ILMT Health Check: Would Your ILMT Survive an IBM Audit?

Find out before the auditor does. Fixed price, a few working days, and a report you can show an auditor.

Already have a letter from IBM, or an audit in progress? That is a different situation and a different way of working: see IBM Audit Response.

What the ILMT Health Check is

ILMT breaks quietly. The console keeps loading, the quarterly reports keep generating, and nobody notices that agents stopped scanning or that the VM Manager lost its hypervisor credentials months ago. The numbers still look like numbers. They are just no longer true. And IBM's sub-capacity terms do not care whether the gap was intentional: missing data defaults to full-capacity licensing.

The ILMT Health Check is a one-time, fixed-price review of your ILMT environment. I go through it the same way an auditor would, point by point, and tell you what would hold up and what would not. You get the findings, a prioritized list of problems and a remediation plan. What you do with it is up to you.

You work directly with me, Tomasz Oniśk. I have worked with ILMT and BigFix since 2014 and have seen the inside of around 30 organizations' deployments. No handoffs, no junior doing the actual review.

What I check

The review covers the areas where sub-capacity positions actually fail. For each one you get a clear verdict: fine, needs attention, or broken.

  • Agent coverage. Endpoints with no BigFix agent and agents that stopped reporting. ILMT can only count what it can see.
  • Scan health. Freshness and completeness of software scans and capacity scans. Stale scans mean your license position is a guess.
  • Physical processor data. VM Manager configuration and hypervisor credentials. When credentials expire, ILMT loses sight of physical cores and the sub-capacity math falls apart.
  • Classification and bundling. Unconfirmed discoveries and false detections that inflate what ILMT says you are running.
  • ILMT and OS versions. The ILMT server itself and the operating systems it monitors. EOL systems drop out of sub-capacity eligibility.
  • Reports and snapshot archive. Whether the quarterly audit snapshots for the last two years actually exist. IBM expects that history.
  • Sub-capacity configuration. The settings that keep your sub-capacity eligibility valid in the first place.

What you get

  • A report with a point-by-point assessment of every area above. Written so you can hand it to management or, if it ever comes to that, to an auditor.
  • A list of discrepancies ranked by risk. What could push you to full-capacity licensing gets separated from what is merely untidy.
  • A remediation plan with effort estimates. For each finding: what to do, roughly how much work it is, and in what order.

Pricing is a fixed price per environment, quoted after a short call about scale and confirmed before any work starts. Starting points:

  • up to ~250 endpoints: from EUR 1,000
  • 250 to 1,000 endpoints: from EUR 2,000
  • above 1,000 endpoints: individual quote

The final quote depends on the scope you expect and on how you want the results presented, plus the specifics of the environment: the number of Passport Advantage sites, the platform mix, the technology in use and the state that environment is in. Get in touch for a detailed quote.

Want to know where you stand?

A 30-minute call is enough to scope your environment and give you a fixed price.

Book a 30-minute call

Prefer writing first? Use the contact form.

How it works

  1. NDA. We sign one before I see anything.
  2. Remote access. A VPN account or a supervised screen-sharing session, whichever your security team prefers.
  3. Review. I go through the checklist against your live environment.
  4. Report. You get it within a few working days.
  5. Walkthrough. We go through the findings on a call and agree what to fix first.

Case study: what a health check finds

Situation. An international insurance group with 716 endpoints connected to ILMT. The console looked normal and the reports raised no alarms.

Diagnosis. 91% of the endpoints had no current scan results. 74% had no physical processor data, because the credentials ILMT used to reach the hypervisors had expired. BigFix policies had been sitting untouched for weeks. On paper the company had ILMT. In practice its sub-capacity reporting was not credible.

Outcome. The health check showed the scale of the problem. The remediation plan restored credible sub-capacity reporting before an audit could put a price on it.

From health check to ongoing care

A health check is a snapshot. ILMT drifts: agents fall off after migrations, credentials expire, catalogs age. If you decide you want the environment looked after month to month, the health check fee is deducted from the first quarter of ILMT Managed Services. Nothing obliges you to continue. The report and the plan are yours either way.

Frequently asked questions

How is a health check different from an IBM audit?

An IBM audit is usually run by an external audit firm on IBM's behalf, and the results go to IBM. The health check works for you and only for you. I check the same things an auditor would, but the findings stay inside your company and you get time to fix them. Nothing is reported to anyone.

Do you have to install anything new in our environment?

No. The review runs on what is already there: the ILMT console, the BigFix console and the data both of them hold. Read access covers most of the checks. If something needs a deeper look, we agree on it first.

How long does the health check take?

A few working days from the moment I get access to the moment you get the report. The exact number depends on the size of the environment, and that is what we settle on the scoping call. The walkthrough call happens once you have had a chance to read the report.

What if my environment turns out to be in bad shape?

Then the health check did its job. Finding problems early is the point, because the earlier they surface, the cheaper they are to fix. The report separates what threatens your sub-capacity position from what is cosmetic, so you deal with the dangerous items first. The insurance group in the case study started at 91% stale scans and got back to credible reporting.

Will I get a quote for fixing what you find?

Yes. The remediation plan includes an effort estimate for each item. You can fix things with your own team, bring me in for the work, or move to ILMT Managed Services. In the last case the health check fee comes off the first quarter.

Check it on your own terms

An auditor will go through the same list sooner or later. Better that you see the results first, with time to act on them.

Book a 30-minute call

Or send a message through the contact form.