Discover and Manage Assets
Qualys ETM Identity tracks every asset in your environment independently. It provides visibility into identities and infrastructure across your organization, enabling you to evaluate your security posture, prioritize risks, and investigate identity-related findings.
By maintaining a well-organized and continuously updated asset inventory, your security teams can:
- Identify vulnerabilities before they are exploited
- Prioritize risk mitigation based on asset criticality
- Ensure compliance with internal policies and external regulations
- Respond swiftly to incidents with accurate context
ETM Identity supports two methods of obtaining asset inventory:
- Unified Asset Inventory (UAI) – a centralized inventory that consolidates assets from multiple Qualys modules and supports external integrations into a single asset repository.
- Asset Inventory (non-UAI) – the traditional inventory model where ETM Identity uses asset information available through the standard Qualys Asset Inventory (CSAM) and identity-specific discovery.
The asset inventory model available to your deployment determines the types of assets that are available, the navigation experience, and certain advanced capabilities. Both deployment models continue to provide ETM Identity functionality, but UAI delivers a broader and more unified asset view across the Qualys platform.
Unified Asset Inventory (UAI)
Unified Asset Inventory (UAI) provides a single, centralized inventory for assets across hybrid environments. Instead of maintaining separate inventories for different asset classes, UAI consolidates identities, compute, applications, containers, storage, certificates, network resources, and other supported asset types into a single unified repository.
For ETM Identity, UAI currently supports identity asset types, including users, groups, roles, tenants, and policies. This unified model enables consistent tagging, search, and cross-platform visibility across all supported assets.
Key advantages include:
- Single source of truth for multiple asset classes
- Unified tagging across different asset types
- Cross-asset search and correlation
- Support for cloud identity providers such as Microsoft Entra ID and Okta
- Expanded inventory for identities and infrastructure assets
..This feature is available on request. Contact Qualys Support or your Technical Account Manager (TAM) to activate it for your account
To know more about the UAI Asset inventory, refer to the Discover and Manage Assets from Unified Asset Inventory section.
Asset Inventory from Qualys Application (Non UAI)
Non-UAI deployments use the standard Qualys Asset Inventory managed through CyberSecurity Asset Management (CSAM). This inventory consolidates assets discovered through active scanning, agents, and network discovery and provides visibility into hosts, installed software, open ports, and identity assets required by ETM Identity.
This deployment continues to provide comprehensive identity visibility and risk assessment while using the traditional asset inventory architecture instead of the unified repository.
To know more about the Asset inventory from Qualys applications, refer to the Manage Asset Inventory from Qualys Applications section.
Common Functions Available Across all Tabs
| Function | Description |
|---|---|
| Search for assets | Search using Qualys Query Language (QQL) for a specific time frame. Date searches evaluate UTC format for all date-related tokens; results may still display in your local time zone. |
| Download report | Download the asset list using the download icon, choosing a report format. |
| Bar chart representation | View bar charts of the top hardware and operating system categories. Click a bar to see the related asset list; toggle the chart on or off. |
| Quick Actions menu | View asset details, or add and remove tags on an individual asset. |
| Actions menu | Select multiple entries and apply bulk actions — Add Tags, Remove Tags, Activate Assets, or jump to the Asset Activation Workflow. |
| Quick Filters | The left pane shows total matching assets, broken down by Source, Manufacturer, and Tag, with asset counts you can click through. |
| Group By Filters | Group assets by criteria such as external attack surface, operating system, hardware, or AWS — some categories include further subcategories. |
How ETM Identity Obtains Asset Inventory
The following diagram summarizes how asset information is made available to ETM Identity.
|
Deployment Type |
Asset Source |
Inventory Available to ETM Identity |
|---|---|---|
|
Unified Asset Inventory (UAI) |
Unified Asset Inventory |
Users, Groups, Roles, Tenants, Policies, Active Directory assets, and other supported unified asset classes |
|
Qualys Asset Inventory (non-UAI) |
Standard Qualys Asset Inventory (CSAM) |
. |
UAI vs. Non-UAI Feature Comparison
The following table summarizes how core capabilities differ between tenants running Unified Asset Inventory and tenants from the Qualys application.
|
Capability |
Unified Asset Inventory (UAI) |
Qualys Asset Inventory (non-UAI) |
|---|---|---|
|
Centralized unified asset repository |
✔ |
— |
|
Identity assets (Users, Groups, Roles) |
✔ |
✔ |
|
Tenants and Policies in Inventory |
✔ |
— |
|
Unified asset tagging across asset classes |
✔ |
— |
|
Global search across multiple asset types |
✔ |
— |
|
Cross-asset visibility across identities, compute, storage, applications, containers, and certificates |
✔ |
— |
|
Configure Active Directory connectors |
✔ |
— |
|
Configure Microsoft Entra ID connectors |
✔ |
— |
|
Configure Okta connectors |
✔ |
— |
|
Dynamic tagging using QQL for identities |
✔ |
Asset Criticality Score configured through Configurations |
|
Automated ACS inheritance through privileged groups |
✔ |
— |
|
RBAC-based access control |
✔ |
✔ |
|
Active Directory assets available in Inventory |
✔ |
Host inventory available through standard Asset Inventory |
|
Host inventory |
✔ |
✔ |
|
Software inventory |
✔ |
✔ |
|
Open Ports inventory |
✔ |
✔ |
|
Vulnerability findings |
✔ |
✔ |
|
Identity misconfiguration findings |
✔ |
✔ |
|
Active Directory Monitoring |
✔ |
✔ |
Choosing the Appropriate Inventory Model
If your ETM Identity deployment uses Unified Asset Inventory (UAI), you benefit from a unified asset repository that correlates identities with infrastructure and cloud assets, enabling richer search, tagging, and cross-asset analysis.
If your deployment uses the standard Asset Inventory (non-UAI) model, ETM Identity continues to provide identity risk analysis using the traditional Qualys Asset Inventory, including hosts, software, open ports, vulnerabilities, and identity-related findings.
This distinction helps you understand how ETM Identity populates its inventory and which capabilities are available based on your deployment.
Related Topics
Manage Asset Inventory from Qualys Applications