Skip to content

Getting More From Your Microsoft SCCM Investment

SCCM is good at what it was built for and was never built for software asset management. You do not have to throw it away to close the gap — but you do have to know precisely where the gap is.

Microsoft SCCM — now Microsoft Configuration Manager, and part of the Microsoft Intune family, though almost nobody calls it that in conversation — is offered free or heavily discounted to volume licensing customers. That makes it an obvious default for discovery, inventory and software distribution, and it does those jobs perfectly well.

The problem starts when it is asked to underpin software asset management, which is not what it was designed for. This piece is about where those gaps sit and how to close them without discarding an investment you have already made and a team that already knows the product.

What SCCM is for

Configuration Manager is a systems management product. Its core purpose is discovering Windows devices, inventorying their hardware and software, and deploying and removing software on them. Within that boundary it is capable and widely deployed, and a lot of organisations run it competently.

Software asset management asks different questions. Not “what is installed” but “what is installed, what is being used, what does the licence metric actually count, and what does that make our position”. The gap between those two sets of questions is where the audit findings live.

Processor and core information

SCCM gathers processor detail through WMI. That is fine when the reporting operating system understands the hardware underneath it, and less fine when it does not — older operating systems running on newer processors can report core and socket counts inaccurately, and the same applies where the reported topology does not reflect what a hypervisor is actually presenting.

For most purposes an approximate core count is harmless. For Oracle and IBM it is not. Both license significant products per processor or per core, with core factors and sub-capacity rules applied on top, so an error in the underlying count propagates straight into a compliance figure. That is the kind of discrepancy a publisher’s audit team finds quickly, and it is difficult to argue with once it is on the table.

Software metering and reporting

SCCM can monitor software usage. It is not, however, something you switch on and read the next morning.

Configuring metering properly needs someone who knows the product well, which means either an existing specialist’s time or an external one’s day rate. Data does not appear immediately — you configure, then you wait. And when it arrives, the output is raw. It is structured for a technical audience and it takes expertise to interpret.

That creates a second problem downstream. The people who need to act on software usage — procurement, finance, the licence manager, whoever owns the renewal — generally cannot get at it themselves. They ask the SCCM specialist for a report, wait, and get something built to someone else’s mental model. Decisions get made slowly or on instinct. It is common enough for organisations to buy a separate reporting product purely to turn SCCM’s output into something a non-specialist can read, which is a strange thing to have to do.

Non-Windows hardware and software

This is where the picture has changed most since this article was first published, and not in the direction anyone expected.

In 2016 it was reasonable to say Configuration Manager was strong on Windows and improving elsewhere — Mac, UNIX and Linux clients existed and were getting attention. Microsoft has since withdrawn them. Linux and UNIX client support was deprecated in 2018 and removed in version 1902; macOS client support was removed on 31 December 2022, with Intune given as the migration path (Source: Microsoft Learn, removed and deprecated items for Configuration Manager clients).

So the non-Windows gap is not narrowing. It is now structural, and it is where a large share of licence value sits.

Oracle is the clearest case. Database and middleware deployments — the products with the highest per-unit exposure of anything most organisations run — are largely invisible. That is not a small blind spot; it is the single most expensive one available.

IBM is similar in kind. There is limited product information, and PVU values still have to be established by hand, which is slow and inherits the processor-accuracy problem above. Software on AIX, HP-UX, Solaris, Linux and macOS is installed, packaged and registered differently from Windows software, and a tool built around the Windows model does not read it reliably.

The practical consequence is that a second inventory source is required for anything that is not Windows. You cannot manage what you cannot see, and the things you cannot see are disproportionately the things that cost the most.

Clusters, hosts and virtualisation

Virtualisation makes licensing harder in a specific way: what you owe often depends not on the virtual machine but on the physical host underneath it, the cluster it can move around, and the hypervisor’s rules about where it is allowed to run.

Configuration Manager does not reliably identify hosts running VMware or Citrix hypervisors, or resolve the cluster relationships between them. Without that topology, any measurement of software across a virtualised environment is a guess with a plausible-looking number attached. For anything licensed per processor or per core, the guess is usually wrong in the publisher’s favour.

Closing the gap without starting again

You made an investment in SCCM. It works for the jobs it was built for, your team knows it, and replacing it is not a project anyone wants. You do not have to.

CerteroX ITAM includes an SCCM interface that imports SCCM data and can drive SCCM applications, packages and jobs from the same console — so existing distribution work continues where it is, rather than being duplicated somewhere new. It sits alongside twenty-seven other named system connectors, including Active Directory, Intune, WSUS, VMware, Hyper-V, Citrix XenServer, IBM HMC, Oracle VM, Red Hat oVirt and Nutanix, so the virtualisation topology is resolved rather than inferred.

The non-Windows gap is closed at source rather than by import. The native inventory agent covers Windows, macOS, Linux, IBM AIX, HP-UX and Oracle Solaris — six operating system families, one agent, one schema. Where an agent cannot be deployed, there is agentless and command-line inventory, and standalone inventory for air-gapped systems.

On recognition, inventory is resolved against the Software Recognition Database — 3.5 million-plus titles, centrally maintained, with release date, end-of-support and extended-support dates attached. That is the difference between a list of executable names and a normalised publisher-and-product record you can license against.

On usage, AppsMonitor meters at file level with first-used and last-used tracking and a percentage-used figure over a rolling 90-day window, without a configuration project first. Reporting is available to the people who need it through role-shared dashboards, threshold alerts and a read-only API with a documented Power BI data source — so the licence manager does not have to queue behind the SCCM specialist to find out what is being used.

And on the two publishers SCCM is weakest against, CerteroX SAM has dedicated engines rather than generic handling. For Oracle: options and packs with evidence and override, processor types and core factors, licence pools with hosting rights, cover-down logic for Enterprise Edition, and E-Business Suite responsibilities. Certero is a verified third-party tool vendor with Oracle License Management Services, which means Oracle’s audit team can accept data from Certero during an official audit as an alternative to installing Oracle’s own measurement tools. For IBM: PVU and Virtual Processor Core metrics, an ILMT connector with compliance gap analysis, Component Resolution that matches deployed components to products with a scored suggestion, and enforcement of the 30-minute inventory cycle that sub-capacity licensing actually requires.

The summary

SCCM is a good systems management product being asked, in a lot of organisations, to be a software asset management product as well. It is not one, and the places where it falls short — processor detail, usable usage data, non-Windows platforms, virtualisation topology — are precisely the places where licence exposure concentrates.

Keep it for what it does. Put something underneath it that answers the licensing questions properly.

If you want to see SCCM data alongside a full non-Windows inventory and a licence position that recomputes as inventory and entitlement land, book a demo.

Related reading

Other posts covering the same ground.

  • Why good IT asset discovery is essential for SAM

    Most SAM programmes are built on Active Directory and an agent deployment, which means they are built on a list that is already wrong. Discovery is not a preliminary step to software asset management — it is the foundation the rest of it stands on.

    • ITAM
    • SAM
    5 min
  • Overcoming the Weaknesses of SCCM Software Recognition

    SCCM can tell you a file exists on a disk. It cannot tell you whether the application was installed, whether it belongs to a suite, or which edition you are running — and every one of those decides what you owe.

    • ITAM
    • SAM
    5 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.