Build Your Fleet's Software Inventory with Intune
Compile the full list of software installed on your Intune-managed devices: method, the data to collect, and uses for security and compliance across the fleet.
Many SMBs could not say precisely which software runs on their devices. Yet you cannot secure, update or audit what you do not know. The software inventory — the exhaustive list of apps installed across the fleet and their versions — is the foundation of any serious security and compliance effort. Without it, every security action rests on assumptions rather than facts.
This inventory is not a luxury reserved for large organizations. As soon as a fleet passes a few dozen devices, human memory no longer suffices: you need a reliable source of truth, kept up to date automatically, on which to base every decision. It is the concrete starting point for taking control of the fleet, and the single artifact that almost every other security and compliance activity ends up depending on.
What a good inventory must contain
A useful inventory goes beyond a plain list of software names. It must let you answer precisely the question: who has what, and in which version?
- The name and vendor of every app installed across the fleet.
- Its exact version on each device, not just an average.
- The distribution: how many devices are affected, which versions coexist.
- Unmanaged software or apps installed outside procedure (shadow IT).
The exact version, not just the name
Knowing that a PDF reader is installed says nothing about the risk: it is its precise version, on each device, that determines whether it is vulnerable or not. An inventory that only lists application names without detailing versions per machine is almost useless for security. Per-device granularity is what makes the inventory actionable.
What the inventory is actually for
The inventory is not an end in itself: it is the starting point for several high-value actions, for both security and fleet governance.
- 1Spot outdated or vulnerable apps to patch as a priority.
- 2Cross-reference installed versions with published CVEs to assess real risk.
- 3Detect shadow IT and unauthorized software on the fleet.
- 4Document the fleet for an ISO 27001, NIS2 or cyber-insurer audit.
Without this foundation, each of these actions is done blind. With it, they become fast and reliable, because you start from a real state rather than from estimates. The inventory is the common denominator of detection, patching and proof of compliance.
A usage example during an audit
Imagine an auditor asking for the list of machines running a given application in a version earlier than a security fix. Without an inventory, answering means going around the machines, which takes days and stays approximate. With a living inventory, the answer comes in seconds, device by device, with the exact version of each. This ability to answer immediately and precisely transforms the relationship with an auditor or an insurer, who reads it as the sign of a genuinely controlled fleet.
A living inventory, not a frozen snapshot
An inventory taken once a year is useless: the fleet changes constantly, with new installs, uninstalls and daily updates. It must be kept up to date automatically to reflect the real state of devices at any moment, and link directly to remediation actions.
The real value emerges when the inventory is not an isolated document but the starting point of a cycle: detect, prioritize, fix, verify. That is when it becomes an operational tool rather than a mere audit deliverable filed away in a drawer.
Avoid the spreadsheet that ages badly
Many teams start with a hand-maintained spreadsheet. It is better than nothing, but the approach quickly shows its limits: within the first week the data is stale, and no one can tell whether a piece of software was updated or uninstalled. A reliable inventory must be fed automatically by the devices themselves.
- Automatic collection from managed devices, with no manual entry.
- Continuous updates reflecting real installs and uninstalls.
- Fast search and filtering by application, version or device group.
- A direct link to remediation actions, rather than a frozen export.
Common mistakes to avoid
A few recurring habits strip the inventory of its real usefulness.
- Settling for application names without tracking versions per device.
- Maintaining the inventory by hand in a quickly outdated spreadsheet.
- Overlooking shadow IT and software installed outside the official catalog.
- Treating the inventory as a one-off deliverable rather than a living source.
From inventory to fleet governance
A well-kept software inventory does more than serve security: it also becomes a governance tool. It reveals, for example, that the same function is covered by three different tools depending on the team, or that a paid license is installed on machines that never use it. Take an SMB of sixty machines: the inventory shows that two PDF readers, two compression tools and three conferencing clients coexist, often through simple legacy. The rationalization that follows reduces both the attack surface and the costs.
- Spot redundant software covering the same function.
- Identify installed but unused licenses, a source of avoidable cost.
- Standardize on a small set of officially supported applications.
- Document the authorized software to frame future installations.
- Link each application to an owner and an update cycle.
This governance reading turns the inventory into a decision lever, well beyond mere version tracking. By standardizing the fleet around a controlled catalog, you simplify support, reduce the number of applications to keep updated, and cut the vulnerabilities to watch accordingly. Fewer distinct applications means less attack surface, fewer patches to track and a more predictable fleet. The inventory then stops being a simple observation and becomes the starting point of a coherent software strategy.
How AuPoint helps
AuPoint builds and maintains this inventory for SMBs and MSSPs from the devices managed by Intune: the platform lists installed apps and their exact versions, detects vulnerable software and its CVEs, then lets you deploy patches through Intune using official vendor installers. Your inventory becomes a genuine security lever, not a document forgotten in a spreadsheet.
Frequently asked questions
Doesn't Intune already provide a software inventory?
Intune reports information about apps discovered on managed devices, which is a base to build on. But to turn it into a genuine security lever, you must cross-reference that data with known vulnerabilities and link it to remediation actions, which a dedicated layer provides.
How do I handle shadow IT?
An automatic inventory fed by the devices reveals software installed outside procedure, invisible in an official catalog. That is the first step to deciding whether to authorize, frame or uninstall it, rather than ignoring it for lack of visibility. Shadow IT is not dangerous because it exists, but because no one knows it exists.
How often should the inventory refresh?
Continuously. The fleet changes every week, with new installs, updates and uninstalls; a frozen inventory becomes misleading within days. Automatic, permanent collection fed by the devices themselves is the only way to have, at any moment, a faithful picture of the real state of the fleet rather than a snapshot that was already stale by the time you read it.
Does the inventory also cover Microsoft Store apps?
A good inventory lists all installed applications, whether they come from a classic installer, the Microsoft Store or a manual install by the user. It is precisely this exhaustiveness that lets you spot shadow IT and uncontrolled versions. Limiting yourself to one type of source would leave blind spots through which vulnerable software could pass unnoticed.
You only secure what you know: start by knowing exactly what runs on your fleet. With AuPoint, build a living software inventory from Intune and connect it to vulnerabilities and patches. Request a demo to discover the real state of your fleet.