IT Asset Management Checklist

Quarterly review cycle a sysadmin or MSP team runs to reconcile hardware and software inventory, retire end-of-life equipment, validate compliance controls, and report financials at the leadership QBR.

5 sections 27 steps Collects data
1

Hardware Inventory and Tagging

  1. Pull device inventory from RMM and MDM
    • Export the current device list from the RMM (NinjaOne, Datto RMM, ConnectWise Automate) and the MDM (Intune, JAMF). Reconcile both — devices in MDM but not RMM are typically Macs missing the agent; devices in RMM but not MDM usually mean unenrolled endpoints that bypass conditional access.

  2. Reconcile the RMM scan against the CMDB
    • Compare RMM agent counts against the CMDB or asset register (ServiceNow, Snipe-IT, IT Glue, Hudu). Note any device on the network without an agent — the most common gap is a long-lived test VM, a kiosk, or a contractor laptop someone forgot to enroll.

    Collects list
  3. Apply asset tags to untagged devices
    • Untagged hardware shows up at every refresh and every audit. Print barcode labels with the asset register's ID, attach to chassis, and update the register with serial number, MAC, and assigned user.

  4. Categorize devices by site, department, and cost center
    • Cost-center mapping drives chargebacks and depreciation allocation. Pull the latest org chart from HRIS so transferred employees aren't still tagged to their old department.

  5. Verify warranty coverage in vendor portals
    • Spot-check serial numbers in Dell ProSupport, HPE Support, Lenovo Premier, or Apple Care portals. Out-of-warranty production hardware feeds the refresh list in section 3.

2

Software and License Reconciliation

  1. Run a software discovery scan with Lansweeper
    • Use Lansweeper, ManageEngine AssetExplorer, or Snow Software to enumerate installed packages across the fleet. Capture publisher, version, and install count for downstream entitlement matching.

  2. Reconcile installations against entitlement records
    • Match installs against purchase records and the Microsoft VLSC, Adobe Admin Console, or Autodesk Account portal. Over-deployment is the source of six-figure true-up bills during a Microsoft SAM engagement or Oracle audit.

  3. Check Microsoft 365 and Adobe seat utilization
    • Pull last-active dates from the M365 admin center and Adobe Admin Console. Reclaim seats inactive for 60+ days; downgrade E5 users who only use mail and Teams to E3 or Business Premium.

  4. Flag unauthorized or shadow IT installations
    • Flag installs not in the approved software catalog — typically remote-access tools (TeamViewer personal, AnyDesk), VPN clients, or AI assistants installed before policy caught up. Microsoft Defender for Cloud Apps and Netskope can corroborate the discovery scan.

    Collects list
  5. Open security tickets for unsanctioned apps
    • File a P3 ticket per finding to the security or service-desk queue with the device, user, and detected package. For high-risk installs (RMM tools the user installed personally, crypto miners), escalate to P2 and isolate the endpoint via EDR.

  6. Queue renewal tickets ninety days before expiration
    • Pull the renewal calendar from the asset register and create PSA tickets at 90/60/30-day intervals. Backup software and endpoint security lapses cause the loudest outages — prioritize those over productivity SaaS.

3

Lifecycle and Procurement

  1. Identify endpoints past the four-year refresh threshold
    • Filter the asset register for devices with purchase dates older than the refresh policy (typically 4 years for laptops, 5 for desktops, 6 for servers). Cross-reference with out-of-warranty status and any TPM 2.0 / Windows 11 eligibility blockers.

    Collects list
  2. Open procurement requests for replacement hardware
    • Submit POs to the standard hardware vendors (CDW, Insight, Connection, SHI) referencing the approved standard SKU. Lead times for business laptops are 2–6 weeks; order before the user's old device fails, not after.

  3. Deploy new endpoints via Intune Autopilot
    • Register hardware hashes in Intune Autopilot or Apple ADE/JAMF before shipping to the user. Zero-touch enrollment avoids the imaging-bench bottleneck and ensures BitLocker/FileVault keys escrow correctly on first boot.

  4. Sanitize retired drives per NIST SP 800-88
    • Run a Purge-level wipe (cryptographic erase for SED, ATA Secure Erase for NVMe, or physical destruction for damaged media). Generic format-and-reinstall is Clear-level and not sufficient for devices that held PHI, PCI, or CUI.

  5. File disposal certificates in the asset register
    • Attach the certificate of destruction from the ITAD vendor (e.g., SEAM, ERI, Iron Mountain) to the asset record and mark status as Disposed. Without the certificate, finance can't write off the asset and auditors flag the gap on SOC 2.

4

Compliance and Security Controls

  1. Verify BitLocker and FileVault encryption coverage
    • Run the Intune encryption report and the JAMF FileVault smart group. Any device showing Not Started or recovery key not escrowed is an audit finding — and a real risk if the device is lost before the next quarterly review.

  2. Confirm EDR agent presence on every managed device
    • Reconcile the EDR console (CrowdStrike Falcon, SentinelOne, Defender for Endpoint) against the device list from section 1. Devices missing the agent are usually offline-too-long machines or recently reimaged endpoints where the GPO didn't redeploy.

  3. Reconcile the service-account inventory
    • List every service account in AD/Entra and tag each with owner, purpose, last password rotation, and privilege level. Domain Admin service accounts older than the rotation policy are the textbook pass-the-hash blast radius — vault them in CyberArk or Delinea before next quarter.

  4. Review patch compliance since the last patch Tuesday
    • Pull the patch compliance dashboard from Intune, WSUS, or Automox. Anything below the SLA threshold (commonly 95% within 14 days for critical CVEs) gets a remediation ticket; document any approved exceptions with a CVSS justification.

  5. Capture evidence for SOC 2 ITGC controls
    • Export screenshots and CSVs for the access review, change management log, and backup success report. Drop them into the GRC platform (Vanta, Drata, Secureframe) tagged to the relevant CC controls. The auditor's first request next cycle will be exactly these artifacts dated this quarter.

    Collects list Collects file Collects paragraph
  6. Open remediation tickets for failing controls
    • For each failing control, create a tracked remediation ticket with owner, target date, and the specific evidence required to close it. Failing controls left open across two quarterly cycles become qualified opinions in the SOC 2 report.

5

Financial Tracking and QBR Reporting

  1. Update depreciation schedules in the finance system
    • Push retired and newly acquired assets to NetSuite, QuickBooks, or Sage. Hardware is typically 3-year MACRS; software CapEx follows the contract term. Reconcile the asset register's net book value against the GL.

  2. Calculate total cost of ownership per device class
    • Roll up purchase price, support contract, software licensing, helpdesk hours, and average lifespan to a per-device TCO. The number that matters at the QBR is dollars per user per year, not capital outlay.

  3. Compare quarterly spend against the asset budget
    • Variance over 10% needs a written explanation. Most overruns trace to unbudgeted hires, emergency hardware replacements, or SaaS auto-renewals that escaped the renewal queue in section 2.

  4. Identify consolidation and cost-saving opportunities
    • Look for overlapping SaaS (two project tools, three diagram tools), unused M365 add-ons, and on-prem services that could move to a per-user cloud model. Pair each finding with an estimated annual savings figure for the QBR deck.

  5. Present asset findings at the leadership QBR
    • The vCIO or IT director walks finance and the executive team through inventory accuracy, license posture, refresh forecast, compliance status, and TCO trend. End with the procurement and budget asks for the next quarter so funding decisions happen in the room.

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 5
Steps 27
Category Systems Administration
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run IT Asset Management Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.