No more typing reviews! Try our Samantha, our new voice AI agent.

BigFix vs Tanium comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Intune
Sponsored
Ranking in Unified Endpoint Management (UEM)
1st
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
377
Ranking in other categories
Configuration Management (1st), Remote Access (2nd), Enterprise Mobility Management (EMM) (1st), Microsoft Security Suite (1st)
BigFix
Ranking in Unified Endpoint Management (UEM)
10th
Average Rating
8.6
Reviews Sentiment
6.4
Number of Reviews
100
Ranking in other categories
Configuration Management (10th), Endpoint Protection Platform (EPP) (24th), Patch Management (7th), Autonomous Endpoint Management (5th)
Tanium
Ranking in Unified Endpoint Management (UEM)
8th
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
23
Ranking in other categories
Vulnerability Management (24th), Endpoint Protection Platform (EPP) (14th), Endpoint Detection and Response (EDR) (23rd), Autonomous Endpoint Management (3rd)
 

Featured Reviews

OluwashileAdeniyi - PeerSpot reviewer
Senior Infrastructure Security Engineer at a outsourcing company with 51-200 employees
Centralized endpoint security has improved and supports hybrid work and BYOD policies
Regarding what I dislike about Microsoft Intune and its downsides, I would say that more Mac controls are needed because we have limited Mac and Linux control. When comparing controls and policies between Windows, Mac, and Linux, Windows has almost everything you can think of, while Mac and Linux have limited types of control. You cannot implement certain things on Mac and Linux that you can on Windows. The limited controls are a major issue. Additionally, if Microsoft could find a way to embed servers into Microsoft Intune, that would be beneficial. Microsoft Intune is not really designed for servers or Windows servers. It is more tailored towards Windows 11 and Windows 10 operating systems. Windows servers are not fully supported. Enterprise organizations usually have both servers and endpoints, which are users' workstations. For servers, most people look for other solutions such as SCCM, which is Configuration Manager. However, SCCM is what Microsoft Intune is trying to replace. Both SCCM and Microsoft Intune belong to Microsoft. Microsoft is trying to transition organizations into Microsoft Intune, the native cloud solution. However, because this update is still in process, servers are not fully compatible with Microsoft Intune and cannot be managed by it. The current policy that has emerged from issues with clients is what they call co-management, which is relatively new, and I do not know if adoption is significant. Many legacy or older customers who have been using these products for decades still have SCCM. When it is time for them to manage their Windows devices, they use what is called cloud attach. Cloud attach is a term whereby your SCCM is connected to your Microsoft Intune. Most people do not know about it, but I have deployed it for several organizations. Cloud attach and co-management work together so that your device is in SCCM, but some policies are pushed from Microsoft Intune. It is like two different solutions working hand in hand. That is what they call co-management. Microsoft Intune does not bring all of your endpoint and security management tools into one place, which is the goal and how it should be. However, as I mentioned, servers are not included. If we talk about end users, Microsoft Intune does bring all your devices together. In a typical enterprise environment, you have end users with workstations, laptops, company-issued phones, and bring your own devices. You can create policies for all of these. However, for the backend, your servers do not have much coverage. Servers are not really covered by Microsoft Intune in that way.
InderjeetSingh4 - PeerSpot reviewer
Administrator at a tech vendor with 10,001+ employees
End-to-end automation has simplified patching and software deployment across thousands of servers
There is one feature in BigFix called the automation patch policy that requires enhancement. When an action is initiated through the patch policy, it appears on the console but arrives in chunks. When targeting hundreds of servers from the patch policy, the actions come in chunks such as ten out of six, ten out of nine, or ten out of fifteen. This fragmented approach creates a significant challenge for the patching team to monitor the action status. I would recommend that the development team provide a single action or one to two actions instead of multiple actions requiring individual monitoring. A broad status update could be provided to the client indicating the overall progress of the patch policy implementation rather than requiring monitoring of every individual action. This would reduce the bandwidth required by the team to track multiple actions on the console.
Sandeepraj Gatla - PeerSpot reviewer
Dfir Analyst at a tech services company with 201-500 employees
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use. We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5. Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a stable solution."
"The solution is fully integrated with the Microsoft platform and the Autopilot feature, which is a unique feature."
"Microsoft Intune has been a time saver and reduces the time and effort IT admins have to invest."
"I mainly use Microsoft Intune analytics for taking that data that exists and bringing it into Power BI dashboards to make it visible to our clients, showing them all the operating systems in their environment and where the latest patches are, and then from there creating plans."
"Its security is most valuable. It gives us a way to secure devices, not only those that are steady. We do have a few tablets and other devices, and it is a way for us to secure these devices and manage them. We know they're out there and what's their status. We can manage their life cycle and verify that they're updated properly."
"Microsoft Intune helps secure hybrid work by allowing organizations to manage and secure devices remotely."
"Microsoft Intune not only saves costs by reducing the number of personnel needed but also offers a comprehensive solution for managing laptops, applications, security, individual access, and enrollment."
"Microsoft Intune has never crashed for me; it always works without fail."
"From a security standpoint, it allows us to make sure that we're not leaving ourselves vulnerable to exploits and things like that. That's the biggest advantage that we see to the product from a security standpoint."
"Servers are patched more consistently than they have been previously."
"We basically use it as our master source and then, from that, it helps us provide a source of truth."
"We've actually fixed the patching by improving our patch application by almost 60%."
"Being able to hit all of our endpoints is the most beneficial feature of this solution."
"Reliability of the agent and the ability to troubleshoot actions after they've been taken are the most valuable features."
"Our compliance levels - i.e. our compliance percentage has improved."
"We've had no issues with stability."
"Tanium's most valuable features are patch management, inventory, and distribution software."
"Tanium is used for endpoint management, specifically patching and configuration management."
"The product is granular and can build complex roles compared to other EDR vendors."
"The solution is scalable and helps to understand how infrastructure works. It helps to improve the health of the organization."
"Tanium’s best features include support for any Windows, Linux, or Mac endpoint, regardless of where it is, and the ability to do IT operations and security operations."
"I like the tool's incident response and security patching."
"When I push a quick update, it's done right away, and I can rescan immediately to confirm completion within minutes."
"I would say Tanium is the best tool for vulnerability management."
 

Cons

"I'd suggest adding more features for macOS in Intune. There should be more functionality for managing macOS. There should be a better capability for pushing things down on macOS. Currently, Intune is not capable of managing macOS at the same level as Windows."
"There needs to be more support for Mac operating systems."
"Each feature has a separate license, making logistics and cost management difficult if not strategically bundled together."
"In future releases, I would like to see better integration with Apple products."
"It would be beneficial to have a more straightforward understanding of Intune's capabilities, presented in a simplified manner."
"Reporting needs improvement."
"The reporting causes problems because we're trying to gather data to present to the management, but we can't get the data they request. If a user has removed an application from his device, but it won't report it at exactly the right time. It takes time to sync from the device to the portal. Let's say we are preparing a list or deck for the number of compliant devices that meet all of the organization's requirements. In a real-time scenario, that device could be compliant, but it is showing as non-compliant on the portal. It sometimes hampers the overall decisions that we make on our end."
"Currently, BitLocker does not support BYOD enrollment, which is a product limitation."
"Sometimes there is a lag time for our users."
"I would like to see the Self Service section made more user-friendly."
"Relay selection and availability needs improvement as an incorrect relay selected can cause network chokes."
"The first setup was complex."
"I would like to see for it to be a little easier for new users to be able to learn and create relevant statements. In my opinion, that's the hardest part for bringing on new people that haven't had BigFix experience. Being able to have easier ways to build relevance in ActionScript would be the biggest improvement I'd like to see."
"The technical support is usually pretty good. However, I had a ticket that stayed open for a couple of weeks which I didn't get a response to, and when we got the response it wasn't really good."
"The self-service application seems to need some work to replace the client UI. There are a lot of pop-ups if you use a baseline as the object that you're setting to a workstation. Unless you're using web UI, the message is not customizable in the user notification."
"I would like the dashboard to be improved to show the problematic machines and good machines."
"In my opinion, sometimes it takes a long time to give solutions or resolve the issue."
"The problem or challenge is a pre-sales and go-to strategy for the SMB market delivered through a channel or model. It's very convoluted and vague, which leads to some confusion about the various types of modules, and the device-to-seat cost is extremely difficult to calculate."
"The most painful thing is the interface. It's a bit unclear sometimes."
"The solution needs to improve the reporting and tracking capabilities."
"When working with Tanium, there are some older devices that haven't been patched for a long time, and certain patches are not included in Tanium. I have to search outside to download patches, create bundles, and then perform the task."
"Tanium required local admin or root rights on Mac devices, which did not comply with our security policies. This made the solution less suitable for our restrictive environment."
"Any movement into a SaaS solution has challenges since the processes and data flows are not well defined. Hence, you need to build it at the same time."
"Most of the time, agent-relative issues have to be more equipped with self-healing features. At times, the agent is there, but for some reason, it doesn't report a status. It gives certain problems that are obviously agent-based."
 

Pricing and Cost Advice

"The price of Intune is included with the license for Office 365, so we don't have to pay anything extra for it."
"For Microsoft 365 E5 clients, cost is not an issue as this product is one of the benefits."
"The pricing is good because customers are not complaining about it."
"We work in the charity sector, so a lot of our clients get Microsoft Premium licenses or Business Premium for free. They get ten licenses free, and a lot of our clients do not have more than ten staff members. They are getting the tool for free, so its cost is not an issue."
"The product is expensive."
"Intune is included in the Microsoft 365 licensing package that we have."
"It is average. Some of the costs are quite high depending on what the customer currently uses, but overall, it is not bad. I would not say that I would not recommend Intune based on the cost. I definitely would, but they can definitely improve on the cost. So overall, its cost is not bad."
"Microsoft Intune is pretty reasonable. We have difficulty with Azure, which is probably why we have not put many assets in Azure. Everything we put there is very expensive."
"You get what we call the Platform Edition, which you get for free. The patch service is maybe $0.50 per workstation per month. Then there's the basic server cost, which is about $1.50 per server per month. You also get into Lifecycle which does power management, OSD remote control, and those types of things, and that might be about 10 times the price - which works out to about $13 per server and, maybe $5 per workstation per month."
"On a scale from one to ten, where one is expensive and ten is cheap, I rate the solution's pricing one out of ten."
"The tool's price continues to go up. The cost per endpoint can vary, ranging from approximately 30 to 80 dollars per year. Compared to other products, pricing is in the middle. You need to buy an additional database license, but most users already have it."
"The price is very fair."
"It might be about $23 a client."
"I can estimate the reduced cost of servers maintenance to approximatively $500,000."
"When purchasing, buying with other IBM tools provided us with a very good discount in pricing."
"The price of BigFix is better than the solutions. You are able to pay monthly or annually. There are not any hidden costs with BigFix. There is an additional cost for the SQL database."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"It's an expensive solution. It would be nice if the cost were lower."
"It is higher than some competitors in the market."
"The solution is expensive but it's a good investment."
"There is an annual license required to use this solution."
"The solution offers value for money."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
9%
Computer Software Company
8%
Outsourcing Company
7%
Financial Services Firm
13%
Manufacturing Company
9%
Government
7%
Construction Company
6%
Financial Services Firm
14%
Government
10%
Manufacturing Company
9%
Healthcare Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business192
Midsize Enterprise62
Large Enterprise186
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise12
Large Enterprise68
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise12
 

Questions from the Community

How does Microsoft Intune compare with VMware Workspace One?
Microsoft Intune is a great tool for managing a mobile device fleet while keeping access control. The solution makes ...
What are the pros and cons of Microsoft Intune?
Microsoft Intune is a great configuration management tool and has a lot of good things going for it. Here are some of...
How does Google Cloud Identity compare with Microsoft Intune?
Microsoft Intune offers not only an easy-to-deploy data protection and productivity management solution, but also ...
What is your experience regarding pricing and costs for BigFix?
I rate the price for BigFix as medium, neither low nor high.
What needs improvement with BigFix?
There is one feature in BigFix called the automation patch policy that requires enhancement. When an action is initia...
What is your primary use case for BigFix?
My current use case involves being one of the products and one of the clients implementing this tool.
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the co...
What advice do you have for others considering Tanium?
For smaller companies, Tanium is quite a big investment, and one needs to have a considerable setup to make it econom...
 

Also Known As

Intune, MS Intune, Microsoft Endpoint Manager
Tivoli Endpoint Manager
Tanium Inc Cloud, Tanium XEM
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Mitchells and Buzzers, Callaway
US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Find out what your peers are saying about BigFix vs. Tanium and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.