We use this solution for vulnerability management and patch management. We use BigFix to get information about the vulnerabilities that exist in the environment. We complete prioritization of those vulnerabilities and provide recommendations to the remediation teams. We assist the teams in case of any issues with remediation.
IBM Watson Cloud BigFix Security and Compliance SME at a computer software company with 10,001+ employees
Patch management service reliable at identifying vulnerabilities and providing recommendations
Pros and Cons
- "The patch management and the BigFix Inventory have been the most valuable features."
- "The BigFix Inventory could have an increased scope regarding the tools that can be detected. It does not cover all the possible software installed in Asset."
What is our primary use case?
How has it helped my organization?
If our customer has a high number of critical vulnerabilities inside their environment, we use BigFix to do the patching. We are able to decrease the number of high and critical vulnerabilities by at least 30% in six months. This is a huge improvement and makes the environment more secure.
What is most valuable?
The patch management and the BigFix Inventory have been the most valuable features.
What needs improvement?
The BigFix Inventory could have an increased scope regarding the tools that can be detected. It does not cover all the possible software installed in Asset. We used the BigFix module in a ILMT module to have the proper coverage. If we had the two of them combined, this would really assist with the inventory of software.
Sometimes we may have a few issues with the fixlet Relevance where the Windows patches sometimes identifies as a false positive. We have opened tickets with the support team. They fixed that as soon as possible.
Buyer's Guide
BigFix
January 2026
Learn what your peers think about BigFix. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
What do I think about the stability of the solution?
This is a stable solution. The only issues that we have had in the past with BigFix is with the sizing. If you don't perform the right sizing of the BigFix server, you may have performance issues. We have had no major issues with the performance itself.
What do I think about the scalability of the solution?
This is a scalable solution. They are releasing a lot of improvements in the latest versions of BigFix. That will help us monitor how the tool is performing and if it would require change or increase of the hardware or the environment to make it run in a smoother way. The scalability has improved a lot.
How was the initial setup?
The initial setup is straightforward. It involves sizing and designing the architecture to put BigFix in place and set up the proper relays. We experienced no issues doing this.
To begin the setup, we tried to identify the baseline of the customer to see how many endpoints the customer has. We also looked at the locations to know if we do need to put a low-level or top-level relay in place in each one of the data centers. In our case, as it's a huge environment, we set up two top-level relays and then a low-level relay in a different data center to not put a high load into network bandwidth when we try to transfer patches over the network.
What about the implementation team?
We implemented this solution in-house.
What other advice do I have?
The extent to which we use the different features of BigFix depends on the needs of our customers. We often propose new features when the need arises.
BigFix is one of my favorite tools. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Consultant at a insurance company with 10,001+ employees
Reasonable price, reliable, and easy to understand
Pros and Cons
- "Almost every feature is wonderful in BigFix. It is very stable, and we can rely on it. It is an awesome tool."
- "It can be improved speed-wise. They can make it a little bit light. If you do any query for servers in bulk, it can take some time. Similarly, creating a job can take some time."
What is our primary use case?
We're using it for Windows patching and inventory. We are totally dependent on BigFix for these tasks.
What is most valuable?
Almost every feature is wonderful in BigFix. It is very stable, and we can rely on it. It is an awesome tool.
What needs improvement?
It can be improved speed-wise. They can make it a little bit light. If you do any query for servers in bulk, it can take some time. Similarly, creating a job can take some time.
Automation is everything, and we're looking for more automation. If we have different jobs to secure the environment, such as with server hardening, and I want a particular service that is not running, BigFix should automatically check it and do the deployment. It can send a message about why a particular job is not working on the servers or not communicating properly with Active Directory. We should be able to check the reason. We just want just a little bit of monitoring in that area.
For how long have I used the solution?
I have been using this solution for more than three years.
What do I think about the stability of the solution?
It is very stable. You can trust and rely on an automated job. It will definitely work. You get a proper message if it is not working for any particular reason. It gives you a complete picture.
What do I think about the scalability of the solution?
It is definitely scalable. We are managing around 20,000 servers with it, and we have more than 100 users. We are providing web report access to application users as well. We create a job and provide access to different teams, such as the monitoring team, backup team, and security team to deploy the job. So, it is definitely scalable.
How are customer service and support?
I have personally worked with them because I request them to create access for all my colleagues. If required, I log a case in BigFix. Earlier the support was very good for BigFix, but now, HCL is facing some challenges. We are getting support, but we need more in that area. Their support was much better as compared to this time.
Which solution did I use previously and why did I switch?
I have not worked with a similar solution previously. We purchased Tanium
two to three years ago. It is being used by a different team, but we are still using BigFix. We want to replace BigFix, but we are not able to because we are more comfortable with it. So, we are continuing with BigFix.
How was the initial setup?
It is very easy. It is simple to understand. Even though I had requested training for BigFix, I would have been able to work with it without training.
What's my experience with pricing, setup cost, and licensing?
Its price is very reasonable.
What other advice do I have?
I have been recommending BigFix to my friends and different companies. We are very happy with BigFix.
I would rate it a nine out of ten. It is an excellent product, but there is always room for improvement.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
BigFix
January 2026
Learn what your peers think about BigFix. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Marketing Coordinator and Project Manager at a computer software company with 1-10 employees
Excellent support, highly scalable and reliable
Pros and Cons
- "The most valuable feature of BigFix is the software deployment."
- "The solution could improve by adding support drivers for different systems and equipment. When you have a lot of different computers if they could fix how to install any updates, firmware, or drivers for different systems or servers it would be good."
What is our primary use case?
I have used BigFix for patch management, compliance for security, and inventory OS deployment to software.
What is most valuable?
The most valuable feature of BigFix is the software deployment.
What needs improvement?
The solution could improve by adding support drivers for different systems and equipment. When you have a lot of different computers if they could fix how to install any updates, firmware, or drivers for different systems or servers it would be good.
In an upcoming release, they should add database support included and deliver the solution as a cloud service similar to the services on Microsft Azure.
For how long have I used the solution?
I have been using BigFix for approximately 10 years.
What do I think about the stability of the solution?
BigFix is extremely stable.
What do I think about the scalability of the solution?
I have found BigFix to be highly scalable. BigFix can be used on 10 computers, 10,000 and 1,000,000 computers. It doesn't matter the number of computers.
We have approximately 50 people using this solution in my organization. We use the solution daily.
BigFix is suitable for both SMB and enterprise customers.
How are customer service and support?
The support from BigFix is excellent.
I rate the support from BigFix a five out of five.
Which solution did I use previously and why did I switch?
I have used other similar solutions previously. The main difference between the other solutions and BigFix is you can do more for a lesser price with BigFix. You can do more with less effort to get it up and work properly. Its broader support for different OS systems.
How was the initial setup?
I rate the implementation difficulty of BigFix a five out of five.
If you choose, for example, Microsoft SSM Configuration Manager, you need a lot of servers, databases, and the configuration of firewalls, et cetera. It's a tremendous cost before you get up and running. With BigFix, in 10 to 15 minutes, you're up and running. Everything is working well.
What's my experience with pricing, setup cost, and licensing?
The price of BigFix is better than the solutions. You are able to pay monthly or annually. There are not any hidden costs with BigFix. There is an additional cost for the SQL database.
I rate the price of BigFix a five out of five.
What other advice do I have?
I would recommend this solution to others. I would advise others the solutions are suitable for small to medium-sized companies, and enterprises.
I rate BigFix a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Vice President, Solutions Group at a tech vendor with 51-200 employees
Supports almost every OS on the market, and works very well for security, mobile device management, and endpoint management use cases
Pros and Cons
- "It is for multiple use cases. A lot of people are looking at it just for security, and that's really endpoint security. The endpoint management part of it in terms of being able to constantly do patching for Windows, Unix, macOS, Cloud, Raspberry, VMware, and all Linux flavors is important, and they are very good at that. They have support for virtually every OS on the market."
- "I remember doing restarts a few times. So, making sure that it is rock solid from an executable perspective is important."
What is our primary use case?
We are a global security and cloud integrator, and we are also a reseller with a capability of up to 69 brands, but we're not married to anybody. Our goal is to give customers exactly what they need based on the scenario. We build everything that we sell. So, we have a large distribution partner that enables us to resell a lot of things. We definitely and always see what's hot in the market, and we are constantly reviewing technologies.
Patching and mobile device management are probably two of the biggest use cases of BigFix.
In terms of the version, some of the clients have the latest version. BigFix is not a subscription as a service. It is not a SaaS model. It is an on-prem model for infrastructure teams to manage folks through the web or through the network, and it is not provided as a service. There is no open-source capability, so it doesn't really have an ecosystem around it. It's basically sold to clients for specific use.
How has it helped my organization?
For security these days, patching is obviously mission-critical. If you leave something unpatched, the vulnerability is easily found by the adversary, so that's critical.
Mobile device management is also critical from the security aspect. BigFix is useful in scenarios where if a device is lost, you can disable it, and you can wipe it. All the company data that is available is completely encrypted, and it is basically illegible or not usable. People even have BigFix Mobile that they put on phones and other peripheral devices. You are basically putting a wrapper around the applications that are company applications in the bring your own device (BYOD) scenario.
What is most valuable?
It is for multiple use cases. A lot of people are looking at it just for security, and that's really endpoint security. The endpoint management part of it in terms of being able to constantly do patching for Windows, Unix, macOS, Cloud, Raspberry, VMware, and all Linux flavors is important, and they are very good at that. They have support for virtually every OS on the market.
A lot of people also use it for infrastructure value. HCL has changed the focus a little bit because it was originally looked at as a pure security tool on the IBM side for mobile device security, but since HCL took it over, it has become more focused on other different components. They've created REST APIs for the cloud, and there is now a scripting language that's associated with it. So, there are more broad use cases because the industry requires that. They also have their own development tool in BigFix.
HCL is India-based, and they've done a good job with BigFix, and they're also able to deliver the software at a lower price now. The integration is better with other security and vulnerability management tools. To remediate endpoint issues that are out there, they integrate with Tenable, Qualys, and others. So, you can manage all of your patches and fixes through one platform, even for all cloud services, which is a good thing.
Training is obviously important, and HCL has done a better job than IBM at making that training available. Usually, there are different ways to do that, such as through video or self-service, etc.
What needs improvement?
I remember doing restarts a few times. So, making sure that it is rock solid from an executable perspective is important.
For how long have I used the solution?
I have been working with all kinds of security tools, including this one, since 2001 or so. It has been 21 years.
How are customer service and support?
We have interacted with them. They've been good and better probably in BigFix than some of the other tools that they acquired in that IBM divestiture.
How was the initial setup?
It is pretty easy to implement.
What other advice do I have?
I would rate it an eight out of ten. It does everything reasonably well. There are so many competitors who do just one piece of this, or they're not really head-up competitors because some are into mobile security, and some are more into mobile endpoint management and patching.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Senior System Administrator at a legal firm with 201-500 employees
Effective deployments, highly reliable, and responsive support
Pros and Cons
- "The most valuable point is when you deploy an application, you have to make sure that the application has been deployed to all computers and that is working perfectly. This solution works well at deployments."
- "Sometimes the workstations communicate back to the BigFix server two or three days in a week or something similar. Sometimes there can be a delay reporting back to the server for a variety of reasons, such as users turning their computer off when they go home. When the user comes back and turns the computer back on BigFix needs to synchronize and sometimes it can take some time, approximately one week. The communication between the agent and the server should be faster, there is room for improvement in this area."
What is our primary use case?
We use BigFix for deploying applications for updating, setting up configurations, making modifications, or customizing Windows. For example, what are the applications that need to run, and what configure is needed.
What is most valuable?
The most valuable point is when you deploy an application, you have to make sure that the application has been deployed to all computers and that is working perfectly. This solution works well at deployments.
Other solutions can have failures, such as ManageEngine, and you have to deploy the application again. In BigFix, once the computer has communicated with the BigFix server, the agent workstation, you can be sure that the application will be deployed and delivered properly.
What needs improvement?
Sometimes the workstations communicate back to the BigFix server two or three days in a week or something similar. Sometimes there can be a delay reporting back to the server for a variety of reasons, such as users turning their computer off when they go home. When the user comes back and turns the computer back on BigFix needs to synchronize and sometimes it can take some time, approximately one week. The communication between the agent and the server should be faster, there is room for improvement in this area.
For how long have I used the solution?
I have been using BigFix for approximately two years.
What do I think about the stability of the solution?
BigFix is reliable and stable, it is perfect.
Performance-wise is the best. When you have to do deployments you are sure that all the workstations will receive it, even though that there is sometimes a delay in reporting back to the server. The only time the deployment would not work is if the computer is decommissioned or not available.
What do I think about the scalability of the solution?
BigFix is simple to scale, we are using the solution regularly. We use it every other week whenever we have meetings, we rely on it.
We have approximately 10 technicians and 3,000 users who receive a patch or use the solution in some way.
How are customer service and support?
We have not had any big issues that would need the support. However, we did have some minor issues and the support was good and responsive.
Which solution did I use previously and why did I switch?
I have used ManageEngine previously.
In my usage, I have found BigFix is more professional than ManageEngine. The reason that I'm saying this is when you deploy an application, you are sure and you are guaranteed that all workstations will receive it. However, for the ManageEngine, for some reason, you will find it may fail for 13 workstations. You might have to redeploy again, otherwise, you have to do it manually.
One of the positives of ManageEngine is it can be easy for users to deploy an application compared to BigFix.
How was the initial setup?
The deployment process of BigFix was straightforward. You need to have a small number of programming skills or scripting skills to complete it. If you have skills, it is very easy to deploy. For somebody who's experienced, and has knowledge of some programming or scripting skills, it's very easy.
What about the implementation team?
There were approximately three people, the vendors, and our technical teams that did the implementation.
BigFix requires specific maintenance, whenever there is a new release we manage it.
What's my experience with pricing, setup cost, and licensing?
You are charged per server and per workstation when using BigFix. ManageEngine is a lot cheaper than BigFix. There are some additional costs, such as support.
What other advice do I have?
I recommend BigFix as long as they have the budget. If they don't have that much money, they can use ManageEngine, which is satisfying for small and medium companies. For example, companies that have 250 computers. I have used ManageEngine at companies that had multiple locations. You can use some ManageEngine on one central location and then deploy it to all your branch offices.
I rate BigFix a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cloud Analyst at a tech services company with 51-200 employees
Provides good reporting, Windows patching, and hardware and software inventory
Pros and Cons
- "The most valuable features of the solution are Windows patching and the hardware and software inventory."
- "The solution’s pricing could be improved."
What is most valuable?
The most valuable features of the solution are Windows patching and the hardware and software inventory. The solution's reporting is very good in a single console.
What needs improvement?
The solution’s pricing could be improved.
For how long have I used the solution?
We have been doing a POC for the last three months with BigFix's Evolution version.
What do I think about the stability of the solution?
I rate the solution a nine out of ten for stability.
What do I think about the scalability of the solution?
Around 500 users are using the solution in our organization.
I rate the solution an eight or nine out of ten for scalability.
Which solution did I use previously and why did I switch?
Intune only supports Windows and does not support other platforms like Unix and Linux. On the other hand, BigFix supports all platforms.
How was the initial setup?
The solution's initial setup is simple and not complex. I have done the full server installation and configuration thrice, and it's not complex.
What's my experience with pricing, setup cost, and licensing?
On a scale from one to ten, where one is expensive and ten is cheap, I rate the solution's pricing one out of ten.
What other advice do I have?
Patch management is configured in existing endpoint computers. We are pushing the custom policy deployment in weekly patches, which require critical and important patches. Since it's a by-policy, it's pushed automatically. We have enabled the solution's remote endpoint management option, but we are primarily focussing on licensing hardware and software inventory.
BigFix's integration with our IT infrastructure was easy. I would recommend the solution to other users.
Overall, I rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Administrator at a tech vendor with 10,001+ employees
Automation tool that allows us to provide ad-hoc requests
Pros and Cons
- "The most valuable features are patch management, software installation, and asset management."
- "I would like the dashboard to be improved to show the problematic machines and good machines."
What is our primary use case?
The solution is being used for automation. We deploy the package as customized software, and we provide ad-hoc requests via BigFix.
The solution is deployed on the cloud, but it can also be installed on-premises.
What is most valuable?
The most valuable features are patch management, software installation, and asset management.
What needs improvement?
I would like the dashboard to be improved to show the problematic machines and good machines.
For how long have I used the solution?
I have used BigFix for five years.
What do I think about the stability of the solution?
It's very stable.
What do I think about the scalability of the solution?
We can scale up or down according to our needs.
How are customer service and support?
Technical support is responsible and knowledgeable. They're supportive when we have any issue in the environment and require help from them.
We can troubleshoot the tool. If there are any major issues, we go to the support team for help.
I would rate technical support as five out of five.
How was the initial setup?
The setup is easy. I would rate it as five out of five.
It requires maintenance every month. Only two or three people are needed for maintenance.
What about the implementation team?
We used a third-party consultant.
Which other solutions did I evaluate?
BigFix is very easy to use. I have also used SCCM, but there were issues with the machine not restarting. There were many problems produced in the environment and in the agent. In BigFix, I haven't seen any issues with the agent. It works smoothly.
What other advice do I have?
I would rate this solution as 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VP of Solutions at a tech vendor with 51-200 employees
It can manage lost devices, so you can wipe them remotely to ensure the IP doesn't get out in public.
Pros and Cons
- "BigFix can manage lost devices, so you can wipe them remotely to ensure the IP doesn't get out in public. Unified endpoint security is a new perspective. I know that HCL is also collaborating with IBM, but I'm not sure if there is any cooperation between them and MaaS360 or other endpoint components."
- "The main shortcoming of BigFix was integration with vulnerability management. If you had a vulnerability in your software and BigFix on the endpoint, you needed integration with Qualys, Tenable, or another vulnerability management solution to fix that. It was like, "Okay, we can identify issues, and get that information back from the endpoint, but what are we doing about it?""
What is our primary use case?
We used BigFix internally at my previous org. My current company is a BigFix reseller. A lot of people are looking at endpoint security now, but we primarily used BigFix for true endpoint management.
Endpoint security has become the main thing, but we used BigFix for patching and a lot of the other use cases in the past, and I think it worked pretty well. Obviously, the market has gotten much more crowded.
What is most valuable?
The UEM component evolved into reunified endpoint management. Many of our customers used it for deployment and patching. HCL has a new endpoint security approach now, but it was really for managing that.
BigFix can manage lost devices, so you can wipe them remotely to ensure the IP doesn't get out in public. Unified endpoint security is a new perspective. I know that HCL is also collaborating with IBM, but I'm not sure if there is any cooperation between them and MaaS360 or other endpoint components.
What needs improvement?
The main shortcoming of BigFix was integration with vulnerability management. If you had a vulnerability in your software and BigFix on the endpoint, you needed integration with Qualys, Tenable, or another vulnerability management solution to fix that. It was like, "Okay, we can identify issues, and get that information back from the endpoint, but what are we doing about it?"
What do I think about the stability of the solution?
The stability has been solid when I've used BigFix with customers in the past. In that space, I don't think everybody is doing as much innovation as in other areas in the endpoint management or security market.
I delineate between those two because endpoint management is a different use case. I think it's probably become a lot more important since the pandemic started.
What do I think about the scalability of the solution?
We never had any challenges with scalability. Some of our customers had tens of thousands of endpoints.
Which solution did I use previously and why did I switch?
I used a few competitors a while back, but I don't know what LANDESK is up to these days. They were a big player in the market, but I don't know what other contenders are out there now.
What's my experience with pricing, setup cost, and licensing?
The patching tool is $250 per client device per year. The inventory and discovery tool is $15 per client per year. They have a lifecycle management tool that is the central component for managing endpoints, which costs around $43 per year. BigFix Compliance is the other part, and that's also around $43.
What other advice do I have?
I rate BigFix nine out of 10. I wouldn't recommend it to everyone. It depends on your infrastructure. If you have a pure Microsoft shop, you can probably get by deploying and managing endpoints their way.
However, if you have a mixed environment of any kind, BigFix is good at what it does. Patch management is vital for security posture, so I wouldn't be surprised if BigFix is becoming increasingly popular.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free BigFix Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Endpoint Protection Platform (EPP) Configuration Management Patch Management Unified Endpoint Management (UEM)Popular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
HP Wolf Security
Cortex XDR by Palo Alto Networks
Tanium
Fortinet FortiClient
Trellix Endpoint Security Platform
Microsoft Configuration Manager
Workspace ONE UEM
Red Hat Ansible Automation Platform
Symantec Endpoint Security
Check Point Harmony Endpoint
NinjaOne
Buyer's Guide
Download our free BigFix Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between BigFix And Carbon Black Cb Defense?
- SCCM vs BigFix: what are pros and cons?
- What is the biggest difference between BigFix and BMC TrueSight Server Automation?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?


















