July 2026 release

Five new modules, one console

This release widens APaaS Assure from the packaging-and-risk core into cloud licences, endpoint protection and Cyber Essentials Plus readiness. A single view now spans where money leaks, where a client is exposed, and whether they would actually pass CE+ - all per-client scoped and audit-logged.

New in this release

Grouped the way the console now is - CE+ pre-assessment, cloud, security and health checks.

CE+ Assessment

Score any client against the five Cyber Essentials Plus controls, mapped to the certification test cases. Automated checks and agent probes rate every device, surface exactly what fails, and build an action plan and a compliance journey that tracks the firewall changes, upgrades and CVEs cleared on the way to a pass.

Microsoft 365 Usage & Licence Optimisation

Cloud-side SAM through Microsoft Graph: per-user activity and which platforms - desktop, mobile, web - each person actually uses. Finds inactive licences, duplicate/overlapping licences, unused seats, and desktop licences used only on web or mobile - every finding costed in pounds. Reuses your Intune connection, read-only.

Endpoint Protection Health

Microsoft Defender and anti-malware health from the device agents - protection state, real-time scanning, signature age, tamper protection and risky exclusions, scored per device with no cloud connection required. Connect Defender for Endpoint to add alerts, incidents and exposure.

Per-Device View

Drill into any single machine: installed apps with the minutes they're actually used, zombie-app categorisation and licence-reclaim potential. Spot the software nobody opens and the seats you're paying for twice, device by device.

Advisory Remediation Agent

An agent that reviews the estate and proposes the next fixes - patch this, remove that, reclaim these seats - as reviewable recommendations with the evidence behind them. Autonomy tiers and a kill switch keep you in control: it suggests, you approve.

Everything below shipped in the June release and still applies - Workplace Automation, live connectors and the executive dashboard.

Workplace Automation - remote fixes, done safely

A curated library of 17 maintenance, diagnostics and patching actions you can run on any managed device, from the console, without a single inbound connection to the client network.

  • Deploy missing Windows updates on demand - scan any device for what's not installed, then push security updates (or everything) with a per-run cap. A required reboot is reported back, never forced on the user.
  • Fix the everyday tickets remotely - reclaim disk space, restart print spoolers, flush DNS, rebuild search indexes, reset Windows Update, repair system files, run Defender scans, resync clocks and refresh Group Policy.
  • Diagnose before you act - read-only battery health, device health (pending reboots, disk health, free space) and network diagnostics give first-line answers in minutes, not site visits.
  • Refresh inventory instantly - trigger an on-demand inventory sync from any device the moment you need current data, instead of waiting for the daily schedule.
  • Curated, not open-ended - only APaaS-authored automations exist. There is no console for ad-hoc scripts, so nothing unapproved can ever reach a device.
  • Integrity-pinned execution - every action carries a SHA-256 fingerprint; the device agent verifies it before running and refuses anything that doesn't match, byte for byte.
  • Outbound-only by design - devices poll for work over HTTPS. No inbound ports, no new firewall rules, no remote-access tooling for your security team to worry about.
  • Audited end to end - every dispatch records who, what, which devices and the outcome. Higher-impact actions ship disabled until a platform admin explicitly enables them.
Built for Cyber Essentials Plus environments: conservative by default, evidenced by design, and risk-graded from read-only diagnostics to admin-gated patching.

Connectors - your inventory, from wherever it lives

New Integrations area connects APaaS Assure directly to the tools UK estates actually run on.

Microsoft Intune - live

Connect with a per-tenant app registration and pull managed devices and detected applications straight from Microsoft Graph. Test the connection in one click, sync on demand, and watch new software land in your estate view minutes later. Credentials are encrypted at rest and write-only.

SCCM / ConfigMgr

Upload an installed-software report from the SCCM console and we aggregate per-device rows into your estate automatically - flexible column handling included. Site configuration is stored ready for the APaaS on-prem gateway, so live pull arrives without re-onboarding.

Universal CSV ingest

Drag and drop Intune exports, SCCM reports, Tenable exports or generic ITAM lists - the format is auto-detected, previewed, and imported with full audit history. Re-uploads are always safe: the newest data wins, nothing is double-counted.

The new executive dashboard - your estate in 30 seconds

The dashboard has been rebuilt around the question every IT leader asks first: what changed, and what should we do about it?

  • New CVEs captured today - every morning, the vulnerabilities our overnight NVD and CISA KEV sync found in your estate, ranked by exploitation and severity, with affected installs and clients. Flip to a 7-day view for the weekly picture.
  • New applications found - anything seen for the first time in recent scans, with install counts and the source that found it. Shadow IT surfaces the day it appears, not at the annual audit.
  • Executive view of the estate - one line per client: devices and reachability, products, estate-wide CVE exposure, actively-exploited apps, SLA position and potential savings. Click through to detail.
  • Top 20 actions - a single prioritised to-do list: overdue KEV deadlines first, then actively exploited software, critical and high exposures, then the licence Remove/Reduce actions that pay for the platform.
Security and spend on one list, ranked the way a security lead would rank them - so Monday morning starts with action, not analysis.

Why this combination is hard to find anywhere else

RMM tools run scripts but don't know your risk. Vulnerability scanners know your risk but can't fix anything. ITAM suites know your licences but neither. APaaS Assure now does all four jobs in one console: unified inventory from agent, Intune, SCCM and ITAM sources · KEV-aware risk with SLA clocks · 5Rs licence rationalisation · and curated, integrity-pinned remote remediation - built in the UK, for UK Cyber Essentials Plus estates.

See the new release on your own estate.

UK-based onboarding · No procurement friction

Book a demo