Most enterprises run hybrid. You have servers on-premises, workloads in AWS, Azure or Google Cloud, and SaaS in the browser. You rely on a mix of agents and APIs reporting back to four different consoles. The ITAM tool that gave you a clean picture five years ago was built for a world that no longer exists.
For IT asset managers, SAM managers and CIOs responsible for visibility and compliance across the data centre and the cloud, the requirements have changed. This is what a modern hybrid ITAM tool has to do, and where traditional tools fall short.
What hybrid cloud ITAM requires
Hybrid cloud ITAM maintains a single, governed record of hardware and software assets across on-premises infrastructure, virtualised environments and cloud-connected systems. It combines discovery, software recognition, lifecycle tracking and governance. You do not maintain separate asset views for the data centre and the cloud.
It has to do four jobs at once:
- See everything. Physical devices, virtual machines, cloud instances, and the software running on each.
- Recognise what it sees. A raw inventory of executable names is not an asset register. It has to resolve to publishers, products, editions and licence categories.
- Tie assets to owners and lifecycle. Who owns an asset, what stage it is at, and when it needs refreshing.
- Tie assets to controls. Compliance reporting, audit defence and policy enforcement.
Tools that cover only part of that list leave you reconciling spreadsheets between two consoles. That reconciliation is a permanent tax on the team.
Why traditional ITAM falls short in hybrid environments
Three patterns break it.
1. On-premises ITAM with a cloud bolt-on
Tools designed for the data centre often pull a thin slice of cloud data through tagging APIs. That covers the resource list, but misses the full software inventory inside cloud VMs, and it never produces a governed software asset record spanning SaaS, on-premises and cloud. The data is there. The model is not.
Cloud cost and resource management tools — CloudHealth, Apptio Cloudability, the native cloud cost portals — focus on cloud cost and resource governance. They do not see your physical infrastructure, your virtualisation farms, or your software publisher catalogue.
A related mistake is using Entra ID, or any identity provider, as the asset manager. Entra handles identity, access and the SSO application catalogue well. It is not an asset register. It does not see hardware, software titles, licence entitlements, publisher compliance rules, virtualisation host-guest relationships or lifecycle state. Treating it as the asset manager produces an SSO application inventory dressed up as an ITAM record. That is exactly the gap an auditor finds.
Many teams stitch an on-premises ITAM tool and a cloud inventory tool together in spreadsheets. It works for a quarter, then the data drifts. Software titles get categorised differently in each, virtualisation gets double-counted, and the audit response that took eight hours last year takes three weeks this year.
The common factor in all three is treating hybrid ITAM as two problems. It is one. The questions are identical on both sides: what runs, how it gets used, what stage of life it is at, and whether it is compliant.
What to look for in a hybrid cloud ITAM solution
Use this as your evaluation list.
1. Unified discovery
The tool has to discover assets across every kind of endpoint: agent-based clients, agentless scans for locked-down or unmanaged systems, network sweeps for devices nothing has ever logged into, virtualisation platforms, and the public cloud providers you actually use. A vendor who can only describe one of these in detail is not offering a hybrid tool. Ask specifically about Unix — AIX, HP-UX and Solaris are where most tools quietly stop.
2. Software recognition at scale
A modern asset register depends on a continuously maintained recognition database. Check its size, its publisher coverage, and whether it carries genuine vendor-specific licensing logic rather than a name-matching table. The difference between a limited recognition library and a deep one becomes obvious the week an audit letter arrives.
3. Virtualisation awareness
Most hybrid environments run a virtualisation layer, and licensing follows the host, not the guest. Coverage needs to include the hypervisors you actually run, and the tool has to understand host, guest and cluster relationships — otherwise every processor-metric licence calculation is a guess.
4. Identity integration
Active Directory remains the on-premises anchor. Entra ID, Intune and Configuration Manager matter for the modern Microsoft-centric environment. Tools that ignore identity miss the ownership and access dimensions of asset management entirely.
5. Service management integration
ITAM data has to flow to and from a service management system. ServiceNow CMDB and Jira Service Management are the de facto standards. Ask how the integration works, in which direction data moves, and what happens on conflict — a tool without a clean answer adds manual workflow that gets skipped the first time anyone is busy.
6. Lifecycle and compliance workflow
Discovery without lifecycle is just a list. Look for hardware refresh planning, software distribution, patch management, disposal tracking, audit management and security vulnerability correlation. Ask which of these the vendor performs and which it exports for another system to perform.
How CerteroX ITAM handles hybrid environments
CerteroX ITAM provides unified asset visibility and lifecycle management across everything you own, running the four pillars the whole platform is built on: visibility through discovery, observability through recognition and telemetry, management through lifecycle, and governance through compliance and audit support.
Discovery is where hybrid tools usually fail, and it is the deepest part of the product. Ten discovery methods land in a single schema — native agent, command-line inventory, agentless collection, standalone inventory for air-gapped systems, Active Directory import, network scan, third-party ITAM import, cloud and SaaS connectors, browser monitoring, and file metering. Because they share one schema, there is no reconciliation project between them.
The native agent covers six operating system families: Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris. Unix is not an integration problem here; it gets the same agent, the same inventory cycle and the same licence engine as Windows. For systems where an agent is not an option, agentless and command-line inventory cover the gap, and standalone inventory handles anything genuinely offline. Network Discovery sweeps a class-C subnet in under five seconds across NetBIOS, SNMP and ICMP, then probes to work out where an agent could actually be deployed — so you find machines before you own them. Non-persistent VDI is supported, and duplicate system detection and stale device archiving keep the register honest.
Virtualisation coverage includes VMware, Microsoft Hyper-V, Nutanix, Oracle VM, Red Hat oVirt, Citrix XenServer and IBM HMC, with host, guest and cluster relationships preserved.
The recognition layer is the Software Recognition Database, carrying more than 3.5 million titles with centrally maintained categorisation, plus a Software Recognition Service that adds release date, end-of-support and extended support dates. Six publishers — Microsoft, Oracle, IBM, SAP, Adobe and Salesforce — have dedicated licence engines rather than generic matching, which is what turns an inventory into a defensible position.
Identity integration covers Active Directory import of users, groups, computers, sites and subnets, along with Intune and Configuration Manager. Entra ID identity sync ships today through CerteroX SaaS Management, including MFA enrolment state, and Okta is supported alongside it.
Lifecycle and management covers software distribution for MSI, EXE and Click-to-Run packages, Windows 11 upgrade orchestration, WSUS-integrated patch management, mobile device management for iOS and Android including Apple DEP, hardware warranty retrieval and expiry tracking, and an App-Centre self-service portal with manager approval chains.
Governance runs as compliance-as-code. Governance Policies use a reusable filter builder, with examples like BitLocker enabled, Defender running and Azure VM tag hygiene, and policy definitions export and import as JSON. Zones segment data across multiple entities, Reporting Levels restrict visibility by organisational unit or location, and role-based access control is granular. End-of-life and end-of-support tracking, application blacklisting and prohibition rules run from the same asset record.
For broader cloud platform visibility, CerteroX Cloud Management is the complementary product, covering twelve cloud and data platforms including AWS, Azure, Google Cloud, Oracle Cloud, Alibaba Cloud, Kubernetes, Databricks, Snowflake and Datadog, with native support for FOCUS — the FinOps open cost and usage specification — and twenty-six named, individually tunable optimisation checks. Certero’s average cloud cost saving across environments under management is 38%.
Certero was named the sole Customers’ Choice in the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools — the only vendor in the category to reach that position.
Worth verifying in a demo
Put these tests in front of any shortlisted vendor, and make them answer each one with the product open rather than in a document.
- Discovery of one data centre VM, one cloud VM, one Linux or Unix server and one network switch, in the same console.
- Software recognition for a sample of your most-used publishers, with the categorisation shown, not described.
- A virtualisation view showing host, guest and cluster relationships, and how that feeds a processor-metric licence calculation.
- A live integration to your CMDB, writing back from the asset record.
- A worked audit response using their data.
- A clear statement of what they do not cover.
That last one is the most useful question in any evaluation, and the answer tells you more than the demo does.
Where to start
Inventory what you already have. Identify where it leaves gaps — cloud, virtualisation, Unix coverage or recognition depth. Score vendors against the criteria above, and make each of them answer a cross-domain question live rather than in a document.
One question, one answer, wherever the workload actually runs. Talk to us or book a demo.
Frequently asked questions
Is hybrid cloud ITAM the same as cloud cost management?
No. Cloud cost management optimises spend on cloud resources. ITAM covers the full asset register — hardware, software licences, virtualisation and lifecycle. They are complementary, and they share data. CerteroX Cloud Management handles the cost side.
SAM is closely related to ITAM but focuses on licensing, compliance and optimisation. CerteroX ITAM covers asset visibility and lifecycle. CerteroX SAM extends that with the effective licence position, entitlement management and audit defence, including dedicated engines for the publishers that carry the most audit risk — Oracle, IBM and SAP among them. Certero is a verified third-party tool vendor with Oracle License Management Services: Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.
How long does deployment typically take?
It depends on the number of locations, the mix of operating systems, and how much of your environment can take an agent. Agentless discovery and network scanning accelerate initial coverage considerably. Get the timeline scoped against your locations and operating systems rather than accepting a generic figure.
Can ITAM data feed ServiceNow?
CerteroX ITAM exposes a read-only API with a documented Power BI data source, and ships twenty-eight named system connectors. If a bidirectional ServiceNow CMDB or Jira Service Management integration is a requirement for you, raise it explicitly during scoping so the integration path is agreed rather than assumed.
GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates.