Impact requirements

Review the requirements before you install and use Impact.

Tanium dependencies

Component Requirement
Tanium™ Core Platform 7.4 or later
Tanium™ Client Any supported version of Tanium Client. For the Tanium Client versions supported for each OS, see Tanium Client Management User Guide: Client version and host system requirements.

If you use a client version that is not listed, certain product features might not be available, or stability issues can occur that can only be resolved by upgrading to one of the listed client versions.

Tanium solutions If you selected Tanium Recommended Installation when you installed Impact, the Tanium Server automatically installed all your licensed solutions at the same time. Otherwise, you must manually install the solutions that Impact requires to function, as described under Tanium Console User Guide: Import, re-import, or update specific solutions.

Tanium solutions at the following minimum versions are required:

  • Tanium™ Interact 2.2.3 or later
  • Tanium™ Endpoint Configuration 1.2 or later (installed as part of Tanium™ Client Management 1.5 or later)

The following Tanium solutions are optional, but Impact requires the specified minimum versions to work with them:

  • Tanium Connect 5.8.54 or later
  • Tanium Threat Response 2.5.1 or later
  • Tanium Trends 3.6.323 or later

Tanium™ Module Server

Impact is installed and runs as a service on the Module Server host computer. The impact on the Module Server is minimal and depends on usage.

For information about Module Server sizing in a Windows deployment, see Tanium Core Platform Deployment Guide for Windows: Host system sizing guidelines.

Endpoints

Supported operating systems

The following endpoint operating systems are supported with Impact.

Operating system OS version Notes
Microsoft Windows Server Microsoft Windows Server 2008 R2 (SP1) and later  
Microsoft Windows Workstation Microsoft Windows 7 (SP1) and later Windows 7 Service Pack 1 requires Microsoft KB2758857.

Third-party software

Impact is supported for use with:

  • Active Directory Domain Services that are running on any version of Microsoft Windows Server that is currently supported by Microsoft.
  • Azure Active Directory Domain Services

For supported versions, see Microsoft: Search Product and Services Lifecycle Information.

Impact uses Security Identifiers (SIDs) and the Tanium Architecture for Active Directory queries. Because of this structure, the number of queries to the domain controller are low and the overall network traffic generated by Impact is minimal. For more information about this process, see Collect and analyze dataCollect and analyze data.

Active Directory user account

The service account that you specify for Impact is not used for Active Directory queries.

Impact uses the user account that you specify when you configure the connection to domains for Active Directory queries. This user should have limited access. You can specify any user, but if you modified the standard user permissions from the default settings, the user must meet the following minimum requirements so that Impact has access to read attribute data from Active Directory:

  • Member of the Domain Users group
  • Permission to read the objectSID attribute from the domain object in the configured domains
  • Permission to read the objectSID attribute on all users, groups, and computers in the configured domains
  • Permission to Read members on all groups in the configured domains
  • (Optional, best practice) Assign List Contents and Read all properties access on all objects in the configured domains, including the domain object.

Host and network security requirements

Specific ports and processes are needed to run Impact.

Ports

The following ports are required for Impact communication.

Source Destination Port Protocol Purpose
Module Server Tanium as a Service Active Directory Server 389 / 636 LDAP / LDAPS Connecting to the Active Directory server.
Module Server Tanium as a Service Active Directory Global Catalog Server 3268 / 3269 LDAP / LDAPS Required only when connecting to the Active Directory Global Catalog server.

For more information, see Configure connections to domainsConfigure connections to domains.

Configure firewall policies to open ports for Tanium traffic with TCP-based rules instead of application identity-based rules. For example, on a Palo Alto Networks firewall, configure the rules with service objects or service groups instead of application objects or application groups.

For Tanium as a Service ports, see Tanium as a Service Deployment Guide: Host and network security requirements.

Security exclusions

If security software is in use in the environment to monitor and block unknown host system processes, your security administrator must create exclusions to allow the Tanium processes to run without interference. For a list of all security exclusions to define across Tanium, see Tanium Core Platform Deployment Reference Guide: Host system security exclusions.

Impact security exclusions
Target Device Notes Exclusion Type Exclusion
Module Server   Process <Module Server>\services\impact-service\TaniumImpactService.exe
  Process <Module Server>\services\endpoint-configuration-service\TaniumEndpointConfigService.exe
Windows endpoints   Process <Tanium Client>\Python38\TPython.exe
  Folder <Tanium Client>\Python38
Impact security exclusions
Target Device Notes Exclusion Type Exclusion
Windows endpoints   Process <Tanium Client>\Python38\TPython.exe
  Folder <Tanium Client>\Python38

User role requirements

The following tables list the role permissions required to use Impact. To review a summary of the predefined roles, see Set up Impact users.

For more information about role permissions and associated content sets, see Tanium Console User Guide: Managing RBAC.

Impact user role permissions
Permission Impact Administrator3 Impact Operator32 Impact Service Account1,2,3,4 Impact User32 Impact Endpoint Configuration Approver21

Impact

View the Impact workbench


SHOW

SHOW

SHOW1

Impact Asset Details

View the details for an asset


READ

READ

READ

Impact Asset Impact

View the impact rating for assets


READ

READ

READ

Impact Asset Items

View the items for an asset


READ

READ

READ

Impact Domains

View, create and edit Impact domains


READ
WRITE

READ
WRITE

Impact Endpoint Configuration

Allows users to approve Endpoint Configuration items for Impact


APPROVE

Impact Service

Allows users to configure the Impact service


CONFIGURE

Impact Service Account

View and update the Impact service account; perform Impact service account tasks


READ
WRITE

READ
WRITE
EXECUTE

Impact Shortest Path

View the shortest path graphs


READ

READ

READ

Impact Support Bundle

View the Impact support bundle


READ

Impact Sync

Start the Impact synchronization


START

START

Impact Sync Status

View the Impact synchronization status


READ

READ

READ

1 This role provides Tanium Data Service permissions (through Interact). You can view which Interact permissions are granted to this role in the Tanium Console. For more information, see Tanium Interact User Guide: Tanium Data Service permissions.

21 This role provides module permissions for Tanium Endpoint Configuration. You can view which Endpoint Configuration permissions are granted to this role in the Tanium Console. For more information, see the Tanium Endpoint Configuration User Guide: User role requirements.

32 This role provides module permissions for Tanium Trends. You can view which Trends permissions are granted to this role in the Tanium Console. For more information, see Tanium Trends User Guide: User role requirements.

4 If you installed Tanium Client Management, Endpoint Configuration is installed, and by default, configuration changes initiated by the module service account (such as tool deployment) require approval. You can bypass approval for module-generated configuration changes by applying the Endpoint Configuration Bypass Approval permission to this role and adding the relevant content sets. For more information, see Tanium Endpoint Configuration User Guide: User role requirements.


Provided Impact administration and platform content permissions
Permission Permission Type Impact Administrator1 Impact Operator1 Impact Service Account1 Impact User1 Impact Endpoint Configuration Approver
Action Group Administration
READ
WRITE
User Administration
READ

READ
Action Platform content
READ
WRITE
Own Action Platform content
READ
Package Platform content
READ
Plugin Platform content
READ
EXECUTE

READ
EXECUTE

READ
EXECUTE

READ
EXECUTE
Sensor Platform content
READ

You can view which content sets are granted to any role in the Tanium Console.

1 This role provides content set permissions for Tanium Trends. You can view which Trends content sets are granted to this role in the Tanium Console. For more information, see Tanium Trends User Guide: User role requirements.