Configure the Tanium environment for the Service Graph Connector for Tanium Endpoints
Configure your Tanium environment to import data using the Service Graph Connector for Tanium Endpoints.
Before you begin
Role required: Tanium administrator
About this task
The Service Graph Connector for Tanium Endpoints authenticates to Tanium using an API token. To follow Tanium's security best practices, the token must be bound to an identity that has only the roles required by the integration—not a privileged administrator account. For more information, see Creating API tokens for ServiceNow.
| Identity | Description |
|---|---|
| Service account (recommended) | Default identity. Provides the cleanest separation of integration permissions from human users. |
| Persona | Use this identity only if your organization doesn't permit dedicated service accounts. |
After you configure an identity, create an API token. Provide the resulting API token to the ServiceNow administrator who sets up the Service Graph Connector for Tanium Endpoints.
Procedure
Configure an identity for binding the API token that is used by the Service Graph Connector for Tanium Endpoints:
- Configure a service account (default identity)
- Configure a persona (alternative identity; to be used only when a service account is not permitted) Create an identity that has only the roles required by the integration.
-
After configuring the identity (service account or persona), generate the API token to be used by the Service Graph Connector for Tanium Endpoints.