Skip to content

IT asset discovery: the critical features your tool must have

A clean discovery report is not the same as a complete one. What separates real asset discovery from device administration, and the four checks that tell you whether your current tooling is missing things.

The cost of poor visibility is rarely obvious. Until it is.

An organisation believed its environment was fully covered. The discovery tool was running. The reports looked clean. Then a software audit turned up a handful of devices and applications nobody could account for. No record, no classification, no alerts. They were not threats. They were gaps. That was enough to shake confidence across the whole team.

This is more common than most CIOs would expect. When you have spent since 2007 helping organisations defend against software vendor audits, you become acutely aware of how expensive a small gap becomes. As infrastructure changes, the risk of falling behind grows with it.

Good data beats a good interface

It is easy to be drawn in by a polished UI, or by the apparent simplicity of an ITAM tool with out-of-the-box workflows that guide you through managing your environment.

A strong interface that helps people make safe decisions is essential. But it is worth asking whether the data underneath it is actually any good. Poor data inside an automated or over-simplified system does not reduce risk. It accelerates it, because now the wrong answer arrives faster and with more confidence attached.

MDM is not asset management

The way end-user devices are administered has changed. Mobile device management tools such as Microsoft Intune have become a straightforward way to support enrolled Windows machines, not just phones.

That is genuinely valuable for supporting individual devices through the active parts of their lifecycle. But administering devices you already know about, and which have already been enrolled, is not the same as discovering systems. It is not the same as managing the risk and cost of hardware and software across the entire asset lifecycle, at volume.

The distinction matters most at the edges: the machines nobody enrolled, the servers finance bought directly, the Unix frames that were never in scope for the MDM project in the first place.

Static discovery does not fit dynamic environments

Legacy tools give you point-in-time visibility. The pace of change is not point-in-time.

Teams end up dealing with assets that appear and disappear unnoticed, alerts that arrive late, manual work that eats days, and several tools presenting different versions of the truth. The result is a layer of noise and — more worryingly — a false sense of security.

Discovery is a strategic capability, not a housekeeping task

Are mergers and acquisitions part of your business strategy? If so, being able to discover and assess risk across a newly acquired environment quickly should be near the top of your requirements list.

The faster you understand the hardware and software you have just inherited, the faster it can be brought under policy, secured, governed and made useful.

What to actually look for

To close the gaps, prioritise tools that:

  • Discover changes automatically. Your ITAM tool should tell you what to manage, not wait for you to tell it.
  • Identify and classify rogue assets, so you can assess risk and prioritise rather than triage by hand.
  • Track change continuously, instead of relying on delayed scans.
  • Deploy with minimal effort, which is what shortens time to value.
  • Deliver audit-ready visibility with verified data that stands up to scrutiny.

None of that is aspirational. It is the baseline.

Four steps to review your current tooling

1. Check what is being missed

Run a gap analysis between real-time asset appearances and your existing discovery logs. Look specifically for devices that appeared and vanished without detection. That is where your current tool falls short, and it is the cheapest diagnostic you can run.

2. Review how classification works

Examine how your system categorises new or unknown devices. If your team spends time manually identifying and tagging assets, automation is missing. Automating classification saves time, but the bigger win is that it removes human error from a process that gets repeated thousands of times.

3. Move to continuous discovery

Evaluate tools that support event-driven or continuous scanning. These detect assets as they connect, disconnect or change, which eliminates the blind spots left by scheduled scans. Continuous visibility means you are not reacting to changes days or weeks after they happened.

4. Strengthen audit support

Audit requirements demand clarity as much as accuracy. Make sure your discovery tooling produces exportable, timestamped records with rich context for every asset. Where the publisher offers one, use a vendor-verified tool — it changes the nature of the conversation.

What this looks like when it ships

CerteroX ITAM was built against exactly this list.

Ten discovery methods land in one schema. Native agent, command-line inventory, agentless, standalone, Active Directory import, network scan, third-party ITAM import, cloud and SaaS connectors, browser monitoring and file metering. There is no reconciliation project afterwards, because there is nothing to reconcile.

Network Discovery sweeps a class-C subnet in under five seconds using NetBIOS, SNMP and ICMP, then probes to establish where an agent can actually be deployed. You find the machines before you own them — which is the M&A case above, in practice.

Six operating system families share one native agent: Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris. Agentless and command-line inventory cover locked-down machines; standalone inventory covers air-gapped and offline systems; non-persistent VDI is supported directly. The platforms most tools treat as an integration problem are treated here as operating systems.

Classification is automatic, not manual. The Software Recognition Database carries over 3.5 million titles with centrally maintained categorisation, publisher normalisation and version recognition. Software identification (SWID) tags carry UNSPSC classification. Duplicate system detection and stale device archiving keep the record honest over time, rather than letting it silt up.

Audit support is a first-class feature. Governance Policies work as compliance-as-code with a reusable filter builder — BitLocker enabled, Defender running, Azure VM tag hygiene — and the audit trail spans agreements, transactions and exclusions. On the vendor-verified point in step four: Certero is verified by Oracle License Management Services, which means Oracle’s audit team can accept data from Certero during an official audit, as an alternative to installing Oracle’s own measurement tools.

Visibility is not a checkbox. It is a capability.

When asset discovery keeps pace with your environment, everything downstream gets easier — security, compliance, daily operations, and possibly your sleep.

If your current tool does not give you this level of insight, it is worth looking at what else is available.

Book a demo, or read more about CerteroX ITAM.

Related reading

Other posts covering the same ground.

  • Device-based licensing and access control

    Locking an application down at user level does not make you compliant with a per-device licence. In a Citrix or RDS environment, one user with access can cost you a licence for every device in the organisation.

    • ITAM
    • SAM
    • Governance
    4 min
  • Gartner Myth Buster – Part 1

    A third-party summary of a vendor can be wrong, and it stays wrong for as long as people read it. The case for checking a vendor's facts at source — and the current, sourced record for Certero.

    • ITAM
    • SAM
    • Governance
    7 min
  • The role of good data in software audits

    An audit is won or lost on the quality of your inventory long before the letter arrives. Six ways data goes wrong, and what it takes to have the answer already in hand.

    • ITAM
    • SAM
    • Governance
    8 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.