Author: admin

  • Why Track Your IT Assets?

    Why Track Your IT Assets?

    When your business has a handful of laptops, remembering who has what is simple. Once you pass 20 or so devices, it becomes hard. Past 50, it becomes guesswork.

    A spreadsheet helps for a while, but it only works if someone updates it every time a device changes hands. In most small businesses, that does not happen.

    What Goes Wrong Without Tracking

    Lost devices stay lost. If you do not know a laptop exists, you will not notice it is missing. Devices get left behind at client sites, taken home and forgotten, or simply shelved in a cupboard. Without a register, there is nothing to check against.

    You pay for software you do not use. Software subscriptions are billed per user. If you do not track who has which licence, you keep paying for former employees and for staff who never log in. This is one of the most common ways small businesses waste money on IT.

    No one knows who has what. When someone leaves the company, someone has to collect their laptop, phone, and any peripherals. If there is no record of what was issued, items slip through the cracks. A monitor stays at home. A phone gets sold on. The next person to join has to buy new equipment instead of reusing what you already have.

    Audits become painful. Software vendors do audit their customers, including small ones. If Microsoft or Adobe asks you to prove how many licences you have and where they are deployed, you need records. Without them, you may end up buying licences you already own or paying penalties for ones you cannot account for.

    Security gaps go unnoticed. A laptop that no one is tracking is a laptop no one is securing. It will not get updates. It will not get wiped when it should be. If it had access to company email or files, that access stays open.

    What Good Tracking Looks Like

    You do not need expensive software to start. A simple register with the following columns is enough for most small businesses:

    • Device name or asset tag
    • Type (laptop, phone, monitor, switch)
    • Make and model
    • Serial number
    • Assigned to (person or location)
    • Date issued
    • Status (in use, in storage, disposed)

    The point is to have one place where you can answer the question “where is this device, and who is using it?” If you cannot answer that in under a minute, you are already losing track.

    Practical Takeaways

    • If you have more than 20 devices, move beyond a spreadsheet you update only when you remember.
    • Keep a single record of every device, who it is assigned to, and its status.
    • Review the register when someone joins or leaves, not once a year.
    • Include software subscriptions in your tracking, not just hardware.

    Tracking your IT assets is not about having the fanciest tool. It is about being able to answer basic questions about your own equipment. If you cannot, you are already paying for it in one way or another.

    What this looks like in practice

    Google Workspace: Without tracking, you don’t know how many Chromebooks you’ve bought this year. Gmail has the purchase emails, but who’s reading them? AssetGraph catches “12 Chromebooks at £449 each” and logs them automatically.

    Microsoft 365: Without tracking, you’re paying for Microsoft 365 seats that nobody uses. Outlook has the invoices, but nobody checks them. AssetGraph reads “25 Business Premium seats, £438.75/month” and flags the 6 that have zero sign-ins.

    The data is already in your inbox. AssetGraph just makes it visible.

  • What to Do When a Laptop Is Lost or Stolen

    What to Do When a Laptop Is Lost or Stolen

    A lost or stolen laptop is stressful, but the steps to handle it are straightforward. The key is to act quickly and follow a checklist rather than trying to remember everything in the moment.

    Step 1: Report It Internally

    Tell the person responsible for IT, or the business owner if you do not have an IT role. The sooner it is reported, the sooner the rest of the steps can happen.

    Do not wait to see if the laptop turns up. Treat it as gone until it is found.

    Step 2: Remote Lock or Wipe

    If you use mobile device management (MDM) software such as Microsoft Intune, Jamf, or Google Workspace device management, you can lock or wipe the laptop remotely.

    • Lock the device first. This stops anyone from accessing it without a passcode.
    • Wipe if the device contained sensitive data and you are confident it will not be recovered.

    If you do not have MDM, skip to Step 3. You cannot remotely secure a device that was not set up for it.

    Step 3: Change Passwords

    Assume that anyone with the laptop can access any accounts that were logged in on it. Change passwords for:

    • Email accounts
    • Company file storage (OneDrive, Google Drive, Dropbox)
    • Accounting software
    • CRM systems
    • Any cloud service the user was signed into

    If the laptop had saved passwords in a browser, treat all of those accounts as compromised and change them.

    Step 4: Check What Data Was on the Device

    Work out what the laptop had access to:

    • Were there client files stored locally?
    • Was there access to financial records?
    • Were there saved credentials for cloud services?

    If sensitive client or financial data was on the device, you may need to notify affected parties. If the laptop was encrypted, the risk is lower. If it was not, assume the data is accessible.

    Step 5: Notify Your Insurer

    If the laptop is covered under your business insurance policy, contact your insurer to start a claim. You will need:

    • The make, model, and serial number
    • The purchase date and cost
    • A description of what happened
    • A crime reference number if it was stolen (report it to the police first)

    Step 6: Update Your Asset Register

    Mark the device as lost or stolen in your asset register. Record the date, what happened, and what actions you took. This matters for insurance, for audits, and for making sure the device is not still counted as an active asset.

    Step 7: Replace and Improve

    Once the immediate situation is handled, think about preventing it happening again:

    • Set up MDM on all company devices if you have not already.
    • Make sure all laptops require a password or PIN to unlock.
    • Enable disk encryption on every device (BitLocker on Windows, FileVault on Mac).
    • Keep a record of serial numbers so you can report them if needed.

    Practical Takeaways

    • Act immediately. Do not wait to see if the device turns up.
    • Lock or wipe remotely if you have MDM.
    • Change passwords for any accounts that were accessible on the device.
    • Report to the police and your insurer if it was stolen.
    • Update your asset register so the device is no longer listed as in use.
    • Put encryption and MDM in place to reduce the impact if it happens again.

    What this looks like in practice

    Google Workspace: A Chromebook goes missing. AssetGraph pulls the serial number from the original Gmail purchase email, checks Google Admin for the last known user and sync time, and alerts the assigned user’s manager. All in under 30 seconds.

    Microsoft 365: A Surface Pro is reported lost. AssetGraph pulls the serial number from the Outlook purchase email, checks Intune for the last sync and compliance status, and can trigger a remote lock. The full chain of custody – who had it, when, and what happened – is in the audit trail.

    The purchase email, the device record, and the user assignment are all connected automatically.

  • What is Passive Asset Discovery?

    What is Passive Asset Discovery?

    Keeping track of IT assets has always been a challenge. Organisations accumulate laptops, servers, mobile devices, cloud instances, and software subscriptions faster than anyone can reasonably document them. For years, the answer was a spreadsheet maintained by a diligent IT administrator – an approach that works until the moment it doesn’t. Passive asset discovery offers a fundamentally different model: instead of asking people to record what exists, you let your existing systems tell you automatically.

    Active vs Passive Discovery

    To understand passive discovery, it helps to contrast it with active discovery.

    Active discovery involves scanning your network to find devices. Tools send ping requests, SNMP queries, or agent-based probes across IP ranges and report back what responds. Active discovery is useful, but it has limitations: it only finds devices that are powered on and reachable during the scan window, it can generate unwanted traffic on sensitive network segments, and it tells you very little about who owns a device or what software runs on it.

    Passive discovery takes a different approach. Rather than probing the network, it collects asset data from the systems you already operate – management platforms, identity providers, endpoint security tools, and cloud consoles – through their APIs. Because these platforms continuously record information as part of their normal operation, the asset data they expose is always current without any additional scanning.

    The two approaches are complementary. Many organisations use passive discovery as their primary source of truth and supplement it with occasional active scans for validation. But for day-to-day asset tracking, passive collection is where the bulk of useful, accurate data comes from.

    Where the Data Comes From

    Modern IT estates generate asset information as a by-product of their normal operation. The key is knowing where to look.

    ### Microsoft Graph

    For organisations using Microsoft 365, Microsoft Graph is a rich source of endpoint data. Intune-managed devices, Entra ID (formerly Azure AD) registered machines, and user-to-device relationships are all queryable through a single API. You can retrieve device compliance status, operating system versions, and the user each device is associated with – without installing any additional agents.

    ### Mobile Device Management

    Whether you use Microsoft Intune, Jamf, or VMware Workspace ONE, your MDM platform already knows every enrolled device, its hardware model, serial number, and enrolment status. Polling the MDM API gives you a continuously updated device list that reflects joiners, leavers, and hardware refreshes automatically.

    ### Endpoint Detection and Response

    EDR tools such as Microsoft Defender for Endpoint, CrowdStrike, and SentinelOne maintain a real-time view of every agent reporting in. An EDR-managed device that stops reporting is often the first sign of a lost, stolen, or decommissioned machine – long before anyone updates a spreadsheet.

    ### Cloud Providers

    AWS, Azure, and Google Cloud all expose inventories of running instances, storage volumes, and network interfaces through their management APIs. Because cloud resources are created and destroyed constantly, automated polling is the only practical way to maintain an accurate record.

    ### Identity Providers

    Your identity provider – Entra ID, Okta, or similar – knows which users exist, which groups they belong to, and which applications they are licensed for. This is invaluable for software asset management, as it lets you tie licences to real people rather than purchase orders.

    Why It Replaces Manual Tracking

    Manual spreadsheet tracking suffers from well-understood problems:

    • Stale data. A spreadsheet is a snapshot from the moment it was last edited. The moment a laptop is reassigned or a virtual machine is spun up, the record is out of date.
    • Single point of failure. One person owns the file. When they are on holiday, no one updates it.
    • No audit trail. Spreadsheets do not record who changed what, or when. For compliance purposes, that is a significant gap.
    • No reconciliation. There is no automatic way to detect that a device listed in the spreadsheet no longer reports to your MDM, or that a user has three SaaS licences assigned when their role only requires one.

    Passive discovery addresses all of these. Data is refreshed continuously by automated polling, multiple authorised users can access a shared source of truth, and every change is logged by the systems that reported it. The audit trail is built in.

    Practical Benefits

    The most immediate benefit is accuracy. When asset records are populated from the systems that actually manage those assets, the data is correct by construction. A laptop that Intune reports as compliant is, by definition, the laptop Intune manages – there is no transcription step where errors creep in.

    A second benefit is coverage. Passive discovery naturally captures assets that manual tracking tends to miss: the developer who created a cloud instance outside the normal procurement process, the contractor enrolled in the MDM but never added to the asset register, the software trial that became a paid subscription and was never cancelled.

    A third benefit is timeliness. Because APIs return current state on every poll, you detect changes – a device going offline, a licence being assigned, an instance being terminated – within the polling interval rather than at the next quarterly audit.

    What Passive Discovery Does Not Do

    Passive discovery is powerful, but it is not a complete answer on its own. It depends on the systems it queries being properly configured. A device that was never enrolled in MDM, never had an EDR agent installed, and was never registered in the identity provider will not appear in any API response. No amount of passive polling will find it.

    For this reason, mature asset management programmes combine passive discovery from authoritative sources with periodic active scanning as a safety net. The passive data provides the rich, detailed, continuously updated register; the active scan confirms that nothing has slipped through the gaps.

    Getting Started

    If you are new to passive discovery, start by inventorying the systems you already operate that expose asset data. For most organisations, the most valuable sources are:

    1. Your identity provider, for users and licences 2. Your MDM, for managed devices 3. Your EDR, for endpoint coverage 4. Your cloud provider APIs, for infrastructure

    You do not need to connect all of them at once. A common starting point is the identity provider and MDM, since together they give you a view of users, devices, and software that covers the majority of an organisation’s estate. From there, you can layer in additional sources as your needs grow.

    Passive asset discovery is not a single tool or product. It is an approach – one that replaces the fragile, manual habits of the past with a data pipeline that runs itself. For any organisation managing more than a handful of devices, it is the foundation of accurate, audit-ready asset management.

    What this looks like in practice

    Google Workspace: AssetGraph reads your Gmail for purchase confirmations like “Chromebook model XYZ shipped” and pulls device data from Google Admin – every managed Chromebook, phone and tablet assigned to your team.

    Microsoft 365: AssetGraph scans Outlook for emails like “Surface Pro 9 ordered, serial #XYZ123” and pulls device data from Intune – every Windows laptop, Surface and mobile enrolled in your tenant.

    No manual data entry. No spreadsheets. The asset register builds itself from the tools you already use.

  • What Counts as an IT Asset?

    What Counts as an IT Asset?

    Most people think of IT assets as laptops and desktops. In practice, the list is much longer. If your business pays for it, relies on it, or would have a problem without it, you should be tracking it.

    Here is a practical breakdown of what counts.

    Hardware

    These are the physical devices your business owns or leases.

    • Laptops and desktops – the most obvious category. Note the serial number, who it is assigned to, and the purchase date.
    • Phones – company mobiles are easy to lose track of, especially when staff leave.
    • Tablets – often bought for specific purposes and then forgotten in a drawer.
    • Servers – whether on-premises or in a rack somewhere, these need tracking for warranty and maintenance purposes.
    • Network equipment – switches, routers, access points. These are easy to overlook because no single person uses them, but they are expensive to replace and disruptive when they fail.

    If it has a serial number and a cost, it belongs on your asset register.

    Peripherals

    These are lower in value individually but add up across a business.

    • Monitors – often stay with a desk rather than a person, which means they get missed when someone leaves.
    • Docks and adapters – small, easily lost, and frequently reordered because no one knows where the existing ones are.
    • Keyboards and mice – low cost, but worth listing if you buy them in bulk.

    Peripherals do not need the same level of detail as laptops, but a simple count per location saves reordering things you already own.

    Software and Subscriptions

    This is where most small businesses lose money through poor tracking.

    • Microsoft 365 or Google Workspace – billed per user. If you do not remove licences when people leave, you keep paying.
    • Design and creative tools – Adobe Creative Cloud licences are a common source of wasted spend.
    • CRM and project management tools – Salesforce, HubSpot, Monday, Asana. Each is billed monthly per user.
    • Accounting software – Xero, QuickBooks, and similar.
    • Communication tools – Slack, Zoom, Teams add-ons.

    Track each subscription, how many seats you have, how many are in use, and the renewal date.

    Cloud Accounts

    If your business uses cloud infrastructure, these accounts are assets too.

    • AWS, Azure, or Google Cloud – track the account, who has admin access, and what it costs per month.
    • Domain registrations – easy to forget until a domain expires and your website goes offline.
    • SSL certificates – these expire and need renewal.

    Why Each Category Matters

    Hardware matters because it costs money to replace and is easy to lose. Peripherals matter because the cumulative cost of reordering them adds up. Software matters because you pay for it every month whether you use it or not. Cloud accounts matter because they hold your data and your billing.

    Practical Takeaways

    • Do not limit your asset register to laptops. Include phones, network equipment, and peripherals.
    • Track software subscriptions separately, with seat counts and renewal dates.
    • List cloud accounts and domains so nothing expires without warning.
    • A complete register means you can answer “what do we own and what do we pay for?” without guessing.

    What this looks like in practice

    Google Workspace: Chromebooks (hardware, from Google Admin), Google Workspace licences (software, from Gmail invoices like “12 Business Standard seats at £9.60/seat/month”), and Google Drive storage (cloud resources) – all tracked as assets.

    Microsoft 365: Surface Pros (hardware, from Intune), Microsoft 365 Business Premium licences (software, from Outlook invoices like “25 seats at £17.55/seat/month”), and Azure cloud resources (from billing emails) – all in one register.

    Hardware, software, cloud – if it costs money and someone uses it, it’s an asset worth tracking.

  • Understanding Asset Lifecycle and Operational States

    Understanding Asset Lifecycle and Operational States

    A common mistake in asset tracking is to treat an asset’s status as a single value. A spreadsheet column headed “Status” might contain values like “active”, “offline”, “in repair”, or “retired” – a mix of concepts that answer different questions. Is the device still in service? Is it currently powered on? Is it broken? Conflating these into one field produces ambiguity and makes the asset register harder to use. The solution is to separate two distinct dimensions: lifecycle state and operational state.

    Two Different Questions

    Lifecycle state answers the question: where is this asset in its relationship to the organisation? It tracks the asset from acquisition through active use, through any maintenance periods, to final retirement and disposal. Lifecycle state changes relatively infrequently – a laptop might be active for three years before being retired.

    Operational state answers the question: what is this asset doing right now? It tracks whether the asset is online, offline, degraded, or unresponsive at the current moment. Operational state changes frequently – a laptop that is online today might be offline tonight, and back online tomorrow morning.

    These are independent dimensions. An asset can be in the “active” lifecycle state but currently “offline”. It can be “in maintenance” and “online”. It can be “retired” and therefore have no operational state at all. Treating them as separate fields, rather than one combined value, gives a clearer and more useful picture of the estate.

    Lifecycle States

    A practical lifecycle model typically includes the following states:

    ### Procured

    The asset has been purchased or otherwise acquired but not yet deployed. It exists in the organisation’s records but is not in use, capturing devices in transit, in stock, or awaiting configuration.

    ### Active

    The asset is deployed and in use. This is the normal steady state for the majority of an estate’s lifespan. An active asset is expected to report to its management systems, though it may be temporarily offline at any given moment.

    ### In Maintenance

    The asset is undergoing planned maintenance, repair, or upgrade. It is still owned and expected to return to active use, but is temporarily not in normal service. This state explains why a device might be offline without triggering an incident alert.

    ### Retired

    The asset has been decommissioned and is no longer in use. It may still physically exist – awaiting disposal, data wiping, or return to a leasing company – but is not part of the active estate. Retired assets should remain in the register for audit purposes.

    ### Disposed

    The asset has been physically disposed of or returned. The record remains for audit and compliance, but the asset is gone. This is the terminal lifecycle state.

    Transitions between these states should be recorded with timestamps. The resulting lifecycle history – when the asset was procured, when it went active, when it was retired – is exactly what compliance auditors look for under frameworks like ISO 27001 (Annex A.8.1) and ITIL asset management processes.

    Operational States

    Operational state reflects the asset’s current technical condition, as reported by whichever management system observes it:

    ### Online

    The asset is reachable and reporting normally. For a laptop, this means the MDM or EDR agent has checked in recently. For a cloud instance, it means the instance is running and responding to health checks.

    ### Offline

    The asset is not currently reachable. This does not necessarily mean there is a problem – a laptop can be offline simply because it is powered off outside working hours. The key is the expected behaviour: an asset that is expected to be online but is offline may warrant investigation.

    ### Degraded

    The asset is online but not fully functional. This might mean a cloud instance that is running but failing health checks, an endpoint with an EDR agent that has stopped updating, or a device reporting errors. Degraded state is a signal that something needs attention, even though the asset has not failed entirely.

    ### Unknown

    The asset’s operational state cannot be determined. This happens when no management system has reported on the asset recently, or when reports conflict. Unknown state is itself actionable – it usually means an agent has been removed, a device has been factory-reset, or the asset has fallen out of management entirely.

    Why the Distinction Matters

    Consider a laptop assigned to a remote worker. Its lifecycle state is “active” – a deployed, owned asset. Its operational state might be “offline” because the worker closed the laptop for the evening. Neither indicates a problem. An asset tracking system that uses a single status field has no clean way to represent this. If “offline” is recorded as the status, it looks like the asset might be lost or broken. If “active” is recorded, it conceals the fact that the device is currently unreachable.

    Now consider a laptop whose lifecycle state is “active” and whose operational state has been “unknown” for two weeks. This is a meaningful signal. The device may have been lost, stolen, or had its management agent removed. The lifecycle state has not changed – it is still an active, owned asset – but the operational state reveals that something requires investigation.

    Separating the two dimensions also improves alerting. A sensible policy might be: notify the asset owner if an active asset’s operational state is “degraded” or “unknown” for more than 48 hours. This is straightforward to implement when lifecycle and operational state are separate fields, and nearly impossible to express when they are conflated into a single value.

    Implementation Guidance

    To implement this model in practice:

    1. Use separate fields. Every asset record should have a `lifecycle_state` field and an `operational_state` field, each with its own allowed values. 2. Derive operational state from source systems. Operational state should be determined automatically from management systems. If the EDR last checked in within the expected interval, the state is “online”; otherwise “offline” or “unknown” depending on how long it has been. 3. Manage lifecycle state deliberately. Lifecycle transitions should require an explicit action – a person or workflow marks an asset as retired, disposed, or in maintenance. They should not change automatically from operational state, because a device going offline does not mean it has been retired. 4. Record transitions. Both state changes should be logged with timestamps. Lifecycle history supports compliance audits; operational state history supports incident investigation and trend analysis. 5. Define expected operational behaviour per asset. Some assets are expected to be online continuously (servers); others only during working hours (user laptops). This determines when an offline state should trigger an alert.

    Reporting Across Both Dimensions

    With both dimensions tracked, reporting becomes more powerful. You can answer questions like: how many active assets are offline for longer than expected, which assets have been in maintenance beyond the agreed window, how many retired assets are awaiting disposal, and the average time an asset spends in each lifecycle state before transitioning.

    These are the questions IT, finance, and compliance stakeholders actually need answered. A single status field cannot support them. Two well-designed fields can.

    Separating lifecycle and operational state is a small design decision that pays off every day the asset tracking system is in use. It reduces false alarms, improves audit evidence, and gives everyone who consults the register a clearer view of what is actually happening across the estate.

    What this looks like in practice

    Google Workspace: A Chromebook arrives – Gmail catches the purchase email. Google Admin shows it enrolled – status: Active. Six months later, the user leaves – Google Admin shows account deactivated – status: Needs Recovery. AssetGraph alerts IT to collect it.

    Microsoft 365: A Surface Laptop is ordered – Outlook catches “Surface Laptop 5, serial #ABC123”. Intune shows it enrolled and compliant – status: Active. When a user leaves, Entra ID shows the account removed – AssetGraph flags the device as Unassigned and alerts IT.

    Every state change is automatic, timestamped and logged for audit.

  • SaaS Licence Optimisation: Reducing Software Waste

    SaaS Licence Optimisation: Reducing Software Waste

    Software-as-a-service has transformed how organisations buy and use software, but it has also introduced a problem that few anticipated: invisible, persistent waste. Unlike on-premises licences, which were typically bought once and tracked carefully, SaaS subscriptions are easy to purchase, easy to forget, and easy to leave running indefinitely. This article explains the problem of SaaS sprawl, how to identify waste, and the practical steps to reclaim unused licences.

    The Problem of SaaS Sprawl

    A typical mid-sized organisation now uses dozens, sometimes hundreds, of SaaS applications. Marketing teams buy survey tools, design teams subscribe to prototyping platforms, developers spin up cloud-based databases, and every team seems to acquire its own project management tool. Procurement is often bypassed entirely; many SaaS vendors accept corporate cards and require nothing more than an email address to start a trial.

    The result is sprawl: more applications than anyone is aware of, paid for through multiple cost centres, with no central record of what is owned, who is using it, or whether it is still needed.

    SaaS waste takes several forms:

    • Unused licences. Seats assigned to users who never log in, often because they changed role or left the organisation.
    • Over-provisioned plans. Premium or enterprise tiers where the standard plan would suffice, retained from a time when the features were needed.
    • Duplicate tools. Two or more applications serving the same purpose, purchased by different teams unaware of each other’s choices.
    • Orphaned subscriptions. Applications still being billed after the project that justified them ended.

    The cost of this waste accumulates silently. Unlike hardware, which depreciates visibly on a balance sheet, SaaS spend is distributed across monthly invoices that individually look small but collectively represent significant, recurring expenditure.

    Tracking Seat Utilisation

    The first step in optimising SaaS spend is understanding actual usage. For each application in your estate, you need three pieces of information:

    1. Total licences purchased – the number of seats you are paying for. 2. Licences assigned – the number of seats allocated to named users. 3. Active usage – the number of users who have actually used the application in a defined period, typically 30 or 90 days.

    The gap between these figures is where waste lives. A plan with 100 purchased seats, 85 assigned, and 30 actively used has significant reclaimable waste.

    ### Getting the Data

    Most SaaS vendors expose usage data through admin consoles or APIs. The mechanisms vary:

    • Microsoft 365. The Microsoft Graph `/reports` endpoints provide usage data for Exchange, SharePoint, Teams, and other Microsoft 365 services, broken down by user and time period.
    • Google Workspace. The Google Workspace Admin SDK Reports API returns user activity for Drive, Gmail, and other services.
    • Salesforce. Login history and user record data reveal active vs inactive users.
    • Atlassian. The Jira and Confluence admin consoles expose active user counts, and the Atlassian REST API returns user and group details.

    Where a vendor does not expose usage data programmatically, single sign-on logs are a useful proxy. If a user has not authenticated to an application through your identity provider in 90 days, they are almost certainly not using it.

    Identifying Waste

    Once you have the data, apply consistent criteria to flag waste:

    • Unused seats. Licences assigned to users with no activity in the last 90 days.
    • Departed users. Licences still assigned to users who have left the organisation. These should be reclaimed immediately.
    • Role mismatch. Users with premium plans whose role does not require premium features. A finance administrator on a Salesforce enterprise licence when a professional licence suffices.
    • Duplicate subscriptions. Two applications of the same category where consolidating onto one would reduce spend.

    Prioritise reclamation by impact. A £50 per month licence assigned to a departed user is reclaimable today. A £200 per month premium plan downgrade affects a smaller number of users but yields more per reclamation.

    Reclaiming Licences

    Reclamation is the step where optimisation becomes real. Identifying waste produces reports; reclaiming licences produces savings. The practical process is:

    1. Validate. Before removing a licence, confirm with the user or their manager that it is genuinely unused. Some applications have legitimate seasonal or infrequent use. 2. Downgrade or remove. For unused seats, remove the licence assignment. For over-provisioned plans, downgrade to the appropriate tier. 3. Document. Record what was reclaimed, when, and why. This supports audit trails and provides a baseline for measuring future waste trends. 4. Notify. Inform affected users that a licence has been removed, and provide a clear route to request reinstatement if needed.

    Monitoring and Preventing Recurrence

    Optimisation is not a one-off exercise. Waste accumulates continuously as users change roles, join, and leave. An effective programme includes:

    • Scheduled reviews. Run usage reports monthly or quarterly, not annually. Waste identified in week four is reclaimable; waste identified in month twelve has already cost you eleven months of unnecessary spend.
    • Automated alerts. Configure alerts for departed users who still hold licences, so reclamation happens within days of a leaver date rather than at the next review.
    • Joiner and leaver workflows. Integrate licence assignment and removal with HR processes. When an employee leaves, their SaaS licences should be revoked automatically as part of the offboarding workflow.
    • Procurement controls. Require new SaaS subscriptions to be registered before they can be expensed. This does not prevent teams from choosing their own tools, but it ensures the organisation knows what is being bought and can track it.

    Measuring Success

    Track your optimisation programme with simple, honest metrics:

    • Total SaaS spend over time, per application and in aggregate.
    • Reclaimed licences per review cycle, and the corresponding cost saving.
    • Percentage of assigned seats actively used, per application.
    • Time between user departure and licence reclamation, as a measure of process responsiveness.

    These metrics make the value of the programme visible to finance and leadership, and they provide the feedback needed to refine the process. SaaS optimisation is a continuous discipline, not a project with an end date – but the savings it produces are real, recurring, and well worth the effort.

    What this looks like in practice

    Google Workspace: AssetGraph reads Gmail for emails like “Your Google Workspace renewal – 12 Business Standard seats, £145.20/month, renews 1st March”. It flags that 3 of those 12 seats haven’t logged in for 60 days – potential saving of £36.30/month.

    Microsoft 365: Outlook emails like “Microsoft 365 invoice – 25 Business Premium seats, £438.75/month” are captured automatically. AssetGraph cross-references with sign-in data and flags 6 seats with zero activity in 30 days – potential saving of £105.30/month.

    That’s £141.60/month of identified waste – £1,699/year – without opening a single spreadsheet.

  • Preparing for a Software Licence Audit

    Preparing for a Software Licence Audit

    Software audits are not just for large companies. Vendors audit small businesses too. Being ready is mostly a matter of keeping decent records.

    What a Software Audit Is

    A software licence audit is when a vendor checks whether the number of licences you have purchased matches the number you are actually using. If you are using more than you have paid for, you may have to buy additional licences. If you have paid for more than you use, you are unlikely to get a refund, but at least you will know.

    Audits are usually initiated by the vendor as part of their contractual right to verify compliance. Some are routine, others are triggered by a discrepancy in purchasing data.

    Which Vendors Commonly Audit

    The vendors most likely to audit are those with the most to lose from under-licensing:

    • Microsoft – audits Microsoft 365, Windows, and server products. Microsoft runs compliance checks regularly.
    • Adobe – audits Creative Cloud and Acrobat deployments, particularly in design and marketing firms.
    • Salesforce – checks user counts against contracted seats.
    • SAP and Oracle – less common in very small businesses, but they do audit mid-sized companies.

    If you use any of these, it is worth assuming you could be audited at some point.

    What They Ask For

    A typical audit request includes:

    • A list of all installations of the vendor’s software across your devices
    • Proof of purchase for each licence
    • The number of users assigned to each product
    • Access to run a scan or review your admin console

    The vendor may send a self-declaration form, or they may ask to run a discovery tool on your network. Either way, they want to compare what you have installed against what you have paid for.

    How to Prepare

    The best preparation is to keep records as you go, rather than scrambling when an audit notice arrives.

    Keep licence records. For every software purchase, store the invoice, the licence agreement, and the number of seats. This applies to both annual and monthly subscriptions.

    Track deployments. Know which devices or users have which software installed. If you use Microsoft Intune or Google Workspace, your admin console already holds this information. For desktop software, keep a manual list.

    Document purchases. If you buy licences through a reseller, keep the reseller invoices. If you buy direct, keep the order confirmations. Store them somewhere you can find them in a hurry.

    Review annually. Once a year, compare what you are paying for against what is actually deployed. This is the same process described in the article on cutting software costs, and it serves double duty here.

    What to Do If You Are Audited

    If you receive an audit notice:

    • Do not ignore it. Responding late makes things harder.
    • Nominate one person to deal with the vendor.
    • Gather your licence records and deployment data before responding.
    • If you find gaps, address them before the audit concludes. Buying the licences you are short on before the audit closes is usually better than waiting for the vendor to find the shortfall.
    • If the audit feels heavy-handed or you are unsure of your position, consider getting advice from an IT consultant or your reseller.

    Practical Takeaways

    • Keep invoices and licence agreements for every software purchase.
    • Track which users and devices have which software installed.
    • Review your licence position at least once a year.
    • If audited, respond promptly and nominate one person to handle it.
    • Being prepared means the audit is a paperwork exercise, not a crisis.

    What this looks like in practice

    Google Workspace: AssetGraph pulls licence data from Gmail invoices – “12 Business Standard seats at £9.60/seat/month” – and cross-references with Google Admin sign-in activity. You can show auditors exactly how many licences you have, how many are in use, and what each one costs.

    Microsoft 365: Outlook invoices like “25 Business Premium seats at £17.55/seat/month” are captured automatically. Intune confirms which devices are licensed. Every licence purchase, renewal and cancellation is in the audit trail with timestamps.

    Auditors want evidence, not spreadsheets. AssetGraph gives you a timestamped record of every licence and device, ready to export.

  • Using Microsoft Graph for IT Asset Tracking

    Using Microsoft Graph for IT Asset Tracking

    For organisations invested in the Microsoft ecosystem, Microsoft Graph is the single most valuable API for asset tracking. It exposes data from Intune, Entra ID, and Microsoft 365 through one consistent endpoint, giving you a real-time view of devices, users, applications, and compliance state without deploying additional agents. This article explains what Microsoft Graph is, which endpoints matter for asset management, and how to authenticate and query it in practice.

    What is Microsoft Graph?

    Microsoft Graph is the unified REST API gateway for Microsoft 365 services. Rather than maintaining separate APIs for Intune, Entra ID, Exchange, Teams, and SharePoint, Microsoft Graph consolidates them behind a single endpoint (`https://graph.microsoft.com`). A single OAuth2 access token can authorise calls across multiple services, and the data model links entities together – a device is connected to its registered user, its applied policies, and its installed applications.

    For asset tracking, this is significant. It means you can answer questions like “who owns this laptop”, “is this device compliant”, and “what applications are assigned to this user” without joining data from multiple disconnected systems. The relationships are already modelled in the graph.

    Relevant Endpoints for Asset Tracking

    ### Devices

    The `/devices` endpoint returns all devices registered in Entra ID. Each device object includes hardware identifiers (device ID, deviceInstanceId), operating system details (operatingSystem, operatingSystemVersion), display name, registration state, and the approximate last sign-in time.

    “`http GET https://graph.microsoft.com/v1.0/devices “`

    For Intune-managed devices, the `/deviceManagement/managedDevices` endpoint provides richer detail, including compliance state, enrolment type, manufacturer, model, serial number, and the user assigned to the device.

    “`http GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevices “`

    ### Users

    The `/users` endpoint returns all user objects in Entra ID. Each user has a unique ID, display name, user principal name, job title, department, and usage location. For asset tracking, this lets you tie devices and licences to real people rather than opaque identifiers.

    “`http GET https://graph.microsoft.com/v1.0/users?$select=id,displayName,userPrincipalName,jobTitle,department “`

    The relationship between users and devices is queryable in both directions. To find all devices registered to a specific user:

    “`http GET https://graph.microsoft.com/v1.0/users/{id}/registeredDevices “`

    ### Applications and Licences

    Software asset management depends on knowing which applications and service plans are assigned to each user. Microsoft Graph exposes this through several endpoints:

    • `/users/{id}/ownedDevices` – devices a user owns
    • `/users/{id}/assignedLicenses` – Microsoft 365 licence assignments
    • `/subscribedSkus` – tenant-level licence inventory and consumption

    The `/subscribedSkus` endpoint is particularly useful for licence optimisation, as it reports both the number of licences purchased and the number currently enabled for each service plan.

    “`http GET https://graph.microsoft.com/v1.0/subscribedSkus “`

    ### Device Compliance

    For organisations subject to compliance frameworks, device compliance state is critical. The `/deviceManagement/managedDevices/{id}` response includes a `complianceState` property with values such as `compliant`, `noncompliant`, and `unknown`. You can also query compliance directly:

    “`http GET https://graph.microsoft.com/v1.0/deviceManagement/deviceCompliancePolicySettingStateSummaries “`

    This returns aggregated compliance status across policies, useful for reporting dashboards and audit evidence.

    Authentication

    Microsoft Graph uses OAuth2 with Azure AD (Entra ID). For automated asset tracking, the recommended approach is to register an application in Entra ID and grant it application permissions, then authenticate using the client credentials flow.

    The flow is straightforward:

    1. Register an application in the Entra ID portal and note the application (client) ID and tenant ID. 2. Create a client secret or, preferably, a certificate for authentication. 3. Grant the application the required permissions, such as `Device.Read.All`, `User.Read.All`, and `DeviceManagementManagedDevices.Read.All`. 4. Request a token from the token endpoint:

    “`http POST https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token Content-Type: application/x-www-form-urlencoded

    client_id={clientId} &scope=https://graph.microsoft.com/.default &client_secret={clientSecret} &grant_type=client_credentials “`

    5. Use the returned access token in the Authorization header of subsequent Graph calls:

    “`http GET https://graph.microsoft.com/v1.0/devices Authorization: Bearer {accessToken} “`

    Application permissions run without a signed-in user, which is ideal for scheduled polling. Always follow the principle of least privilege – grant only the read permissions your tracking workload requires.

    Common Queries

    ### Find all non-compliant devices

    “`http GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?$filter=complianceState eq ‘noncompliant’ “`

    ### List devices not seen recently

    Stale devices are a common source of asset register inaccuracy. The `lastSyncDateTime` property on managed devices indicates the last time the device checked in with Intune:

    “`http GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?$filter=lastSyncDateTime lt 2026-07-01T00:00:00Z&$select=deviceName,lastSyncDateTime,userDisplayName “`

    ### Identify unused licences

    Combining `/subscribedSkus` (total purchased) with `/users/{id}/assignedLicenses` (consumed) lets you calculate how many licences are unassigned and therefore potentially reclaimable.

    Pagination and Rate Limits

    Microsoft Graph returns large result sets in pages. Most collection endpoints return 100 or 1000 items per page with a `@odata.nextLink` URL pointing to the next page. Your polling code must follow these links until the collection is exhausted.

    Graph enforces per-application and per-tenant throttling limits. For typical asset tracking workloads – polling device and user lists every few hours – these limits are unlikely to be a problem. If you are pulling large volumes, add small delays between pages and implement exponential backoff when you receive HTTP 429 responses.

    Practical Considerations

    Not every device in your estate will appear in Microsoft Graph. Devices managed purely by a third-party MDM, on-premises servers not joined to Entra ID, and cloud instances in non-Microsoft providers will not be represented. Microsoft Graph is most powerful as one source within a multi-source asset discovery strategy, combined with EDR, cloud provider, and other MDM APIs.

    Despite this, for any organisation standardised on Microsoft 365, Graph is the natural starting point. It covers the majority of endpoints, users, and licences in a single, well-documented API, and the data it returns is authoritative – it reflects exactly what Microsoft’s management platforms believe to be true. That makes it an ideal foundation for an automated, continuously updated asset register.

    What this looks like in practice

    Microsoft 365: Outlook emails like “Microsoft 365 invoice – Business Premium, 25 seats, £438.75/month, renews 15th” are picked up automatically. Intune shows every enrolled device with serial numbers, models and assigned users.

    Google Workspace: The same approach works with Gmail – invoice emails like “Your Google Workspace order #12345 – £145.20/month for 12 seats” are captured. Google Admin shows every managed Chromebook and mobile device.

    AssetGraph works across both platforms, so mixed environments get a single unified view.

  • ISO 27001 and Asset Management Requirements

    ISO 27001 and Asset Management Requirements

    ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines a risk-based framework for protecting information assets, and a significant portion of its Annex A controls concern asset management specifically. For organisations pursuing or maintaining ISO 27001 certification, the ability to demonstrate accurate, up-to-date asset records is not optional – it is a core requirement of the audit.

    This article explains what ISO 27001 requires for asset management, where the common gaps are, and how automated asset tracking helps meet the standard’s expectations.

    The Structure of ISO 27001

    ISO 27001 is structured in two parts:

    • Clauses 4-10 define the management system requirements – how the organisation plans, operates, and improves its ISMS.
    • Annex A contains the reference controls. These are the security measures organisations select based on their risk assessment, using the ISO 27002 standard for implementation guidance.

    Asset management sits within Annex A.8. The 2022 revision of ISO 27001 reorganised the controls, and Annex A.8 now contains five controls covering identification, classification, and handling of information and assets.

    Annex A.8 Controls

    ### A.8.1 – Identification of Assets

    This is the foundational asset management control. It requires the organisation to identify all assets relevant to the ISMS and to maintain an inventory of them. The standard explicitly states that an asset inventory should be maintained throughout the asset lifecycle, from acquisition through to disposal.

    Assets in scope include not only hardware but also software, data, services, and people. The inventory should identify each asset’s owner, location, and classification.

    For most organisations, the asset inventory is the area where automated tracking delivers the most value. A spreadsheet that is updated quarterly cannot meaningfully satisfy “maintained throughout the lifecycle”. An API-driven register that polls MDM, cloud, and identity providers can.

    ### A.8.2 – Classification of Information

    Information assets must be classified according to their sensitivity and criticality. Typical classifications include Public, Internal, Confidential, and Restricted. The classification determines how the information is handled, stored, and transmitted.

    Asset tracking supports this control by providing the context needed for classification: knowing which device holds which data, and who has access to it, is a prerequisite for applying the right classification in the first place.

    ### A.8.3 – Handling of Assets

    This control addresses the physical and logical handling of assets – storage, transmission, processing, and disposal. It requires procedures for secure media handling and for the secure deletion of data when assets are decommissioned.

    An asset register that records lifecycle state – including when a device was retired and how its data was sanitised – directly supports an audit of this control.

    ### A.8.4 – Access to Information

    Annex A.8.4 requires that access to information and associated assets be restricted to authorised users. Asset tracking contributes here by maintaining the mapping between users, devices, and the information they can access. When an employee leaves, the asset register should reflect which devices and licences need to be revoked.

    ### A.8.5 – Secure Development

    While primarily aimed at development practices, this control has asset management implications: development environments and test data are themselves assets that must be inventoried and managed.

    The 2013 vs 2022 Revision

    Organisations certified under the older 2013 revision of ISO 27001 should note that Annex A.8 was restructured in the 2022 update. The 2013 version had a more granular set of controls under A.8, including separate controls for media handling (A.8.2) and access control (A.9). The 2022 revision consolidated and simplified these, but the underlying requirements are substantially the same: identify your assets, classify them, control access, and handle them securely.

    All new certifications and surveillance audits now use the 2022 version. If your asset management practices satisfied the 2013 controls, they will largely satisfy the 2022 ones, but the mapping between controls has changed and your statement of applicability should be updated accordingly.

    Where Organisations Fall Short

    In audit experience, the most common asset management findings are:

    • Incomplete inventories. Cloud instances spun up by developers, SaaS subscriptions bought on a corporate card, and contractor laptops enrolled in the MDM but not added to the asset register all represent untracked assets.
    • No ownership assigned. An inventory that lists assets but does not identify an owner for each one fails to meet A.8.1. Without ownership, accountability for security and lifecycle management is unclear.
    • Stale records. An inventory that lists devices retired months ago, or omits devices acquired since the last update, does not reflect reality. Auditors test this by comparing the inventory to live system data.
    • No lifecycle tracking. The standard requires assets to be managed throughout their lifecycle. An inventory that records acquisition but not retirement, or that has no record of how decommissioned assets were disposed of, is incomplete.

    How Automated Tracking Supports Compliance

    Automated asset tracking addresses each of these gaps directly.

    Completeness. By polling multiple authoritative sources – MDM, identity provider, cloud provider APIs, EDR – automated discovery captures assets that manual tracking misses. A cloud instance appears in the inventory the moment it is created, not the next time someone updates a spreadsheet.

    Ownership. Identity-integrated asset tracking associates each device with the user registered in the identity provider, providing a natural owner for each asset. Where no user is associated, that itself is a signal worth investigating.

    Currency. API-driven polling refreshes the inventory on a defined schedule – hourly, daily, or at whatever interval suits the organisation. The inventory reflects the current state of the estate, not a historical snapshot.

    Lifecycle. By tracking lifecycle state explicitly – active, in maintenance, retired – and recording state transitions with timestamps, the system produces an audit trail that demonstrates compliance with the “throughout the lifecycle” requirement.

    Evidence. Auditors do not take claims at face value. They want evidence: logs, exports, reconciliations. An automated system produces these as a by-product of its normal operation. A spreadsheet does not.

    Preparing for Audit

    If you are approaching an ISO 27001 audit, the asset management evidence you should be able to produce includes:

    1. A current asset inventory covering hardware, software, and information assets 2. Evidence of ownership for each asset 3. Classification assignments for information assets 4. Records of asset lifecycle transitions, including retirement and disposal 5. Reconciliation between the inventory and live system data, demonstrating that the inventory is accurate

    Automated tracking makes all of these straightforward to produce. The inventory is a query against the tracking system. Ownership comes from the identity integration. Lifecycle transitions are recorded as state changes with timestamps. Reconciliation is a comparison between the tracking system’s view and the underlying source APIs.

    ISO 27001 does not prescribe how you maintain your asset inventory – it specifies what the inventory must contain and what it must demonstrate. Automated tracking is not a requirement of the standard, but it is the most reliable way to satisfy the standard’s expectations in a modern, dynamic IT estate where assets are created, changed, and retired continuously.

    What this looks like in practice

    Google Workspace: Google Admin shows every managed device. Gmail picks up procurement emails like “12 Chromebooks purchased, £449 each”. AssetGraph logs who has each device and when it was assigned – exactly what ISO 27001 Annex A.8 requires.

    Microsoft 365: Intune provides the full device inventory. Outlook catches emails like “Surface Laptop 5, serial #ABC987, assigned to J. Smith”. Every device change is logged with a timestamp for your audit trail.

    Both platforms feed the same audit-ready asset register, so ISO 27001 evidence is always current.

  • How to Do a Simple IT Audit

    How to Do a Simple IT Audit

    An IT audit sounds formal, but at its core it is just finding out what you have. If you have never done one, you can make a solid start in an afternoon. Here is how.

    Step 1: List Every Device You Can See

    Walk through your office or workspace. Note every device you can physically see: laptops, desktops, monitors, phones, tablets, printers, switches, routers, access points.

    For each device, record:

    • What it is (laptop, monitor, etc.)
    • Make and model
    • Serial number (usually on a sticker on the bottom)
    • Where it is located

    Do not worry about perfection. A partial list is better than no list.

    Step 2: Check Your Microsoft 365 or Google Workspace Admin

    Log in to your admin console. This tells you what software licences you are paying for and who has them.

    In Microsoft 365, go to the admin centre and look at active users and their assigned licences. In Google Workspace, check the user list and the licences assigned to each.

    Note down:

    • Total number of user accounts
    • How many licences of each type you are paying for
    • Any accounts for people who have left the company

    This step alone often reveals licences you are paying for unnecessarily.

    Step 3: Review Your Credit Card Statements

    Software subscriptions are usually paid by card. Go through the last three months of statements and list every recurring charge that looks like software.

    Common ones to look for:

    • Microsoft 365 or Google Workspace
    • Adobe Creative Cloud
    • Slack
    • Zoom
    • CRM tools (HubSpot, Salesforce, Pipedrive)
    • Accounting software (Xero, QuickBooks)
    • Cloud storage (Dropbox, Box)
    • Project management tools (Asana, Monday, Trello)

    For each, note the monthly cost and who is responsible for the account.

    Step 4: Note What Each Device Is Assigned To

    Go back to your device list from Step 1. For each device, record who it is assigned to. If it is shared, note that. If it is in storage, mark it as unassigned.

    If you do not know who a device belongs to, that is useful information too. It means the device is untracked, which is exactly the problem you are trying to fix.

    Step 5: Identify Gaps

    Now compare what you found:

    • Are there user accounts in Microsoft 365 for people who no longer work at the company? Those are wasted licences.
    • Are there software subscriptions on your credit card that no one recognises? Those are candidates for cancellation.
    • Are there devices with no assigned owner? Those need to be allocated or stored properly.
    • Are there devices on your list that you cannot find? Those may be lost or taken home.

    Write down every gap you find. Each one is something to act on.

    Practical Takeaways

    • You do not need specialist software to do a first audit. A spreadsheet is fine.
    • Combine what you can see (devices) with what you can find in admin consoles (licences) and on your card statements (subscriptions).
    • Do not try to do it perfectly the first time. An incomplete audit you actually do is worth more than a perfect plan you never start.
    • Schedule a follow-up in three months to fill in the gaps and keep the register current.

    What this looks like in practice

    Google Workspace: Instead of walking around with a clipboard, AssetGraph pulls the device list from Google Admin. Gmail has already captured every purchase email. You export the full register in one click – devices, licences, costs, assigned users.

    Microsoft 365: Instead of asking each team what they have, AssetGraph pulls the device list from Intune. Outlook has already captured every invoice. One report shows every Surface, every Microsoft 365 seat, and every renewal date.

    An audit that used to take three days now takes three minutes.