes through Tanium Support.[2] Neither page says management stops at the limit. Under the agreements, excess use is settled through the audit and remediation clause.[7] Catalog: Exceeding Maximum Managed Endpoints triggers a Console warning.

Virtualization & partitioning

Hypervisors. For a virtual system, the hypervisor is a single Endpoint if the Service is installed at hypervisor level.[1] Guest operating systems that run their own Tanium Client are Endpoints in their own right, because the definition covers virtual devices.[1] Catalog: A hypervisor counts as one Endpoint when the Service is installed at hypervisor level.

VDI. VDI Endpoints count towards the total and are classed as Ephemeral or Standard under the general definitions.[1] The Tanium Client deployment guide is more specific. Tanium Cloud allocates a licence for each unique Tanium Client for 30 days after that Client last registers. Each VDI instance that is created or re-imaged counts as a licensed endpoint for at least 30 days, and each deleted instance keeps consuming a licence for 30 days after it last registers.[4] The guide’s sizing formula is:[4]

Component Estimated count 
Physical endpoints and persistent VDI instances A 
VDI instances created or re-imaged over a 30-day period B 
Physical endpoints added or re-imaged over a 30-day period C 
Total required licences A + B + C 

Read literally, a pool of 500 non-persistent desktops rebuilt every night needs licences for every instance created or re-imaged in a rolling 30-day window, not for 500 seats. That makes VDI rebuild frequency the main driver of Tanium licence demand. The guide also suggests tagging VDI endpoints into their own computer groups, which makes this population easier to report on separately.[4] Catalog: VDI endpoints count and are classified as Standard or Ephemeral; Tanium licence formula for VDI environments.

Terminal servers. Terminal servers are listed as Managed OS Instances.[1] The definition counts devices, not users, so on this reading the sessions hosted on a terminal server are not separate Endpoints. Tanium does not state this explicitly.

Cloud / BYOL

The same Terms apply to Tanium Cloud and on-premises deployments.[1] Tanium Cloud includes one service instance by default. More can be bought, but Tanium recommends a single instance to simplify usage and reporting.[1] Catalog: Tanium Cloud includes one service instance by default.

Programs

There is no separate counting program. Evaluation Software runs for the Evaluation Period stated in the welcome email or licence key notice, or 30 days if none is stated, and is limited to internal lab, demonstration, evaluation, training and testing use.[7]

Out of scope

  • Ephemeral Endpoint counting beyond the definition. The Terms define the class but publish no separate counting window.
  • Licensing of third-party entity providers such as Microsoft Intune.
  • Contract-specific counting terms in signed Schedules.

References

  1. Tanium License Usage TermsLast Updated: September 21, 2026. Catalog: Tanium License Usage TermsEffective 2026-09-21. Retrieved 2026-10-01.
  2. Managing the Tanium license (Tanium Cloud)Updated 2026-09-24. Catalog: Managing the Tanium license (Tanium Cloud)Effective 2026-09-24. Retrieved 2026-10-01.
  3. Managing the Tanium license (on-premises)Updated 2026-09-23. Catalog: Managing the Tanium license (on-premises)Effective 2026-09-23. Retrieved 2026-10-01.
  4. Deploying the Tanium Client (Tanium Cloud)Licensing in VDI environments. Updated 2026-10-01. Catalog: Deploying the Tanium Client (Tanium Cloud)Effective 2026-10-01. Retrieved 2026-10-01.
  5. Tanium Solutions & Bundles for Cloud (as of November 2025)Catalog: Tanium Solutions & Bundles for Cloud (as of November 2025)Retrieved 2026-10-01.
  6. Tanium Endpoint Management for Operational Technology requirementsUpdated 2026-07-23. Catalog: Tanium Endpoint Management for Operational Technology requirementsEffective 2026-07-23. Retrieved 2026-10-01.
  7. Tanium End User License AgreementLast Updated: August 2026. Catalog: Tanium End User License AgreementRetrieved 2026-10-01.

See also

Catalog Rows Cited

3Metrics12Rules

Esc