ScreenMeet for Tanium: Frequently Asked Questions
Overview
This article answers the most common questions from customers who use ScreenMeet Remote Support through the Tanium Direct Connect integration. Topics are ordered by how frequently these topics come up in support discussions (either with customers/prospects/internal Tanium + ScreenMeet discourse), with connectivity coming first as the most frequently recurring topic.
Start Here: The Three Most Common Fixes
Most connection problems are resolved by confirming three things: (1) *.screenmeet.com and *.scrn.mt are allowed on port 443 over both TCP and UDP; (2) TLS/SSL inspection has an exception for *.screenmeet.com; and (3) this traffic bypasses proxy servers. Whitelist by domain, not IP, since some ScreenMeet IPs are dynamic.
Connectivity and Performance
The large majority of connection delays are network-related, not application faults. Use this table to match a symptom to its most likely cause and resolution, then see the reference questions below. Rows are ordered by how often each symptom is reported.
Symptom | Most likely cause | Resolution |
|---|---|---|
Slow to connect or times out | Incomplete whitelist or proxy interference | Allow |
Poor quality, low bit rate, or session switches to Tiles | Blocked or unstable | Allow |
Blocks in firewall logs despite whitelisting | TLS/SSL inspection breaks certificate pinning; URL filtering (Zscaler, Netskope, Prisma, GlobalProtect) | Add an inspection exception for |
Error code | Network or policy block (proxy, blocked certificate-revocation URLs, endpoint security tool) | Re-verify whitelisting, proxy bypass, and TLS inspection exceptions. |
Slow connect and sessions drop when Windows users switch | Proxy defined at user level only; the client runs as | Configure the WinINET proxy at the system level. See Network and Proxy Configuration below. |
Works with "Ask the endpoint user for permission" checked, fails unchecked | TLS inspection or incomplete whitelist on the unattended path | Apply the same domain, port, and TLS exceptions to the unattended flow. |
Strict or isolated network stalls at certificate validation | Windows CRL/OCSP lookups over port | Allow outbound |
How long should a connection take?
Under normal conditions, a session connects in 50 to 70 seconds.
Because of the multi-step routing and communication architecture required between enterprise management platforms, ~50 seconds is the optimal working baseline. This is the expected, healthy state of the integration and cannot meaningfully be reduced below ~50 seconds baseline. If the time to connect value is substantially above ~50 seconds, environment specific tooling such as VPNs, firewalls, TLS/SSL inspection, etc can be looked into to reduce any added latency.
How do we gather deeper logs for a slow or failed session?
Provide the ScreenMeet Session ID or PIN with each report, since it is required to isolate a session. Enable local debug logging on the endpoint by launching with loglevel="debug" (or setting externalloglevel:Debug), then reproduce the issue. You can also run the WebRTC connectivity test at integration.screenmeet.com/webrtctest from an affected and an unaffected endpoint to compare. See Retrieving Logs.
Network and Proxy Configuration
What exactly needs to be allowed?
Allow *.screenmeet.com and *.scrn.mt to 443 over TCP and UDP, and allow this traffic to bypass proxy servers where possible. This is sufficient for most environments. For proxy, VPN, and enterprise specifics, see the Enterprise Deployment Guide.
What is *.scrn.mt for?
The *.scrn.mt domain is used only for short hostnames. Whitelist it alongside *.screenmeet.com if your environment restricts by domain.
Can we whitelist by IP instead of FQDN, and what are the egress IPs?
FQDN allowlisting is strongly preferred because several ScreenMeet IP addresses are dynamic and change over time. The published Egress IP Addresses primarily cover REST API calls to Salesforce CRM and are not needed if you do not use that integration. If you must restrict by IP, expect to maintain the list. Sessions route to the most performant region, so a deployment confined to one geography generally uses that region's addresses.
Timeouts
Can we extend how long a session waits before timing out?
Yes, for the session-level timeout. The New Session Timeout setting defines how long a created session waits for the first participant to join before it expires. Configure it in the ScreenMeet console under Settings and Policies > Remote Support Settings. It defaults to one hour and can be extended up to 48 hours.
The Tanium console times out after about three minutes before the endpoint finishes connecting.
That timeout is enforced by the Tanium front end, which handles command execution to the endpoint, and it is not a ScreenMeet setting. When the operator view times out but the endpoint client eventually starts, you do not need to restart: go to Shared Services > Direct Connect > Screen Sharing Sessions, select the session, and click Join. The underlying cause of the long connect time should still be addressed through whitelisting and proxy configuration.
Front-End Timeout Is Managed in Tanium
The operator-side connection-wait timeout is controlled by Tanium and cannot be changed in the ScreenMeet console. More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Working with screen sharing.
Sessions hang in a "connecting" state and do not time out on their own.
A created session where an agent never joins is subject to a hard-coded 30-minute timeout that protects against orphaned sessions. The configurable idle timeout applies only after an agent has successfully joined. If sessions that failed to connect remain in a connecting state, they clear at the 30-minute mark; an operator can also end them manually from the Screen Sharing Sessions list.
Agent Identity and Branding
The end user sees "agent," or only the first character of the technician's name, in the permission prompt.
Two settings govern this. First, the displayed name depends on the Agent Obfuscation setting in the console under Organization > Settings and Policies > Remote Support Features; set it to Show Full Name to display the technician's full name instead of "agent" or an abbreviated form. Second, Tanium must pass the agent's display name rather than a numeric user ID; if the Tanium display-name field contains a number, the prompt shows that value, so populate it with the user's actual name.
Can we brand the console and customize the consent message?
The consent screen the end user accepts can be tailored using the Custom Consent Message option; the default reads that the agent has requested permission to view the user's screen.
Unattended Access
Can we connect to signed-out or login-screen Windows endpoints?
Yes. The Tanium integration already includes the core unattended capability, so an operator can connect to a Windows endpoint at the login screen with no user signed in, provided the operator has the unattended permissions. After you enter operating system login information on a machine with no logged-in user, the session may briefly show a disconnection message; wait several seconds for login to complete and the connection to reestablish.
What is the difference between Remote Support and Beam?
Beam is ScreenMeet's separate unattended-access product for organizations that do not use Tanium, and it is not compatible with the Tanium integration. Because the Tanium integration already includes the equivalent core unattended functionality, Tanium customers do not need Beam or a Beam group configuration to reach signed-out endpoints.
Data, Recording, and Integrations
How much cloud storage do we have, and how long are recordings kept?
ScreenMeet Cloud storage is included with the subscription, and stored session files are automatically pruned after 90 days. Recordings and screenshots are associated with individual sessions and accessed through session history. For extended or region-specific retention, files can instead be routed to your own AWS S3 or Azure Blob storage.
Why do user counts differ between the console and data exports?
Data exports include only active users, while the console UI shows all users, including inactive and deleted records kept for audit history. Provisioning is just-in-time: an account is created when a user first starts a session or signs in through the magic link. A user is marked inactive after 30 days without a session and deleted after 90 days of inactivity; deletion is automatic and cannot be done manually.
Can we use the ScreenMeet ServiceNow integration?
The ScreenMeet ServiceNow integration is available as a separate product and generally requires its own organization rather than being enabled inside the Tanium integration. Engage your ScreenMeet or Tanium account team to scope and license it. Tanium Direct Connect separately offers the option to send screen sharing audit logs to ServiceNow, which is configured in Tanium.
Where can we get security certifications such as SOC 2 and ISO 27001?
Security certification materials are shared under NDA. If the request is on behalf of an end customer, ScreenMeet establishes the NDA directly with that customer before sharing the certificates. Contact ScreenMeet support to begin the process.
Roles and Permissions
Agents can see admin or supervisor options in the ScreenMeet console. How do we restrict them?
This occurs when an agent has the Integration Admin - ScreenMeet role, which grants administrative access in the ScreenMeet console. Remove that role from the user. To run sessions, an agent needs only the Screen Sharing Agent role, which limits console access to Support Sessions and My Session History. The Screen Sharing Administrator role in Tanium maps to admin access in ScreenMeet, including Global Session History and Organization settings.
Roles Are Assigned in Tanium
Screen sharing roles are assigned in Tanium Console and mapped to ScreenMeet automatically. More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Screen Sharing user role permissions.
Licensing
Can ScreenMeet add licenses, expand our count, or add a temporary buffer?
No. Screen sharing licensing is enforced entirely on the Tanium side. ScreenMeet cannot manage, adjust, expand, or add a buffer to your license count, and ScreenMeet support cannot override an exhausted allocation.
Any change to your license count must be made through Tanium.
Licensing Is Controlled by Tanium
Only Tanium can adjust screen sharing licensing. Direct license count and seat questions to your Tanium account team. More information is surfaced in the Tanium documentation at Tanium Direct Connect User Guide: Working with screen sharing.
How are per-operator licenses allocated?
Obtain Screen Sharing per-operator licenses based on the number of Tanium Console operators you expect to establish screen sharing sessions. The allocation model is:
A per-operator license is allocated to each Tanium Console operator establishing a screen sharing session or accessing the ScreenMeet console from Tanium Console. Each Tanium Console operator can create unlimited concurrent screen sharing sessions.
The license allocation lasts for 30 days and counts as an active operator license. The 30-day allocation restarts each time that a Tanium Console operator establishes a screen sharing session or opens the ScreenMeet console.
If the active operator license count exceeds your total per-seat license count, additional Tanium Console operators cannot establish a screen sharing session.
Can we remove or delete a user to free up a license?
No. Once an operator is active, they are counted as active for the full 30-day period. ScreenMeet cannot delete the user to free up the license, and users cannot be dynamically removed to reclaim a seat. The allocation is released only when the 30-day period elapses without that operator establishing a session or opening the ScreenMeet console. Because opening the console also allocates a license, avoid opening it with accounts that do not need to run sessions.
Platform Notes
The Privacy Curtain option is missing on some devices.
Privacy Curtain relies on functionality not present in older Windows builds, so it does not appear on those versions, for example Windows 10 Enterprise 2016 LTSB (build 14393). It is available on current, supported Windows versions. If the feature is missing, confirm the endpoint's Windows version against the supported list.
What does an end user need to allow on a Mac the first time?
On the first connection to a macOS endpoint, the user must grant ScreenMeetSupport the Screen Recording and Accessibility permissions in System Settings, then click Later when prompted. For attended macOS sessions, a view-only session is established first; the operator then requests control, and the user must accept before control is granted.