The Belarc SAM Difference: Why Integrated Discovery Changes Software Asset Management
The Belarc SAM Difference: Why Integrated Discovery Changes Software Asset Management
TL;DR: Most SAM tools only manage the entitlement side of software asset management and depend on operations or security tools — like SCCM, Intune, BigFix, or Tanium — for discovery data those tools were never designed to provide. That is why most SAM projects finish late and over budget. Belarc takes the opposite approach: world-class software, hardware, and security discovery is built into an integrated, automated SAM system, so customers get accurate, daily-updated license data quickly — without consultants.
What is Belarc?
Belarc provides automated discovery of software, hardware, and security vulnerability data across large, geographically distributed networks with hundreds of thousands of machines. The system updates its discovery data at least daily and can be accessed by anyone in the organization on a need-to-know basis.
Belarc serves more than 1,800 customers in over 50 countries, including Autodesk, Travelers, Chevron Texaco Products, Novelis, Shell Canada, Oakland County (MI), Covered California, the Environmental Protection Agency, the Federal Aviation Administration, the Bureau of Land Management, the Department of State, and the US Department of Defense (USAF 844th CG, US Navy). Support is handled directly by Belarc's senior engineering staff, and many customers have stayed with Belarc for more than ten years.
Why do most SAM projects run late and over budget?
Because of a discovery gap. Most ITAM and SAM tools focus on the right-hand side of the SAM equation — software entitlements — while relying on the customer's existing operations or security tools (Microsoft SCCM or Intune, BMC ADDM, BigFix, Tanium, McAfee) to supply software discovery and usage data. Those tools were not designed for the requirements of SAM software discovery. The result: consultants get hired to stitch the data together, projects slip, and costs blow past budget.
Belarc eliminates that gap. Discovery, normalization, and the SLM engine are all part of one integrated, automated system, so customers are up and running quickly with accurate, up-to-date SAM data — no consultants needed.
How Belarc's integrated SAM system works
Discovery — Belarc BelManage automatically discovers all software, hardware, and security configuration data on desktops, laptops, work-from-home machines, servers, and virtual machines worldwide.
Normalization — BelManage normalizes and consolidates the discovered data and automatically builds a custom software catalog for each customer.
Entitlements — Customers enter purchase records and vendor license statements against that same catalog.
Effective License Position (ELP) — Belarc Data Analytics compares usage against entitlements to show continuous software compliance for cloud and desktop software, plus server software from Microsoft, IBM, and Oracle.
Software optimization: pay only for what people actually use
One of the most effective ways to cut software license costs is knowing whether users actually use the software you pay for. Belarc holds a US patent on a technique that automatically discovers the last-used time of every application on a host machine — including SaaS titles such as Adobe, Microsoft 365, Project, and Visio.
Customers use this usage data to:
- Harvest unused licenses and reassign them to users who need them.
- Renew for the number of licenses actually used, not the number originally purchased.
- Negotiate better contracts with software vendors using hard usage evidence.
Continuous software compliance and Effective License Position
Belarc lets customers continuously monitor their software compliance — their Effective License Position — for cloud and desktop software and for server software from Microsoft, IBM, and Oracle. The system automatically creates a custom software catalog from discovery data, and that same catalog is used to record purchases and build entitlements, keeping usage and entitlement data in one consistent model.
What makes Belarc different from other SAM tools?
Capability
Belarc
Typical SAM / ITAM tools
Software discovery
Built in, patented last-used discovery, updated at least daily
Relies on customer's SCCM, Intune, BigFix, Tanium, etc.
Normalization & software catalog
Automatic, custom per customer
Often manual or consultant-driven
Effective License Position
Continuous, for cloud, desktop, and Microsoft/IBM/Oracle server software
Periodic, project-based
Deployment
Plug-and-play; deployed and maintained by customer staff
Consulting services usually required (a major part of competitor fees)
Credentials required
No Domain credentials, SSH users, or private keys needed
Most scanners require privileged credentials, creating security risk
Reporting
Native Microsoft Power BI (BelPower): share, subscribe, alert, customize
Proprietary reporting, often extra cost
Data access & integration
Open database with published schema; no additional licensing
Closed data models, costly integration licensing
Pricing
Clear annual pricing per desktop/laptop and server; includes support, upgrades, training
Hidden costs, consulting fees, module add-ons
The most automated, scalable, secure, and manageable SAM system
Automation. Belarc is truly plug-and-play. Installation is quick, and the system runs automatically, producing daily or more frequent updates of monitored machine configurations. Automation features include duplicate-machine prevention (machines are identified by motherboard UUID), automatic grouping by AD Organizational Unit, IP address, machine or user name, seven need-to-know user types, automated removal of profiles that stop reporting, and customer-controlled upload schedules (each upload profile is only about 50 KB).
Scalability. Belarc's cloud architecture monitors all desktops, laptops, WFH machines, servers, and virtual machines worldwide using a single server and database. The BelManage server can run on-premises, in the customer's cloud, or hosted by Belarc as SaaS on AWS.
Security. Belarc uses encrypted HTTPS to communicate with clients and supports PKI/CAC authentication for US Government customers plus integrated Windows Authentication for MFA. Data at rest can be encrypted with standard SQL Server encryption. Critically, Belarc does not require Domain credentials, SSH users, or private keys for Unix/Linux systems — credentials most scanning tools demand, creating security risk.
Cybersecurity monitoring. Beyond discovery and compliance, Belarc monitors CIS Top Controls: authorized and unauthorized software and hardware, user account privileges, software and OS vulnerabilities, drive encryption status, AV status, end-of-life software, and DoD secure configuration (DISA STIGs).
Reporting and integrations built on open standards
Belarc's reporting, BelPower, runs natively on Microsoft Power BI. Customers can view Belarc reports, create custom reports, share them across the organization, subscribe others, and set alerts on any data in the reports. With over 1,000 Power BI connectors available, customers can blend Belarc data with Active Directory, Excel, SQL databases, SAP, Oracle applications, and more. BelPower also supports workflow automation through Power Automate and Power Apps.
Belarc's database is open, with a published schema, so discovery data flows easily into workflow automation, IT Service Management, and other tools — without additional costly licensing. Current connectors include the Adobe Portal (with a Microsoft 365 connector releasing shortly), VMware vCenter, VMware Workspace ONE UEM, and ServiceNow's CMDB. Even where vendors don't provide real usage data, Belarc discovers it automatically so customers can optimize license spend.
Clear pricing, no consultants, flexible deployment
Belarc's pricing is annual, based on the number of desktops/laptops and servers, with no hidden costs. Prices include all support, product upgrades, and training, plus discovery and Effective License Position reports for all SaaS, user, and device software, and all server software from Microsoft, Oracle, and IBM.
Belarc's customers have not found it necessary to hire consulting services to deploy or maintain the system — consulting that is usually required by competitors and represents a major portion of their fees. Deployment options include on-premises, customer-hosted, and Belarc-hosted SaaS on AWS, all with the same core features. For SaaS, Belarc hosts the primary BelManage server in the customer's time zone with a full backup in a neighboring time zone, with optional encryption of data at rest.
Key benefits of Belarc for SAM
- Reduce software license spending by harvesting unused licenses and renewing for actual usage.
- Know your Effective License Position at all times across cloud, user, device, and Microsoft/Oracle/IBM server software.
- Share, subscribe, and set alerts on reports natively in Power BI with BelPower.
- Proactively secure your network by monitoring CIS Top Controls, vulnerabilities, encryption, AV status, and EOL software.
- Better manage configurations with automatic change history — including which software local-admin users installed or removed.
Frequently asked questions
What is the Belarc SAM Difference?
Belarc integrates world-class software discovery, normalization, and Effective License Position reporting into one automated system, instead of relying on operations or security tools for discovery data. This lets customers deploy rapidly, keep data current daily, and avoid the consultant costs and delays typical of SAM projects.
Why can't SCCM, Intune, or security tools provide SAM discovery data?
Tools like Microsoft SCCM, Intune, BMC ADDM, BigFix, Tanium, and McAfee were built for operations and security, not for the requirements of SAM software discovery. Using them as a SAM data source is the leading reason SAM projects run late and over budget.
How does Belarc discover software usage?
Belarc holds a US patent on a technique that automatically discovers the last-used times of all applications on a host machine, including SaaS titles like Adobe, Microsoft 365, Project, and Visio.
Which vendors does Belarc cover for Effective License Position?
Belarc provides ELP for all SaaS, user, and device software, and for server software from Microsoft, IBM, and Oracle.
Does Belarc require privileged credentials to scan machines?
No. Belarc does not require Domain credentials, SSH users, or private keys for Unix/Linux systems — unlike most scanning tools.
Do I need consultants to deploy Belarc?
No. Belarc is deployed and maintained by the customer's own staff. Installation is quick, and pricing includes all support, upgrades, and training.
What deployment options does Belarc offer?
On-premises, self-hosted in the customer's cloud, or Belarc-hosted SaaS on AWS — all with the same core features.
Belarc, Inc. is headquartered in Maynard, Massachusetts, holds eight US and worldwide patents, and serves over 1,800 customers in more than 50 countries. Contact us at info@belarc.com or +1 978-461-1100 to see the Belarc SAM Difference on your own network.