If you are standing up a software asset management programme and shopping for a
tool to support it, you will have to decide where you stand on agent-based versus
agentless discovery. Some products offer only an agent. Others offer only
agentless collection. Both will tell you their approach is the right one.
The honest answer depends on your circumstances, what the programme is meant to
achieve, and how you want to run the environment you are managing. But it usually
lands in the same place, and it is not one of the two options you were offered.
Discovery comes first
Before you can manage anything on a network, you need to know two things: what is
there, and what each of those things actually is.
That sounds too obvious to state, except that a number of products effectively
ignore it. How do you deploy an agent to something you do not know exists? How do
you deploy an agent to a switch, which cannot run one?
You cannot. Which means an agent-only product is bounded by the list you already
had. It will tell you a great deal about the machines you knew about, and nothing
whatsoever about the ones you did not — and the ones you did not are usually the
interesting ones.
Where each approach falls down
Agent-only. Richer data, collected continuously, including things you can only
see from inside the operating system: software usage metering, local
configuration, patch state. But you have to know a device exists before you can
deploy to it, some devices cannot take an agent at all, and there are parts of the
infrastructure — data centres especially — where getting approval to install one
ranges from slow to impossible.
Agentless-only. Finds things without prior knowledge, and reaches devices that
could never run an agent. But it depends on the device being reachable at the
moment you scan. If you have remote workers who rarely connect to the corporate
network, you get intermittent, out-of-date information about what is on their
machines — which is bad for SAM, where usage evidence and installation dates are
the whole basis of a licence position.
Both approaches have strengths and weaknesses, and which weakness hurts more
depends entirely on your organisation.
The answer is both
By now the answer to the question in the title is probably obvious: both.
Unless you already have a discovery capability you trust to find everything you
own, you need agentless discovery first. It finds not just PCs, laptops and
servers, but switches, printers and other connected devices — including the
connected hardware that has quietly attached itself to the network without going
through anybody’s asset process.
That last category matters increasingly for security rather than licensing. A
great deal of connected equipment now sits on corporate networks with poor
security and no patching story. Used without a policy governing it, and
undiscovered, it is a genuine route in.
Once you know with confidence what is actually out there, you can plan and deploy
agents to the devices that can take one, and get the full software inventory and
usage picture SAM depends on.
There are also places where agentless collection is the better answer permanently,
not just as a first pass:
- Servers are rarely switched off and are always on the network, so the argument
for an always-resident agent is weaker — the device is reachable whenever you
want to look at it.
- You may not be permitted to install agents on data centre hardware at all,
whether through change control, vendor support terms or hosting arrangements.
- Some devices — network equipment, printers, appliances — will never run an
agent under any circumstances.
So a hybrid of agent and agentless discovery is not a compromise. It is the
correct design. It gives you the current, detailed inventory and usage information
SAM requires, and the coverage that discovery requires, and it makes patching and
software distribution possible where an agent is present.
What that looks like in CerteroX
CerteroX ITAM was built around this rather than adapted to it. There are ten
discovery methods, and they all resolve into one schema, so there is no
reconciliation step between them.
Finding what you do not know about. Network Discovery sweeps a class-C subnet
in under five seconds across NetBIOS, SNMP and ICMP, then probes port 22 to
establish where an agent could actually be deployed. Discovery runs ahead of
deployment rather than after it. SNMP collection also brings back real detail from
devices that will never run an agent: printer consumables and page counts, switch
port and routing tables.
Where an agent works. The native agent covers Windows, macOS, Linux, IBM AIX,
HP-UX and Oracle Solaris — one agent, six operating system families, the same
inventory cycle and the same licence engine for all of them. Unix platforms are
not an integration project here, which is usually where a data centre-heavy
environment finds out whether a tool was designed for it or retrofitted.
Where an agent does not work. Agentless collection and a command-line
collector (csinvcli) handle locked-down machines. Standalone inventory covers
air-gapped and offline systems, which no scan will ever reach. Non-persistent VDI
is handled as its own case rather than producing a new device record every
morning.
Keeping the picture honest. Active Directory import brings in users, groups,
computers, sites and subnets, and can be cross-referenced against an independent
scan so AD is a source rather than the source. Duplicate system detection and
stale device archiving stop the device count inflating, which matters when your
licence position is calculated from it.
For SAM specifically, the agent is what earns its place: AppsMonitor file-based
usage metering with first-used and last-used tracking, a % Used utilisation metric
over a rolling 90-day window, and Terminal Server and RDS remote-usage tracking
per device. That is the evidence you need before reclaiming a licence from
somebody, and it is not available from a network scan.
The question to ask a vendor
Rather than asking whether a product is agent-based or agentless, ask three
things.
How does it find a device nobody has told it about? What does it do about the
machines where an agent cannot be installed, and about the ones that never touch
the network? And when it has collected the same device by two different methods,
which record wins, and where does that decision happen?
A product that has good answers to all three is one that will still be giving you
an accurate picture in three years.
Name the coverage gap you cannot close today — the locked-down subnet, the air-gapped rack, the Unix tail — and book a demo. The session is built on whichever one you pick.