Documentation Index

Fetch the complete documentation index at: https://docs.screenmeet.com/llms.txt

Use this file to discover all available pages before exploring further.

Screen Sharing User Role Permissions

Prev Next
This content is currently unavailable in French. You are viewing the default (English) version.

Screen Sharing User Role Permissions

Overview

This article describes the roles and permissions that control ScreenMeet screen sharing through Tanium Direct Connect, including how each Tanium role maps to a ScreenMeet role and which permissions govern unattended sessions. Assign these roles in Tanium; ScreenMeet applies the matching role automatically.


Roles

Tanium Role

ScreenMeet Role

Grants

Screen Sharing Administrator

ScreenMeet Admin

Change settings, features, and policies; access data; join active sessions created by other users; open the ScreenMeet console to configure organization settings using a magic link.

Screen Sharing Agent

ScreenMeet Agent

Start sessions and use standard ScreenMeet features. Includes the Screen Sharing Console permission for console access without the ability to modify organization settings.


Permissions for Unattended Sessions

Two permissions control unattended sessions. Neither is assigned to any default role, and both must be added to a custom role.

Permission

Effect

Screen Sharing Support Session Unattended Execute

Establish unattended sessions with Windows endpoints that do not require endpoint user permission. After the session ends, the endpoint locks by default.

Screen Sharing Support Session Disable Autolock Execute

Leave the endpoint unlocked after an unattended session ends. Requires the Screen Sharing Support Session Unattended Execute permission.

Unattended Access Is Restricted by Design

The default Integration Admin - ScreenMeet, Screen Sharing Agent, and Integration Viewer - ScreenMeet roles do not permit unattended sessions. To grant unattended access, build a custom role and persona. See Unattended Screen Sharing Sessions and Personas.


Additional Permissions

  • Screen Sharing Product Options Read: When Let the Agent Decide is set for Session Recording in the ScreenMeet console, this permission lets the operator choose whether to record a session.

  • Screen Sharing Console or Screen Sharing Console Admin: Required to open a session with an endpoint that has no Tanium Client.

  • Integration Admin - ScreenMeet: Required to view all sessions, join sessions started by other operators, and view the Audit Log.


Best Practice

Use Least Privilege

Assign screen sharing users only the roles and permissions they need. Restrict unattended-session permissions to a custom persona scoped to specific computer groups and users.


Where Roles Are Configured

Role Setup in Tanium

Roles, permissions, and personas are created in Tanium Console under Administration > Permissions. More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Screen Sharing user role permissions.