This message was deleted.
# _general
s
This message was deleted.
e
Defender / Defender Cloud
k
On what front? PC/Laptops? What OS? etc etc
d
Every front. Basically a company inventory so that if requested we can easily generate a report for all our hardware/software/patch status Many years ago I used lansweeper but not sure if there is something else that people like
s
We currently use Kaseya VSA for monitoring, reporting, auditing, patch management & remote support, but are investigating alternatives. Some stuff it does really well. Other stuff...
r
Have you looked at the features of your monitoring tools. we (eG Innovations) have a load of configuration tracking features that folks find suitable for this type of need. Monitoring tools have to track changes and configuration anyway - otherwise it doesn't make a lot of sense if configurations change and if you don't know something has changed you can't find the root-cause. You may have already got this in-house if you have monitoring in place. These features are usually restricted by RBAC to admin roles - e.g. as an admin I see this
So I can pull up reports like
And yes - Lansweeper is dedicated asset management and discovery tool, with a lot of value baked on top by ensuring it's outputs are fluffed up and integrate into ITIL frameworks and practices. It's very useful for those responsible for compliance and audit etc to do their paperwork and it also has lifecycle planning tools for hardware etc (which is where the monitoring vendors tend to stop). If budget is no problem it's probably the solution I've seen most in enterprise.
k
eG can do infra as well (hence why I asked for the scope)
d
@Kees Baggerman thought I answered the scope question? Everything within the domain needs to be easily reported on at will. Servers, laptops, pc, etc. @Rachel Berry does EG Innovations require a client to be installed on devices?
k
Oh you did @Danny no worries! Some products might just do more than you need or not enough 🙂
r
I think it depends on what is monitored and how there's a mixture of agented and agentless approaches. For physical desktops (laptops) there's a lightweight agent that pulls off data like WiFi, ISP latency. It's not per se an inventory solution like lansweeper (nobody buys a monitoring solution for the configuration change tracking - not sure I've ever heard a customer ask about until actually in production) so you'd have to talk one of the solutions guys to see if it would capture everything (LanSweeper exposes things like EOL dates iirc). But you must have something in place at the moment monitoring stuff and most monitoring products have these features tucked away somewhere - we have a feature called a "compliance check" that lets you reference a configuration as a kind of golden template and it'll go find everything of the same type which differs, and you can compare systems for differences... if you are monitoring you probably have agents etc deployed where needed already. I suspect that's one reason customer use rather than a dedicated inventory solution as it's free and means can avoid talking to security team.
There's a screenshot of the type of info change tracking is really meant for (figure 13) in https://www.eginnovations.com/blog/configuration-change-tracking/
d
Thank you! Will look into this and let you know!