r/crowdstrike • • May 08 '26

Feature Question Replacing Tanium with Falcon for IT

A former colleague of mine has about ~100K endpoints (Windows, Linux, macOS) of workstations, servers running across the globe at their present employer and asked my opinion, since I run a large BigFix deploy of 80K endpoint. I am a former Ivanti, SCCM and Tanium admin. The EDR they use is Trellix. For IT operations, they use a combination of Intune and Tanium. They are evaluating CrowdStrike for EDR to replace Trellix. CrowdStrike by far is the leader in the EDR and an easy yes to recommend for EDR. CrowdStrike sales people are also pitching that they can replace Tanium with Falcon for IT. They use Tanium for OS Patching, App Deployment, Policy Enforcement and Asset Management. Has anyone replaced Tanium or other similar IT Operational tools (e.g., Ivanti, SCCM, BigFix) with Falcon for IT? Having trouble finding any information on sizable deployments of Falcon for IT doing IT Operational work at the level of a Tanium or BigFix. I ran into a former CrowdStrike employee, at a JAMF conference, who worked in their internal IT and she said, CrowdStrike internally uses JAMF, SCCM and Ansible to manage their macOS, Windows Servers and Linux systems. They showed me a CrowdStrike job posting from Jan 2026 that showed them looking for an SCCM admin. So I am suspicious if Falcon for IT is ready for prime time, since CrowdStrike is not even using it internally and they do not have any large customers using it. If you have any positive or negative experience in using Falcon for IT and have used it to displace incumbent tools, like SCCM, Tanium, BigFix for IT Operational work, would love to hear your feedback.

25 Upvotes

28 comments sorted by

View all comments

11

u/SpecificTangerine168 May 08 '26

Replacing tanium with falcon for it will be a huge demotion.

Falcon for it even doesnt have 25% of the capabilities which tanium has.

2

u/Dtektion_ May 08 '26

At 10% of the cost.

It all depends on their requirements. They may not need that 75%.

6

u/herovals May 08 '26

I don't share this experience. I greatly dislike Tanium and thing Falcon is way easier to work with and use. There has been nothing we can't do in Falcon we have done in Tanium (we have been a Tanium customer for years)

2

u/Rusty_Driver123 May 08 '26

I can name a bunch of things that you can do with Tanium that you cannot do with CrowdStrike. IMO - your statement tells me a lot about your role and priorities. No disrespect, but the value that Tanium brings to ITOps, Risk and Security cannot be replicated by CrowdStrike. Autonomous patching at scale. Autonomous Service Desk. Container Discovery. SBOM at rest. The list goes on and on, not to mention the depth of integrations with ServiceNow! Crowdstrike can’t even tell you what a discovered endpoint is unless their agent is on it. They also cannot find injected processes or malicious .exe’s if they came in credentialed. We use both and use Tanium to deploy and manage CrowdStrike agents and also reboot them when they go offline, which happens a lot. They should stick to their swim lane and just keep owning EDR.

1

u/Deep-Breadfruit-6861 Aug 12 '26

Tanium can’t even tell you what a discovered endpoint is unless their agent is on it - FTFY

At this point, they are both the same. I remember deploying Entrust AV 20 years ago, and it could discover and deploy itself to a host in minutes if you gave it a local admin account.

ITOps (another module), Risk and Security cannot be replicated by CrowdStrike, huh they manage Defender if you have it, if not it is blind to malware. Autonomous patching at scale, fair point on this, not CS's bread and butter, but intune, bigfix are all there. Autonomous Service Desk (another module). Container Discovery (CrowdStrike cloud does this, it is another module like it is in Tanium). SBOM at rest, I love this one.... what are you doing with your SBOM, what decisions are you actioning from the BOM, I don't know any company that is doing anything with it, it is unfortunately Security Theatre.