Skip to content

The Key Issues Behind IT Asset Identification

If you cannot measure what you have, you cannot manage it — and you certainly cannot defend it. The four things that most often break IT asset identification: tool sprawl, incomplete discovery, missing attributes, and entitlement nobody can produce.

The old adage that you cannot manage what you cannot measure has never applied more directly than it does to IT asset identification.

Not being able to measure accurately what hardware and software you have installed reaches well past basic IT Asset Management. It determines whether you can defend a software audit, and whether you can optimise licensing to reduce cost going forward. Both of those are downstream of one question: do you actually know what is there?

Here are the issues organisations most often run into.

Tool sprawl

The first problem is the inventory tooling itself.

Most organisations work out quickly that manual discovery and inventory is not viable. It takes so long that the information is stale on delivery. So the first requirement of a discovery and inventory tool is that it gives you current information, continuously, rather than a periodic snapshot.

What happens next is more insidious. An organisation buys a tool to solve one problem, then a different tool to solve another. There is hardware to discover and software to discover, and the two rarely arrive in the same product. Add a tool for the data centre, one for Unix, one for mobile, and the number of tools in use — each of which itself needs managing — grows past the point of usefulness.

The result is many separate information feeds that have to be collated before they mean anything for ITAM, SAM or software licence optimisation. You would expect that collation to be straightforward. It very rarely is, even between products from the same vendor.

Are you discovering everything?

A fragmented approach makes it hard to introduce any real quality assurance over whether all hardware and software is being found.

You might be content with a discovery rate of, say, 95%. Consider what that means. Across 10,000 devices, 95% leaves 500 machines you do not know about. Not 500 devices that are slightly out of date — 500 you have no record of at all. Whatever is installed on them is unlicensed by default, unpatched by default, and invisible to every control you have built.

You do not need an industry average to make that uncomfortable. Put your own device count and your own confidence level into the same sum, and the number that comes out is the size of the gap you are currently carrying.

Attributes, not just presence

Even where a tool finds everything, it may not return everything you need.

Effective SAM depends on attributes that basic discovery tends to get wrong or omit entirely. Processor core counts and core factors. Which hypervisor a workload sits on, and how that hypervisor’s licensing rules apply. Cluster membership. Partition configuration on Unix hardware. Whether a machine is covered by a licence pool, and under which hosting terms.

These are exactly the fields a publisher’s audit turns on. A tool that reports a server exists, but reports its processor topology incorrectly, has not given you a compliance position. It has given you a liability with a tick next to it.

Entitlement you cannot produce

Beyond tools, there is the question of how you manage licence entitlement.

Many organisations have no central repository for entitlements, or a fragmented one spread across procurement systems, mailboxes and spreadsheets. Combined with the absence of a Definitive Media Library, that means you cannot prove your right to use software when you are challenged during an audit.

This one is genuinely solvable in-house. Collecting and collating entitlements into a central repository that incorporates a DML lets you understand your shortfalls before someone else does, and react properly when an audit is announced. The work is unglamorous and it is worth doing regardless of tooling.

What closes these gaps

Each of the four problems above has a specific answer in CerteroX ITAM and CerteroX SAM.

Against tool sprawl: one schema. Ten discovery methods — native agent, command-line inventory (csinvcli), agentless, standalone, Active Directory import, network scan, third-party ITAM import, cloud and SaaS connectors, browser monitoring and file metering — all land in the same data model. Twenty-eight named system connectors bring in what you already run rather than demanding you replace it. There is no collation step afterwards, because the feeds were never separate.

Against incomplete discovery: find things before you own them. Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes to establish where an agent can actually be deployed. Six operating system families share one native agent — Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris — so the platforms most tools treat as an integration problem are treated here as operating systems. Agentless and command-line inventory cover locked-down machines, standalone inventory covers air-gapped and offline systems, and non-persistent VDI is supported directly. Duplicate system detection and stale device archiving keep the record honest as it ages.

Against missing attributes: the fields the audit turns on. Processor types and core factors, cluster and virtualisation awareness for SQL Server and Windows Server core licensing, IBM PVU and Virtual Processor Core metrics with an ILMT connector and compliance gap analysis, and Oracle options and packs reported with evidence and an override. Connectors read VMware, Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix, so virtualisation is interpreted from the platform rather than inferred from the guest.

Against unprovable entitlement: a repository that is part of the position. Licences, transactions, agreements, maintenance, suppliers and publishers are held in one place, with assignment by device, processor or core, Microsoft Licence Statement import, volume, retail, OEM and FPP transaction capture, subscription expiry tracking, and purchase order and invoice capture. The effective licence position — purchased, used, available, required, variance, exposure — is computed continuously from that entitlement against real inventory, rather than assembled the week the audit letter arrives.

On the question of whether the evidence survives contact with a publisher: Certero is verified by Oracle License Management Services, which means Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.

The point

No tool will honestly promise you perfect discovery, and you should be wary of one that does. What you can reasonably demand is that every method reports into one model, that the difficult platforms are covered natively rather than excluded, that the attributes licensing actually depends on are collected correctly, and that your entitlement sits somewhere you can produce it from under pressure.

Get those four right and IT asset identification stops being the thing that delays every other decision.

Book a demo, or read more about CerteroX ITAM and CerteroX SAM.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.