Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Saas Discovery And Question For Sccm Admins

Card image cap

Long story short, am License manager/SAM guy at company (6000 employees), we have our licenses under control, even though our workstations aren't allowed to have any agent running other than SCCM. I'm proud of that, even though we have limited visibility. The Witch-King of Workstations has declared that only SCCM will run because other agents "take too much resources". Bullshit, but whatever.

We had an unauthorized SaaS event, someone bought a subscription to an AI tool (used his own creditcard because he very well knew I wouldn't allow it). This tool is blocked but... Who watches the watchmen? The guy that bought it was from the network team so he just said "rules for thee but not for me".

Anyway, I found out that this guy was using that tool through hearsay and asked the Witch-King if he could find its usage since "SCCM is all we need". He couldn't find it. In none of the tools he supposedly manages (MS Defender also showed no results, probably because SSO wasn't enabled?)

Now, I have some pull in the org and one of the guys at the network team owned me one, so I asked him to open up the firewall logs (Palo, I don't have access and I don't want it tbf) and it was a good thing he was sharing his screen because I don't think he enjoyed ratting out his teammate.

Palo isn't a discovery tool, it's a "search for what is on your radar" tool. Xensam, Flexera, ... Plenty of products do what I want and that is to track and log who is logging into a SaaS platform. BUT you'd need to have the AGENTS running.

I couldn't find a lot of info on SCCM agents and what they actually log and if it is useful for SaaS discovery so I thought I'd ask the experts here. Please enlighten me and if you have any tips so I can bypass the Witch-King all the way to the man in the black tower himself for a business case on other agents, I'm all ears.

submitted by /u/zndr-cs
[link] [comments]