Screen Sharing User Role Permissions
Overview
This article describes the roles and permissions that control ScreenMeet screen sharing through Tanium Direct Connect, including how each Tanium role maps to a ScreenMeet role and which permissions govern unattended sessions. Assign these roles in Tanium; ScreenMeet applies the matching role automatically.
Roles
Tanium Role | ScreenMeet Role | Grants |
|---|---|---|
|
| Change settings, features, and policies; access data; join active sessions created by other users; open the ScreenMeet console to configure organization settings using a magic link. |
|
| Start sessions and use standard ScreenMeet features. Includes the |
Permissions for Unattended Sessions
Two permissions control unattended sessions. Neither is assigned to any default role, and both must be added to a custom role.
Permission | Effect |
|---|---|
| Establish unattended sessions with Windows endpoints that do not require endpoint user permission. After the session ends, the endpoint locks by default. |
| Leave the endpoint unlocked after an unattended session ends. Requires the |
Unattended Access Is Restricted by Design
The default Integration Admin - ScreenMeet, Screen Sharing Agent, and Integration Viewer - ScreenMeet roles do not permit unattended sessions. To grant unattended access, build a custom role and persona. See Unattended Screen Sharing Sessions and Personas.
Additional Permissions
Screen Sharing Product Options Read: WhenLet the Agent Decideis set for Session Recording in the ScreenMeet console, this permission lets the operator choose whether to record a session.Screen Sharing ConsoleorScreen Sharing Console Admin: Required to open a session with an endpoint that has no Tanium Client.Integration Admin - ScreenMeet: Required to view all sessions, join sessions started by other operators, and view the Audit Log.
Best Practice
Use Least Privilege
Assign screen sharing users only the roles and permissions they need. Restrict unattended-session permissions to a custom persona scoped to specific computer groups and users.
Where Roles Are Configured
Role Setup in Tanium
Roles, permissions, and personas are created in Tanium Console under Administration > Permissions. More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Screen Sharing user role permissions.