Overview
This article lists the licensing, endpoint, and network requirements that must be met before you establish ScreenMeet screen sharing sessions through Tanium Direct Connect. Complete these items before provisioning agents or opening sessions.
Prerequisites
The ScreenMeet offering purchased through Tanium, with per-operator licenses allocated.
Screen sharing users provisioned in Tanium with the appropriate roles.
Endpoints running a supported operating system.
Network and host security requirements configured as described below.
Licensing
Obtain Screen Sharing per-operator licenses based on the number of Tanium Console operators you expect to establish sessions. Each operator who starts a session or opens the ScreenMeet console consumes one license for a rolling 30-day period. For the full licensing model, see ScreenMeet Screen Sharing for Tanium Direct Connect: Overview.
Operating System Support
Verify that your endpoints run a supported operating system before attempting a session. Connection behavior differs by platform, and unattended connections to macOS endpoints are not supported.
Endpoint OS Support List
More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Screen sharing OS support.
Network Requirements
Allow ScreenMeet application traffic through port 443/TCP and 443/UDP. ScreenMeet application traffic uses TLS-encrypted connections. Endpoints require access to ScreenMeet hosts and IP addresses to establish sessions.
URL | Source | Port / Protocol | Description |
|---|---|---|---|
| ScreenMeet client |
| Required for endpoints to establish screen sharing connections. |
If security software monitors or blocks unknown URLs, your security administrator must allow the ScreenMeet hosts and IP addresses. Whitelist *.screenmeet.com and *.scrn.mt for port 443 over TCP and UDP. For the full host and egress IP lists, see the ScreenMeet Firewall Configuration / Whitelisting and Egress IP Addresses references.
Bypass Proxy Servers
Allow traffic to *.screenmeet.com to bypass any proxy servers in your network. Screen sharing traffic that passes through a proxy negatively impacts session performance.
TLS Inspection
If your network decrypts TLS traffic, add an exception for traffic to and from *.screenmeet.com. The ScreenMeet client uses certificate pinning, so TLS inspection can cause a false "not secure" warning at connection time, and the unattended (Beam) capability will not connect when TLS inspection is active.
Host and Network Security
Configure host and network security requirements before your first session. More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Host and network security requirements.
Endpoint Tooling
Endpoints with a Tanium Client require the Screen Sharing tools, installed through Tanium Endpoint Configuration. After you add the ScreenMeet offering or add new endpoints, installation of Screen Sharing tools can take several minutes. Sessions to an endpoint that does not yet have the tools installed will fail. Wait several minutes and try again. To connect to an endpoint that has no Tanium Client, see Connecting to Endpoints Without a Tanium Client.
Verification
Confirm per-operator licenses are allocated and within your total seat count.
Confirm
443/TCPand443/UDPto*.screenmeet.comand*.scrn.mtare open and bypass proxies.Open a test session to a supported, tools-installed endpoint and confirm the ScreenMeet interface loads in Tanium.