Free endpoint security check

Companies with best-practice endpoint management are demonstrably better protected. With the free Endpoint Security Check, you can find out how well your devices are protected.

With the end of life of Ivanti DSM, organizations must urgently address the replacement.
SOFTTAILOR is a partner of Microsoft (Intune, SCCM), Baramundi and Ivanti and helps you migrate from Ivanti to Microsoft or Baramundi.

The Microsoft Endpoint Configuration Manager (MECM) — also known as SCCM — is the on-premise standard for the deployment and security of devices and applications. Continuously developed since the 1990s, MECM is today an extremely sophisticated and powerful solution that is used by organizations all over the world. The special thing: With co-management, MECM combines your on-premise infrastructure with the possibilities of the Microsoft cloud.
MECM is the top dog for managing on-premise and highly available Windows devices: whether servers or point of sale and production systems. MECM is also the first choice for organizations that do not want to move endpoint management to the cloud and, in extreme cases, operate air-gapped networks.
We usually implement co-management with MECM and Intune to combine the power of MECM with the power of the Microsoft cloud.
MECM is a very sophisticated product with many features that is extremely good at what it should do: manage endpoints with a Windows operating system. The granularity of the configurations is significantly higher in many places than with Intune.
Patching, inventory, managing applications, software metering, OS deployment and upgrades, extremely robust reporting, and more. MECM can deliver exactly what you want on devices at just the right time and under specific conditions. This means that MECM is almost unlimited and precisely configurable.
Due to the widespread use and popularity of Configuration Manager, there is, on the one hand, a high level of integration with almost all Microsoft products, as well as connection options for other products such as ServiceNow or Spider via REST API, PowerShell or even database.
The management of servers and end user devices is very different, which is why Microsoft omitted servers when designing Intune and this is only possible with MECM. Plus, managing endpoints without an Internet connection is impossible with Intune.
Configuration Manager turns the complex management of highly available devices, such as point of sale solutions, into a straightforward process and reduces patching costs.
As a result of the long and widespread use, a huge community has formed around the Configuration Manager. As a result, there are various add-ons, tools and forums that aim to automate and solve every problem.
Let's talk MECM. Let's discuss your challenges and goals to understand how we can best help. With clear recommendations, implementation strength and tried and tested procedures.
No: Intune is the more modern product, but especially in more complex environments, the full power of Microsoft endpoint management often comes together. Intune opens up the world of modern unified endpoint management and the convergence of endpoint management and endpoint security, but has a strong focus on Internet-connected end-user devices and simplifying administration. Anyone who wants to continue to control the deployment of end devices in a very granular way, as well as manage servers, on-premise and high-availability endpoints, needs MECM - and there are no known plans to change this. In addition, MECM's extensive reporting is often used to support regulatory requirements. We recommend co-management with MECM and Intune in almost all cases.
The Microsoft Endpoint Configuration Manager is a powerful tool, but it also requires complexity and maintenance and must be well tailored to your individual organization. MECM is our everyday tool. Let us take away the complexity of MECM for you.
We would be happy to introduce you to MECM in a 30-minute, free “harbor tour”.
We will advise you on the cost and function-optimized licensing of MECM in coordination with your planned deployment. For example, the license for Intune, and therefore for MECM, is included in many Microsoft 365 subscriptions. You can obtain these and all Microsoft licenses from us.
Whether DSM, Empirum, Baramundi, another or no UEM solution at all. We will guide you through the POC, examine your current UEM setup and create a tailor-made concept and migration plan for MECM, possibly in co-management with Intune.
During implementation, we ensure technical best practices and a smooth user experience. This avoids frustration among users, management and you.
MECM only delivers its benefits as well as it is maintained and configured. Otherwise, complexity returns very quickly. We configure, secure, update, and monitor MECM according to best practices and are by your side for support, troubleshooting, and development.
Expandable with additional Endpoint Management as a Service modules up to all-round carefree endpoint management for maximum security and productivity.
Whether troubleshooting, improvements or permanent takeover of activities. We are your point of contact for on-demand and continuous support & advice for everything that concerns Microsoft Endpoint Configuration Manager.
Together with Intune, MECM will be the most widely used tool for endpoint management for many years. Especially for companies that cannot operate their endpoint management entirely from the cloud due to business, technical or security aspects. After the training, you will be able to complete the basics of administration and configuration from MECM to enterprise environments.
Modular software packaging as a service offers you individual software packages with quality Made in Germany with a simple process for onboarding, ordering and coordination. Both for regular software packaging and for migrating software packages when switching to MECM.

MECM experts are rare, expensive and not redundant. Many companies therefore have problems correctly configuring, keeping up to date, and monitoring MECM. They are not using their full potential, or even worse, are frequently troubleshooting.
Basic MECM configuration according to best practices
Backup, update, and proactive monitoring
On demand support, troubleshooting, and expert development
Proactive recommendations on optimization potential and new features, adapted to your environment
Monthly service review
Expandable with Endpoint Management aaS modules for maximum security and productivity
Stability instead of headaches and wasted time with MECM
A go-to partner with knowledge from numerous supervised MECMs
Redundant and flexibly scalable
Significant cost savings vs. internal set-up of equivalent know-how, capacity and redundancy
Capacity for you to further develop the overall direction of your IT

Microsoft Intune is rapidly evolving. Your endpoint strategy and the management of this ecosystem are endless. The resulting workload can be overwhelming for IT teams, meaning they can no longer focus on the overall direction of corporate IT.
Intune basic configuration based on best practices
Proactive monitoring of availability and functionality
On demand support, troubleshooting, and expert development
Proactive recommendations on optimization potential and new features, adapted to your environment
Monthly service review and proactive recommendations
Expandable with Endpoint Management aaS modules for maximum security and productivity
Stability instead of headaches and wasted time with Intune
Always up to date on Intune's latest features and capabilities
A go-to partner with the knowledge of numerous supervised Intune Tenants
Redundant and flexibly scalable
Significantly lower costs vs. internal setup of the same know-how, capacity and redundancy
Capacity for you to further develop the overall direction of your IT

With the initial OS installation via the network, no operating system has to be installed on the computer beforehand, but the operating system is installed completely according to your own specifications, without unnecessary software.
Zero Touch Provisioning
Installing via PXE
Definition of the installation or task sequence
Device deployment time is reduced
Individually defined and consistent status after installation regardless of the pre-installed OS
Reducing help desk expenses through standardization
In-depth information about software and hardware inventory
Simple expansion and adjustment of information is possible
Collection of information about actually used software
Deep insight into the hardware and software used
Save license costs due to unused software
No manual effort for additional information that needs to be collected
With Microsoft Configuration Manager, it is possible to clearly define when an installation or restart is allowed. Even dependencies on other systems can be included.
Precise definition of maintenance time windows when installation of updates and/or applications is allowed
Define orchestration groups to allow installations, and restarts depending on the availability of other systems
Deadlines for installing updates and applications at the defined time
Systems are only updated at a defined time
High availability of systems
No annoying updates during critical business hours
MECM is the bridge to Microsoft Intune and many other Microsoft cloud features and combines endpoint management of on-premise devices with modern endpoint management.
Cloud Management Gateway
Azure AD group synchronization
Co-management (integration with Intune)
Cloud analysis of devices
Using Intune features for OnPremise devices
Managing endpoints over the Internet through a Microsoft-hosted infrastructure
Easy transfer and assignment to Entra ID
Windows 11 Readyness Assessment
Resolve issues quickly, easily, and securely with Configuration Manager Remote Control.
Remote connection authenticated via AD
Lock screen access
Easy configuration whether user consent is required or not
Sending Ctrl+Alt+Del, sharing the clipboard, locking the mouse and keyboard
Increased end-user productivity and satisfaction
Access when the device is only turned on to solve tickets in absentia
Preventing disruptions when resolving problems
No management of servers
No management of on-premise endpoints
Poor management of highly available endpoints
More automation but less precise configuration options
Superficial reporting
Accurate management of highly available endpoints
Management of on-premise endpoints up to entire air-gapped networks
Microsoft server management
Best of both worlds: Benefits of MECM for end user devices and benefits of Intune for on-premise devices
Large community and adaptability to individual requirements
Comprehensive, detailed reporting

Companies with best-practice endpoint management are demonstrably better protected. With the free Endpoint Security Check, you can find out how well your devices are protected.




We'll get to know each other and find out what's currently on your mind when it comes to MECM. You will get initial ideas on how we can help you.
After the initial discussion, we will present you with a specific proposed solution and the offer for implementation.
Equipped with automation and best practices, our team implements the proposed solution in record speed.

Microsoft Endpoint Configuration Manager (MECM) is the essential solution for companies seeking precise and comprehensive management of their devices — whether on-premise, in hybrid environments, or through integration with the Microsoft cloud. With decades of development, MECM is a proven, flexible and powerful platform that meets modern endpoint management requirements.
“MECM expertise is required, but often difficult to find. Many companies are faced with the challenge of correctly configuring MECM, keeping it up to date and monitoring it efficiently. The full potential is often not exhausted, while valuable resources flow into troubleshooting. ”
— Thore Lenz, CEO of SOFTTAILOR
MECM can be complex to implement and maintain. This is exactly where SOFTTAILOR comes in: As an experienced partner, we help you make optimal use of MECM — from basic configuration to continuous monitoring to long-term optimization. Our goal is to take away the complexity of MECM and at the same time increase the efficiency and security of your IT environment. Our services include:
Get started now: Companies that rely on MECM benefit from a sophisticated solution for managing their devices, better security and a more efficient IT infrastructure. Together with SOFTTAILOR, you can utilize the full potential of MECM — without additional effort for your team. Our experienced team is ready to analyse your challenges and develop tailor-made solutions for your company. Here Can you make an appointment.
The combination of MECM and Intune provides you with the optimal solution for endpoint management. This hybrid approach allows you to continue managing on-premises systems with precision while benefiting from the advantages of modern cloud solutions. SOFTTAILOR helps you combine the best of both worlds.
Microsoft Endpoint Configuration Manager (MECM), also known as System Center Configuration Manager (SCCM), is included in a variety of Microsoft subscription plans designed specifically for businesses. Plans that include MECM/SCCM as standard include:
It is important to note that Microsoft 365 Business Premium not offers the same MECM/SCCM licensing benefits as Enterprise (E) or Frontline Worker (F) subscriptions. Although Business Premium includes Intune Plan 1, however, MECM/SCCM licenses are not included in this plan. If your organization needs these features, alternative Microsoft plans or separate licensing are required.
If your company does not want to use one of the above subscriptions, it is possible to purchase MECM/SCCM as a standalone license independently of the Microsoft packages. This flexibility enables companies to individually adapt their IT solutions. We would be happy to provide you with detailed advice on this topic. Arrange a initial consultation.
Managing servers is a central point when using MECM/SCCM. SCCM licenses for managing servers are never included in the above subscriptions and must always be purchased separately. These licenses are essential for companies that want to professionally and efficiently manage server environments.
Through cloud management gateway and co-management, SCCM provides seamless integrations with a wide range of Microsoft services, including Active Directory, Microsoft Intune, and Azure. These integrations enable centralized management of all devices, user accounts, and security policies. This allows companies to control and manage their entire IT infrastructure more efficiently without having to configure different systems separately.
PowerShell is an essential tool in SCCM administration. Administrators can use PowerShell scripts to automate tasks such as software distribution, user management, and system monitoring. This significantly reduces administrative costs and allows recurring tasks to be carried out more efficiently. PowerShell also provides advanced troubleshooting and logging features, making it a powerful tool for SCCM administrators.
MECM bietet eine Vielzahl von Funktionen, die Unternehmen bei der Verwaltung ihrer Endgeräte unterstützen:
Softwareverteilung: MECM ermöglicht eine zentrale und effiziente Verteilung von Software und Updates. IT-Teams behalten die Kontrolle über Anwendungen und Betriebssysteme und können Verteilungszeiten flexibel anpassen, um den Betrieb minimal zu unterbrechen.
Sicherheitsrichtlinien: Sicherheitsrichtlinien können zentral erstellt und auf alle Endgeräte angewendet werden, was die Einhaltung von Sicherheitsstandards im Unternehmen sicherstellt. MECM stellt sicher, dass Patches und Sicherheitsupdates rechtzeitig aufgespielt werden, wodurch potenzielle Sicherheitslücken reduziert werden.
Cloud-Integration: MECM integriert sich nahtlos mit Microsoft Intune und bietet dadurch eine umfassende Lösung für hybride Umgebungen. Softtailor empfiehlt Co-Management, da es das Beste aus beiden Welten kombiniert: MECM bietet granulare Steuerung und umfangreiche On-Premise-Management-Funktionen, während Intune das cloudbasierte, internetgestützte Unified Endpoint Management für mobile Endgeräte vereinfacht. Co-Management ermöglicht Flexibilität und Sicherheit durch die parallele Nutzung beider Systeme – ideal für komplexe Unternehmensstrukturen, die eine hohe Verfügbarkeit und Kontrolle benötigen.
Inventarisierung: MECM bietet eine Inventarfunktion, die eine detaillierte Übersicht über alle verwalteten Geräte liefert, einschließlich Software, Hardware und Compliance-Status. Dies erleichtert die Verwaltung und unterstützt die Einhaltung von Unternehmensrichtlinien.
Remote-Zugriff und -Steuerung: IT-Administratoren können über MECM Endgeräte aus der Ferne überwachen und steuern, was die Fehlerbehebung und Verwaltung auch in verteilten Umgebungen vereinfacht.
SOFTTAILOR provides comprehensive services for implementing SCCM/MECM. SOFTTAILOR takes care of all tasks, from initial consultation and planning to configuration, maintenance and support. Thanks to SOFTTAILOR's expertise, companies can be sure that their SCCM/MECM solution is optimally tailored to their needs. Contact us for a non-binding initial consultation and let us optimize your endpoint management.
Setting up SCCM requires a proper server structure and an SQL database to store configuration data. The configuration should be carried out in accordance with Bes practices right from the start to ensure smooth operation over the long term. Due to the complexity of SCCM, it is recommended to call in an IT service provider such as SOFTTAILOR, who will take over the implementation and make individual adjustments for your company.
The license costs for SCCM vary depending on the number of devices to be managed and the functions required. For small companies, the costs can be moderate, while larger organizations must expect higher license fees. In particular, licenses to manage servers with SCCM can be costly. However, SCCM licenses are often already included in Microsoft 365 packages such as Business Premium, E3 and E5, which many companies use anyway. There are also costs for the necessary server infrastructure, SQL licenses and IT support. It is recommended to work with an experienced service provider such as SOFTTAILOR to find the optimal solution and avoid unnecessary costs.
In SCCM, updates are managed through various deployment strategies, including manual, automated, and phased deployment. Automatic deployment uses rules (ADRs = Automatic Deployment Rule) that roll out updates regularly without manual intervention. The phased deployment allows updates to be gradually distributed across device groups, which is ideal for testing and large companies. Central administration ensures that security updates are implemented promptly and efficiently to close security gaps.
SCCM supports cybersecurity in companies through comprehensive patch management, which enables the automatic provision of security-relevant updates and patches on end devices. It also provides features for configuring security policies and monitoring compliance. With SCCM, IT administrators can centrally control security standards and ensure that all devices on the network meet current security requirements. Comprehensive reporting and administration enable precise tracking and help meet regulatory requirements.
The Microsoft Endpoint Manager (MEM) combines various tools for managing and securing end devices. Core components include Microsoft Intune for cloud-based device management and the locally installed Configuration Manager (MECM), ideal for complex infrastructures and detailed control of servers and PCs. MEM thus enables hybrid, flexible management — including Intune and MECM co-management — and ensures comprehensive security policies and optimized usability.
Software distribution in SCCM is carried out by creating software packages, which are then assigned to end devices. Administrators can set various distribution rules to ensure that software is only installed on specific devices. Centralized administration allows installations and updates to be efficiently controlled, which leads to higher IT security and lower administrative costs.
Installing SCCM requires at least a Windows Server 2012 R2 or higher. An SQL database is also required to store configuration and monitoring data. In addition, sufficient storage and network performance should be available to ensure smooth operation. A scalable infrastructure is crucial, especially for larger IT landscapes with many end devices.
1. Granularity and flexibility
SCCM enables a fine-grained configuration for managing Windows-based devices. Organizations can determine exactly when and how updates and software are distributed — ideal for environments with strict availability requirements.
2. High integration and compatibility
SCCM integrates seamlessly with other Microsoft services and third-party tools, such as ServiceNow and Spider. This strong compatibility makes management and automation easy.
3. High availability and control over devices
Especially for critical infrastructures such as servers and POS systems, SCCM offers reliable management and enables updates outside operating hours, which optimizes availability.
4. Hybrid management options
Companies that prefer a hybrid approach between on-premise and cloud can combine SCCM with Intune. Co-management brings the flexibility of the cloud to traditional IT environments and helps IT teams implement a comprehensive endpoint management strategy.
SCCM offers advantages through the ability to granular management of end devices and a high degree of flexibility in update control, particularly important in complex corporate environments. Although Intune is a more modern solution, it doesn't completely replace SCCM. Intune is focused on modern, internet-connected devices and easy management, while SCCM continues to cover servers and on-premise systems. By combining Intune and MECM in co-management, companies benefit from comprehensive endpoint and security management.
Co-management is a hybrid solution that makes it possible to manage devices with both SCCM (System Center Configuration Manager) and Intune. This combination gives IT administrators more flexibility as they can take advantage of SCCM's extensive configuration options while incorporating Intune's cloud-based features. For example, certain administrative tasks, such as device compliance and app deployments, can be delegated to Intune, while other areas continue to be controlled via SCCM. Co-management is particularly useful for companies that want to gradually move from local to cloud-based administration.
MECM (Microsoft Endpoint Configuration Manager) is the modernized version of the earlier SCCM (System Center Configuration Manager) and refers to the same product. The main advancements are that MECM has had greater integration with cloud services such as Microsoft Intune in recent years, making it easier to manage mobile devices in particular. MECM also offers advanced endpoint management features, such as closer integration with Microsoft security solutions. While SCCM was originally developed for on-premise devices, MECM combines on-premise and cloud-based administration in one solution.
SCCM (System Center Configuration Manager) is a comprehensive software solution from Microsoft that enables IT departments to centrally manage and configure networks, servers, and devices. It offers a variety of functions, such as software distribution, monitoring of IT infrastructures and carrying out inventories. SCCM plays a critical role in IT security and compliance because it can implement security policies and efficiently distribute updates and patches.