No more typing reviews! Try our Samantha, our new voice AI agent.

BigFix vs Tanium comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Intune
Sponsored
Ranking in Unified Endpoint Management (UEM)
1st
Average Rating
8.2
Reviews Sentiment
6.7
Number of Reviews
378
Ranking in other categories
Configuration Management (2nd), Remote Access (2nd), Enterprise Mobility Management (EMM) (1st), Microsoft Security Suite (1st)
BigFix
Ranking in Unified Endpoint Management (UEM)
11th
Average Rating
8.6
Reviews Sentiment
6.3
Number of Reviews
99
Ranking in other categories
Configuration Management (9th), Endpoint Protection Platform (EPP) (25th), Patch Management (8th)
Tanium
Ranking in Unified Endpoint Management (UEM)
7th
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
22
Ranking in other categories
Server Monitoring (4th), Vulnerability Management (26th), Endpoint Protection Platform (EPP) (17th), Endpoint Detection and Response (EDR) (22nd)
 

Featured Reviews

OluwashileAdeniyi - PeerSpot reviewer
Senior Infrastructure Security Engineer at a outsourcing company with 51-200 employees
Centralized endpoint security has improved and supports hybrid work and BYOD policies
Regarding what I dislike about Microsoft Intune and its downsides, I would say that more Mac controls are needed because we have limited Mac and Linux control. When comparing controls and policies between Windows, Mac, and Linux, Windows has almost everything you can think of, while Mac and Linux have limited types of control. You cannot implement certain things on Mac and Linux that you can on Windows. The limited controls are a major issue. Additionally, if Microsoft could find a way to embed servers into Microsoft Intune, that would be beneficial. Microsoft Intune is not really designed for servers or Windows servers. It is more tailored towards Windows 11 and Windows 10 operating systems. Windows servers are not fully supported. Enterprise organizations usually have both servers and endpoints, which are users' workstations. For servers, most people look for other solutions such as SCCM, which is Configuration Manager. However, SCCM is what Microsoft Intune is trying to replace. Both SCCM and Microsoft Intune belong to Microsoft. Microsoft is trying to transition organizations into Microsoft Intune, the native cloud solution. However, because this update is still in process, servers are not fully compatible with Microsoft Intune and cannot be managed by it. The current policy that has emerged from issues with clients is what they call co-management, which is relatively new, and I do not know if adoption is significant. Many legacy or older customers who have been using these products for decades still have SCCM. When it is time for them to manage their Windows devices, they use what is called cloud attach. Cloud attach is a term whereby your SCCM is connected to your Microsoft Intune. Most people do not know about it, but I have deployed it for several organizations. Cloud attach and co-management work together so that your device is in SCCM, but some policies are pushed from Microsoft Intune. It is like two different solutions working hand in hand. That is what they call co-management. Microsoft Intune does not bring all of your endpoint and security management tools into one place, which is the goal and how it should be. However, as I mentioned, servers are not included. If we talk about end users, Microsoft Intune does bring all your devices together. In a typical enterprise environment, you have end users with workstations, laptops, company-issued phones, and bring your own devices. You can create policies for all of these. However, for the backend, your servers do not have much coverage. Servers are not really covered by Microsoft Intune in that way.
Ravi Khanchandani - PeerSpot reviewer
Founder Director at Techsa Services
Long-term partnership improves customer satisfaction and delivers efficient endpoint management
BigFix supports something known as Patch Policies, which allows users to define that whenever critical patches are released, they should get evaluated against machines and automatically deploy them. Their software distribution is very efficient because they use a pull mechanism rather than a push mechanism, allowing each machine to download from the closest repository and install themselves. The same assessment mechanism applies for real-time vulnerability remediation, allowing identification, evaluation, and automatic remediation across machines. Compliance metrics typically measure the patch percentages deployed against the number of endpoints, which could be various device types including virtual machines and mobile devices. Measurements are taken against each device type, looking into compliance percentages for browsers such as Chrome and Edge based on their versions.
MA
Division Manager, Information Technology at a legal firm with 51-200 employees
Centralized policies have improved remote endpoint control and have simplified data visibility
The integration is not simple and easy. It requires experienced users or people who have done the implementation. When certain policies are applied, they do not immediately push the policies. For example, we manage endpoint device USB access. We set a policy to block it, but it does not come into effect immediately. Sometimes it takes three or four days for it to reflect. That is a pain point. I have raised this issue with support as well, but they said that I need to limit the number of devices in the policy. In terms of application deployment, for us, it was seamless.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Conditional access helps me control uncontrolled access."
"Intune's compliance features are valuable because they allow immediate visibility into ongoing situations."
"We are a remote company, and the product helps us manage the global endpoints. It helps us natively manage the endpoints in the cloud from anywhere."
"With on-premises Active Directory, the main challenge was that we had no control when a user was working from home. We didn't know what exactly a user was doing and whether the AV was up to date or not. Intune provides better control of their machines."
"The security posture is very good. It's very customizable."
"I like how Intune deploys the policies and makes them customizable. You can deploy it through Intune and forget about it."
"After implementing Microsoft Intune, we have seen a 50 to 70% reduction in device provisioning time and a 30 to 40% reduction in routine endpoint management efforts, allowing our IT team to focus less on routine management and providing faster software deployment while experiencing a significant reduction in support tickets."
"Microsoft Intune does a great job of helping protect our environment."
"The combination of CyFIR and BigFix has allowed one of our major customers, one of the top Fortune 50 financial firms in the world, to reduce their forensic investigator count by about 4 FTE with the combination of CyFIR and BigFix."
"I like the overall usage of it; it's easy to use, gives you great visibility into your environment, allows customization of your reports, and offers a community of users from whom you can pull experience and knowledge, which is one of the main advantages of using BigFix."
"Vulnerability scanning and patch automation."
"The stability on this solution is rock solid; I will put money up against it, and BigFix is absolutely unbelievably stable."
"BigFix tremendously reduced the amount of work that we had to do on each server in a centralized manner, reduced help desk calls by 60-70%, empowered users with a self-service portal to fix their own problems, and helped us avoid compliance fines in the tens of thousands of dollars by enabling accurate software audits and license verification."
"What I like most is that it is a powerful solution."
"Patch management is vital for security posture, so I wouldn't be surprised if BigFix is becoming increasingly popular."
"We've had no issues with stability."
"Tanium is stable and it is also lightweight."
"It's definitely not complex, it is pretty user-friendly and it's a solid tool enterprise to use."
"Tanium's most valuable features are patch management, inventory, and distribution software."
"The product is granular and can build complex roles compared to other EDR vendors."
"Tanium’s best features include support for any Windows, Linux, or Mac endpoint, regardless of where it is, and the ability to do IT operations and security operations."
"The insights we gain from our endpoints and the management capabilities that Tanium provides have been a boon to our operations and security."
"Tanium has made the process of detecting threats more proactive with its detection. So, the process is easier and more efficient."
"Tanium is highly scalable."
 

Cons

"I rate Microsoft support between six to eight. The support often involves third parties hired by Microsoft who are knowledgeable, but sometimes the help I receive is not adequate."
"There is room for improvement in Microsoft Intune regarding Linux and Mac compatibility because some limitations exist."
"There is room for improvement in integration and security as well."
"Intune lags all of its competitors in terms of report generation."
"The installation could be improved to be simplified."
"Reporting can be better. Only global administrators can see detailed reports at the moment, and I don't want to use the global admin."
"The reporting functionality of Microsoft Intune is limited compared to Microsoft System Center, which offers many more reporting options."
"It would be great if Intune offered better data protection controls for BYOD Windows PCs."
"I want to see a solution for being able to deploy automated software to a Mac running OS X 10.13, something that's going to deal with kernel exceptions and answering prompts for user permissions for data folders and whatnot. They need to really streamline and automate the Mac software deployment."
"The deployment has room for improvement and can be more streamlined."
"The one feature that I would have like to see included (I know it is coming in the next release), is the block function of the newly announced BigFix Detect module."
"The main shortcoming of BigFix was integration with vulnerability management."
"The stability is generally pretty good. The one thing that we came across is the battle between load on endpoints and load on our servers and relays versus how quickly, effectively and reliably actions can be taken. I'd like to not have to take an action on a system while I'm working with someone and then have to say whether something will happen between five seconds or thirty minutes from that point."
"The first setup was complex."
"The solution should have some kind of a local caching methodology, where the patches can be taken locally into a localized relay server, and from there, the patch can be applied, so that there is not much usage of the network required."
"I would like to see more integration with external data."
"It is not really additional functions, or the features that are needed, rather the complexity would be reduced based on the number of modules required to put together a comprehensive operational security and risk compliance model."
"The solution lacks mobility."
"They could improve the UI."
"When working with Tanium, there are some older devices that haven't been patched for a long time, and certain patches are not included in Tanium. I have to search outside to download patches, create bundles, and then perform the task."
"I would like to have more integrations and custom plugins to input. Integration is always a big deal in a lot of different environments."
"The main issues are the network connection because different customers have issues with their networks. It's difficult implementing this type of solution because the network is the main feature in the architecture for these types of solutions. Tanium could improve by creating some network optimization."
"Tanium required local admin or root rights on Mac devices, which did not comply with our security policies. This made the solution less suitable for our restrictive environment."
"Any movement into a SaaS solution has challenges since the processes and data flows are not well defined. Hence, you need to build it at the same time."
 

Pricing and Cost Advice

"The clients pay for a license and each can have a different type of license, such as an E3 or E5."
"I rate Intune an eight out of ten for affordability. It's bundled with the 365 licensing, which is competitive overall."
"In terms of the product price and licensing costs, my company finds the product to be reasonably priced."
"I don't have any problem as far as cost is concerned. It is bundled with our license."
"All security solutions worldwide are expensive. Microsoft has allowed a small scale of features within Microsoft Intune for cost-efficient solutions. If you want the full suite, you need to invest more to gain better security features."
"I recently got to know that the AD P1 license is compulsory to use Intune Autopilot, which was surprising for me. Earlier, this was not the case. It is the wrong thing to do. We now need to purchase AD P1 licenses for us and for our customers. I would rate it a seven out of ten for pricing."
"Microsoft Intune is not cost-effective as a standalone product."
"If you ask the accountant or the finance department, they'll tell you that it is way too expensive, but when I look at the cost and compare it with the value you actually get, it's more than fair."
"We have a subscription-based contract with BigFix."
"I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical."
"The cost is slightly high."
"It is too costly. It is one of the best tools, but because of pricing, not all clients support it. Its licensing is on a yearly basis."
"Compliance, inventory, and licensing are really pricey. They should lower the price. It discourages users from getting onboard."
"The license is subscription-based."
"You are charged per server and per workstation when using BigFix. ManageEngine is a lot cheaper than BigFix. There are some additional costs, such as support."
"The price of BigFix could be lower. However, I am always seeking a lower price."
"It is higher than some competitors in the market."
"It's an expensive solution. It would be nice if the cost were lower."
"The solution is expensive but it's a good investment."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"There is an annual license required to use this solution."
"The solution offers value for money."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Manufacturing Company
10%
Computer Software Company
8%
Government
7%
Financial Services Firm
13%
Manufacturing Company
10%
Government
7%
Construction Company
5%
Financial Services Firm
14%
Government
11%
Manufacturing Company
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business190
Midsize Enterprise65
Large Enterprise185
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise12
Large Enterprise67
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise3
Large Enterprise12
 

Questions from the Community

How does Microsoft Intune compare with VMware Workspace One?
Microsoft Intune is a great tool for managing a mobile device fleet while keeping access control. The solution makes ...
What are the pros and cons of Microsoft Intune?
Microsoft Intune is a great configuration management tool and has a lot of good things going for it. Here are some of...
How does Google Cloud Identity compare with Microsoft Intune?
Microsoft Intune offers not only an easy-to-deploy data protection and productivity management solution, but also ...
What is your experience regarding pricing and costs for BigFix?
The pricing is pretty good and now follows a subscription model similar to other major software solutions, making it ...
What needs improvement with BigFix?
I have concerns about BigFix's pricing, which I find to be slightly on the higher side. While it may not be the most ...
What is your primary use case for BigFix?
I have been working at Tech Data for the last 12 plus years.
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the co...
What advice do you have for others considering Tanium?
For smaller companies, Tanium is quite a big investment, and one needs to have a considerable setup to make it econom...
 

Also Known As

Intune, MS Intune, Microsoft Endpoint Manager
Tivoli Endpoint Manager
Tanium Inc Cloud, Tanium XEM
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Mitchells and Buzzers, Callaway
US Foods, Penn State, St Vincent's Health US Foods, Sabadell Bank, SunTrust, Australia Sydney, Stemac, Capgemini, WNS Global Services, Jebsen & Jessen, CenterBeam, Strauss, Christian Hospital Centre, Brit Insurance, Career Education Corporation
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Find out what your peers are saying about BigFix vs. Tanium and other solutions. Updated: May 2026.
902,270 professionals have used our research since 2012.