Skip to content

Is your ITAM function ready for Coronavirus?

A business continuity checklist for ITAM and SAM leaders — licensing when staff work from personal devices, temporary rights changes that are never reversed, unsanctioned software, and keeping sight of machines that no longer touch the corporate network.

While there is nothing to be gained from adding to the noise, when organisations around the world start preparing contingency plans for how to keep operating through a widening emergency, it is worth walking through what that means for IT and software asset management specifically.

Colleagues in HR and IT are refreshing their business continuity plans. ITAM and SAM leaders should be doing the same, because most of the decisions taken in a hurry during a disruption land in your ledger afterwards.

Employees self-isolating or working from home

BYOD, secondary use rights and licensing

Organisations with a highly mobile workforce are usually well prepared for empty offices and staff taking laptops home. Organisations that do not routinely issue laptops are not. Expect a jump in people using personally owned devices to reach corporate applications — email, productivity suites, collaboration platforms — over the public internet.

If those applications are modern and cloud-delivered, such as Microsoft 365, Google Workspace or Salesforce, this is rarely a licensing problem, provided entitlement is tied to the user rather than the device. Where it is tied to the device, you need secondary use rights in place. Older applications licensed under schemes that never anticipated home working are where the difficulty sits: you may not be able to give people enough access to stay productive without buying something.

Free trials are still commitments

A great many productivity and collaboration vendors push free trials hard the moment remote working spikes. That can be genuinely useful. But a free trial is exactly that. Continued use after it lapses can convert automatically into a charge, or leave you carrying a cost nobody budgeted for. Take the offer if it helps — just decide in advance what happens on the day it expires, and record the expiry date somewhere that is not one person’s calendar.

Security follows the device

When personal devices reach corporate systems, they arrive without the protections you normally assume: managed anti-malware, patch levels you control, a corporate firewall between the machine and the internet. Access to sensitive systems needs re-scrutinising and risk assessments need revising to reflect a higher likelihood of unsanctioned devices and insecure connections.

The same applies to phones. Most modern applications accommodate a licensed user working across several devices, but confirm that is true of yours, and assess what the increase means for data integrity and privacy.

Whatever you change in a hurry, record it. Every short-term relaxation made to enable home working needs to be reviewable, and reversible, once the emergency passes. In CerteroX ITAM this is what Governance Policies are for: compliance rules expressed as reusable filters — BitLocker enabled, Defender running, tag hygiene on cloud VMs — with the policy definitions exportable and importable as JSON, so a temporary exception is a tracked change rather than an oral tradition.

Changing user rights

Contingency plans often assume that technical and administrative staff will backfill for sick colleagues, or temporarily pick up additional responsibilities, so that business operations keep running.

With enterprise systems from Oracle, IBM and SAP, that is a licensing event. Users may need additional rights, or a change of licence type, to hold the privileges required to support a mission-critical system.

If this applies to you, track it. The expensive failure mode is not granting the rights — it is granting them for an emergency and never reversing them, so that a temporary elevation quietly becomes a permanent entitlement class that you are still paying for, and still liable for, at the next audit. Hoping for a compassionate reading of your licence terms is not a control.

CerteroX SAM’s SAP analysis exists for precisely this shape of problem: priority-ordered analysis rules propose the licence type each named user should hold, so current, suggested and optimal positions sit side by side and an elevation that outlived its reason is visible rather than buried. For SaaS applications, CerteroX SaaS Management’s workflow engine can drive the reversal itself — eight triggers, eleven conditions and thirteen actions on one canvas, with every provisioning and deprovisioning step written to an audit log.

New software and hardware requests

Disruption changes how teams work together and which tools they reach for.

Organisations with existing investments in collaboration platforms are well-equipped to absorb it. In some cases the emergency is the event that finally drives adoption of a platform that has been paid for and under-used for years — which is worth measuring, because it changes the renewal conversation.

Organisations without an established platform get a harder version. Teams either suddenly demand access to software they previously ignored, or they go their own way and adopt whatever works, outside IT’s visibility and control.

Head that off if you can, by making sure department leads know what is already available to them before everyone is working from a kitchen table. But assume some of it will happen anyway — and that is now a discovery problem rather than an unknown. CerteroX SaaS Management converges three signals to surface applications nobody registered: identity provider sync from Entra ID and Okta, authoritative user and licence lists pulled through 47 vendor connectors, and a browser extension that attributes SaaS domain use per user. Applications resolve against a catalogue of more than 35,000, and AI tools are classified from catalogue feature tags rather than a hardcoded list, so the Shadow AI dashboard keeps finding things after you stop maintaining it. OAuth grants that people consented to along the way are discovered too, scored from 0 to 100 on sensitivity, scope, consent and dormancy, and revocable in one click.

On hardware, expect a squeeze from both directions. A sudden move to remote working competes for laptop stock at exactly the moment everyone else wants the same units, and procurement lead times do not compress to match. Knowing what you already own — including what is sitting in a drawer, out of warranty, or assigned to someone who left — is worth more in that week than a purchase order.

Maintaining visibility of devices off the network

Governance responsibilities do not lessen because the office is empty. They increase. Visibility of the assets actually in use is the whole basis of the function.

If your ITAM tool depends on machines being reachable on the corporate network at the time of audit, an extended period of home working degrades your inventory faster than most people expect — weeks, not years. The licensing consequence is slow. The service desk consequence is immediate: a remote user calls with a problem and nobody can see the current configuration of the device or what is installed on it.

This is the practical difference between agent-based and network-scan inventory. CerteroX ITAM ships a native inventory agent for Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris, so the record follows the device rather than the subnet. Where an agent cannot be deployed there is agentless and command-line collection (csinvcli) for locked-down machines, and standalone inventory for air-gapped and offline systems. Ten discovery methods in total land in one schema, which is what stops “we have partial visibility” turning into a reconciliation project later.

Impacts on the ITAM and SAM functions directly

Suppose your own team is affected and people have to work away from the office. Do they stay productive, or does the function stall?

Ask the practical questions. Can your team reach both the reporting and the administrative side of the toolset remotely? Can cover be delegated without handing someone the keys to everything? CerteroX uses role-based access control with granular permissions, Reporting Levels that restrict visibility by organisational unit or location, and personal as well as role-shared dashboards — so a stand-in gets exactly the scope they need. There is also a read-only API with a documented Power BI data source, which means routine reporting can carry on without anyone logging into the tool at all.

Then plan for the worse case. What if one or more of the ITAM and SAM team are ill for an extended period? Can the function afford the lost output, and what does that do to the wider projects you are supporting? If it cannot, do you have people trained well enough to backfill? And if not, do you have a services agreement in place with a provider who can supply skills at short notice?

None of us wants the disruption. But ITAM and SAM professionals are the custodians of technology governance, and planning for the worst is the job.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.