TrustRadius: an HG Insights company

Heimdal Patch and Asset Management

Score8 out of 10

8 Reviews and Ratings

What is Heimdal Patch and Asset Management?

Heimdal Patch and Asset Management is a cloud-based tool that automates OS and third-party updates. The automated patch management solution delivers updates within 4 hours of vendor release, after scanning for malware, removing unwanted software, and checking that the patch installs and works correctly.

Once installed, Heimdal’s lightweight agent is able to define granular group policies and orchestrate patching across Windows, macOS, and Linux - no extra servers.

Key patch management features and capabilities:

  • Silent, flexible deployment – Automates installs without user interruption, with options for reboot rules, postponement, and software self-service.
  • Bandwidth optimization – Limits download speeds and enables peer-to-peer distribution to reduce network load.
  • Granular policy control – Unlimited group policies for different sites, departments, or clients.
  • Comprehensive update views – Tracks installed, pending, and available updates with details on severity, product, and vulnerability IDs.
  • Custom software deployment – The Infinity Management add-on can patch any proprietary software.
  • Full asset visibility – Monitors all installed applications and versions for compliance and lifecycle management.
  • Compliance & audit support – Generates detailed logs for CIS, NIST, and Cyber Essentials. Finds missing updates instantly with compliance checkers.
  • Multi-tenant management – MSPs or MSSPs can use it to manage multiple clients or business units with role-based access controls from a single dashboard.

Heimdal delivers unification through a modular approach. Patch management can be started immediately, and additional modules like PAM, DNS filtering, or endpoint protection are also available as the need arises so that when unexpected compliance requirements emerge or new security challenges surface, there is no need to switch vendors or manage multiple agents.

Media

Heimdal Patch & Asset Management
where to schedule patches with Heimdal's Patch & Asset Management
some of the +350 3rd-party apps that can be patched with Heimdal's Patch & Asset Management
Heimdal's Infinity management add-on, used to update proprietary software

1 / 4

Top Performing Features

  • Configuration Monitoring

    Constant monitoring of a network set up to identify vulnerabilities as they occur within the network or tech stack on the network.

    Category average: 8.3

  • Vulnerability Classification

    Prioritizing vulnerabilities, to determine which vulnerabilities are most urgent and require a quicker resolution.

    Category average: 8.7

  • Network Analytics

    Analyzes various data reports and logs (DNS, firewall, user data, security information etc.) to identify threats in a network.

    Category average: 7.8

Areas for Improvement

  • Authentication

    Authentication of users and services within a network to prevent vulnerabilities from being introduced to the network.

    Category average: 8.1

  • Vulnerability Intelligence

    Software that is able to label and store information about vulnerabilities to access for future use cases.

    Category average: 8.2

  • Threat Intelligence Reporting

    Generates reports that display information on threats (such as name, type, frequency of attack, area affected, etc.)

    Category average: 7.7

Automating patch managment to free up time and improve security.

Use Cases and Deployment Scope

Heimdal Patch and Asset Management provides us with a number of tools. Firstly, we use it to maintain a comprehensive list of software assets installed on all endpoints. Off the back of this, we use the 3rd party software module to keep all supported software up to date with the latest patches. The final element is ensuring our operating systems are fully patched to reduce the possibility that any vulnerability is exploited. I love that it gives a holistic view of what we have, its current patch status and what we need to be aware of.

Pros

  • Maintains a comprehensive list of software assets
  • Ensures 3rd party software is fully patched
  • Ensures OS patches are applied

Cons

  • Difficult to force an update on an individual endpoint - works best automatically

Most Important Features

  • Automation
  • Security
  • Vulnerability Management

Return on Investment

  • Reduced need for extra staff in IT department
  • Enabled round the clock monitoring and automation

Alternatives Considered

Kaseya VSA

Other Software Used

Kaseya VSA, Kaseya BMS, IT Glue, Heimdal Email Security, Heimdal Email Fraud Prevention, Heimdal Next-Gen Endpoint Antivirus, Heimdal Privileged Access Management, Heimdal Ransomware Encryption Protection, Heimdal Threat Prevention

The Mjölnir of patch management tools

Use Cases and Deployment Scope

We utilise Heimdal's patch and asset management as a key component to maintain our accreditation with ISO27001 and Cyber Essentials. The ability to patch all manor or applications in a controlled environment, which in turn has a positive impact on the service desk. As well as using the products ourselves we also recommend Heimdal to our customers and are currently engaged in a campaign to engage new customers and are leading with patch management as one of the key pain points that IT departments and service desks need to address.

Pros

  • All updates are delivered across all devices, whether domained or not.
  • Ability to add applications to patching regime is excellent.
  • Single pain of glass portal for all modules.
  • If needed (rarely), support has been first class.

Cons

  • Continue to add more supportable applications
  • Enhanced reporting tools

Most Important Features

  • Wide range of application support
  • Cloud portal for management

Return on Investment

  • Great ROI - assisting in getting Cyber Essentials, which in turn opens us up to more customers.
  • Reduction in time spent by the service desk patching devices.

Alternatives Considered

Microsoft Endpoint Manager (Microsoft Intune + SCCM)

Other Software Used

Heimdal Next-Gen Endpoint Antivirus, Heimdal Application Control, Heimdal Ransomware Encryption Protection, Heimdal Threat Prevention

Use Patchmanagement like a celebrity.....use Heimdal Security

Use Cases and Deployment Scope

It pretty much du the work by itself. We use it to update third-party software on all our machines. It works without any problems and we're glad to have it. It saves us a lot of time.

Pros

  • Removing some old apps automaticly
  • It updates on all platforms
  • Security patching works very good

Cons

  • I think it works good

Most Important Features

  • Updates
  • Patchment
  • Security

Return on Investment

  • It saves us a lot of time that we can use on other problems
  • It keeps our computer updatet and secure

Alternatives Considered

Heimdal Threat Prevention and Heimdal Endpoint Detection and Response (EDR)

Other Software Used

Heimdal Threat Prevention, Heimdal Endpoint Detection and Response (EDR), Sophos Intercept X

Works as expected; with little interaction required (if desired) once setup. Support are always on hand and helpful.

Use Cases and Deployment Scope

We use it to monitor and administer supported 3rd party updates (Chrome, iTunes, etc.) and Microsoft patches automatically on a daily, weekly and monthly basis.

We control "sensitive" machines via policy so updates are a manual push. This allows us to test updates constructively before rolling out en-masse.

Pros

  • Keeps the 3rd part software Heimdal supports right up to date.
  • Allows a good level of control and customisation in policy for deploying Updates safely and quickly.
  • Good control of the endpoint to force/postpone restarts to help commit updates the require it.
  • Agent based allows for central control and consistent patching when dealing with a flexible work environment.

Cons

  • Can't interact with 'Other Microsoft products' such as .NET installs so no option to patch centrally.
  • "Limited" number of 3rd party software supported. Uplift in license to allow unsupported 3rd party software updates (via uploaded .msi's for example)
  • Reporting can be a little tricky to pull together at first when trying to understand the level of "compliance" for patches.

Most Important Features

  • Agent based management allowed for consistent patch management wherever there's an internet connection.
  • Automatically scheduling and release of Windows updates with little administrative overhead
  • Controlled, prompted reboots to commit updates quickly without disrupting end users

Return on Investment

  • Allows us to maintain a good security posture specifically around patches
  • Time saved having to administer other, more manual solution
  • Data Centre resource saved hosting heavy workload to manage patches

Alternatives Considered

ManageEngine Patch Manager Plus and Qualys Cloud Platform

Heimdal Patch and Asset Management Review

Use Cases and Deployment Scope

In order to update 3rd Party applications as well as custom applications we are using Heimdals Patch and Asset Management.

It gives us the possibility to stay up to date and minimize the risk of Vulnerabilities by 3rd party applications.

The module is supporting most of the 3rd Party applications in use and we rarely have to add additional ones through Heimdals Infinity Management.

Pros

  • Fast updates of well-known 3rd party applications
  • Fast Management with only seldom cases in which we need to stop a change
  • Quick Support-Team that will handle problems professionally
  • Good amount of settings in the Dashboard with Group Policy options to allow custom settings for different Departments or Sub-Companies

Cons

  • Updates of applications might causes unforeseen issues with applications as Add-Ins are not supported anymore after updating or they are getting removed during the update in my opinion
  • Applications might have problems if they are not installed by the Heimdal 3rd Party Patching Module (msi vs. exe versions) I've found. There is no Info about whether a application will fully work for updates if they got installed from another source than the patching module and they are always showing up as normally supported. So it is a good idea to install all applications from Heimdal when first executing the Patching Module as otherwise unforeseen reboots and problems with non-working applications might occur
  • There is no option to disallow an update, when the software which needs the update is currently running I've found. Only a scheduling is available, which will need the attention from the user so the application to close it down before so the update will not fail/break the application. Update re-runs are cached well however and new tries will be executed automatically.
  • It is not possible to execute a one-time install or update operation but the feature will be available soon according to support
  • The asset management is not able to provide a overview of all currently installed applications. Instead it will only show which application is installed (with which version) in a certain time period I've found. A Admin cannot be sure whether a application is a) currently installed on the system or b) was currently uninstalled from the system, if he doesn't choose the perfect time range in the Management Console, which basically means guessing, I've found.

Most Important Features

  • Updating 3rd Party Apps
  • Seeing an Overview of installed applications and whether all PCs are up-to-date
  • Removing unwanted software automatically

Return on Investment

  • More Support necessary than without automated patching
  • ROI is hard to determine as there was no 3rd party exploit in the time we have used Heimdal Patch and Asset Management

Alternatives Considered

PDQ Deploy

Other Software Used

PDQ Deploy