New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now liveSee changelog →
Remote monitoring & management
RMM: agent inventory, patch, and discovery in one feed
Ingest endpoint inventory, patch state, and network discovery from a lightweight agent, with Microsoft 365 sync — remote monitoring and management for the fleets you run.
Product preview · sample workspace (demo data)
Engagements
RBAC
Tickets
acme.infronest.com/workspace
All systems operational
WORKSPACE
A
Acme Corp
MODULES
Overview
Infrastructure
Security & VAPT
IT Assets
Tickets23
Git & QA
Vendors
Budgets
Access & RBAC
Live workspace overview
Last sync 2s ago · Updated by agent
Today7d30d
Servers
142
All healthy
Open tickets
23 (7 urgent)
SLA at risk
Assets tracked
1,284
+12 this week
VAPT score
A+
Last scan 2h ago
Server response time · last 24h
avg 142ms
Product proof
Already live in the product
Backed by app modules
Running in production today: agent-fed inventory, patch, and discovery data, plus Microsoft 365 sync.
Protected app route: /rmm
How it works
Built around real workflows
Highlights below describe capabilities already present in the protected app behind this page.
Agent inventory ingest
Patch and discovery data
Microsoft 365 sync
Tenant-scoped endpoint feed
Workflow
What teams can do here
Step 1
Deploy the agent
Step 2
Ingest inventory and patch state
Step 3
Sync Microsoft 365
Step 4
Act from a unified feed
How it works
How it works
01
Deploy the agent
A lightweight agent on each managed device posts to the RMM ingest endpoints. Devices are the same records used by device management, so inventory, patch state and discovery all attach to one endpoint identity rather than a parallel list.
02
Ingest software inventory
The agent reports installed software with name, version, publisher, install date and its source, whether that is the Windows registry, pkgutil, dpkg or brew. Inventory items can be matched to a software licence so ownership and entitlement stay connected.
03
Ingest patch and discovery data
Missing patches arrive with an identifier such as a KB number or package id, a severity, a status and whether a reboot is required. Network discovery reports found devices by IP, MAC, hostname, guessed OS, open ports and vendor, ready to convert into assets.
04
Deploy patches and run commands
Group devices into a patch deployment with a severity filter, a schedule and an optional automatic reboot. For ad hoc work, queue a remote command in PowerShell or a shell; the agent runs it and reports back the exit code and output.
05
Sync Microsoft 365
With Azure credentials configured, a Microsoft Graph client-credentials sync pulls Intune managed devices into the discovery list and reports the directory user count. When no credentials are set it returns a clear error rather than a fake success.
Example
A worked example
A typical 250-seat accounting firm rolls the agent to every workstation. Inventory comes back showing 38 distinct applications, two of which match existing licence records. The patch feed lists 120 missing updates across the fleet, 17 of them critical; the admin builds a deployment targeting the workstation group, filtered to critical and important severities, scheduled for Saturday night with automatic reboot allowed. A discovery sweep also surfaces an unmanaged NAS by IP, MAC and vendor — converted into a tracked asset on the spot — and the Microsoft 365 sync reconciles the Intune device list into the same console: one endpoint picture instead of four spreadsheets.
FAQ
Frequently asked questions
What does the RMM agent report back?
The agent posts to three ingest endpoints: software inventory, patch state and network discovery. That gives you installed applications with versions, the list of missing patches with severity and reboot needs, and devices found on the network in one feed.
How is installed software matched to licences?
Each inventory item records its name, version, publisher, install date and source, and it can be linked to a software licence record. That connects what is actually installed on endpoints to the entitlements you are paying for and tracking elsewhere.
Can I roll patches to groups on a schedule?
Yes. A patch deployment can target a device group, filter by severity such as critical and important, run at a scheduled time and optionally reboot automatically. That lets you stage updates to a ring of machines instead of touching each one by hand.
What does network discovery capture?
Discovered devices are recorded with IP and MAC address, hostname, a guessed operating system, open ports and vendor. Each can be converted into a tracked asset, so scanning the network becomes a way to grow the inventory rather than a throwaway report.
How does the Microsoft 365 sync work?
It uses Microsoft Graph with client-credentials OAuth against your Azure tenant to pull Intune managed devices into the discovery list and report the directory user count. Without configured Azure credentials it returns an explicit error, never a fabricated result.
Can I run commands on a device remotely?
You can queue a remote command in PowerShell or a shell against a managed device. The agent executes it and reports the exit code and captured output, so routine fixes and checks can be scripted from the console and audited afterwards.
Which operating systems does the RMM agent cover?
Windows, macOS and Linux — inventory sources include the Windows registry, pkgutil, dpkg and brew. Android is handled through device management, and there is no iOS or iPadOS agent today; Intune-managed devices can still surface via the Microsoft 365 sync.
Software inventory, missing patches, discovery and remote commands attach to the same device record — with scheduled ring deployments to close what they find.