- A central engine for endpoint posture improvements
- Excellent compliance reporting with customizable dashboards
- Scalability and expandability support any heterogeneous environment.
Information Security Analyst at Cleveland Clinic
Patch management makes it easy for out-of-band and in-band patching
What is our primary use case?
How has it helped my organization?
BigFix has helped us in improving the overall endpoint posture and lifecycle management of the workstations as well as applications.
What is most valuable?
- Compliance reporting is the best.
- Patch management makes it easy for out-of-band and in-band patching.
- Inventory correlation with third-party tools.
What needs improvement?
- Complex design and administration
- Offline management
- Remote support on unsupported platforms
- A large infrastructure required to implement for a medium-sized organization
- Also, I would like to see if BigFix could be application aware for more in-depth compliance and reporting.
Buyer's Guide
BigFix
June 2025

Learn what your peers think about BigFix. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Talent Acquisition Executive at a consultancy with 1,001-5,000 employees
It helps us manage over 25,000 workers at our work stations. Sometimes there is a lag time for this product.
Pros and Cons
- "The product is less costly when compared to other solutions, and this is a good solid solution for what we have paid."
- "It is user-friendly."
- "Sometimes there is a lag time for our users."
What is our primary use case?
My primary use case for this solution is for department management. It helps us manage about 25,000 individual workers, who are all at work stations.
How has it helped my organization?
The product is less costly when compared to other solutions, and this is a good solid solution for what we have paid.
What is most valuable?
It is very flexible, and very user-friendly.
What needs improvement?
I would like to see a system to erase a virus and then create an analysis to find a virus. This would be a nice additional feature for the product.
In addition, sometimes there is a lag time for our users.
For how long have I used the solution?
More than five years.
How is customer service and technical support?
The technical support was pretty good. The response time was good.
How was the initial setup?
I did not find anything difficult in the implementation process.
What about the implementation team?
When selecting a vendor, I think it is important to consider whether the product is going to be a long-term product. And, we also need to provide the best solution for the department.
What's my experience with pricing, setup cost, and licensing?
It is cheaper than other solutions on the market.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
BigFix
June 2025

Learn what your peers think about BigFix. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
AVP, aPaaS Engineer at a financial services firm with 10,001+ employees
The product is complicated to use, but the plugin development options are great
Pros and Cons
- "It has plugins development options, which are great."
- "The product is quite buggy and complicated to use."
It has plugins development options, which are great. However, the product is quite buggy and complicated to use.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder Director at Techsa Services
A single tool for patch compliance, security compliance & software compliance of an entire compute infrastructure
Pros and Cons
- "Patch Management for a variety of operating systems makes it valuable as we can rely on a single tool for obtaining patch compliance of the entire compute infrastructure."
- "Relay selection and availability needs improvement as an incorrect relay selected can cause network chokes."
What is our primary use case?
- Patch Management
- Software Distribution
- Security Compliance
- Software Compliance
How has it helped my organization?
Patch compliance has improved. Using software distribution, the software distributed in the environment has been standardized. With the same software versions across the environment, compatibility issues have come down with a reduction in helpdesk tickets arising out of different software versions. There is also a check on software assets by means of implementing the software inventory module and a great deal of software compliance has been achieved.
What is most valuable?
Patch Management for a variety of operating systems makes it valuable as we can rely on a single tool for obtaining patch compliance of the entire compute infrastructure. This also ensures that we do not need to have different skills for different OS patch requirements.
What needs improvement?
- Relay selection and availability needs improvement as an incorrect relay selected can cause network chokes.
- Client reporting to the console is a minor issue but definitely needs improvement.
- Reporting needs to be enhanced with maybe a simple GUI based report generator with drag and drop features to create a custom report. The current mechanism is a bit clunky by use of filters.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
No scalability issues. We have customers ranging from 250 endpoints to over 100,000 endpoints.
How are customer service and technical support?
Customer support is excellent, but involving customer support and crossing the initial hurdles of getting past the first level of support personnel sometimes takes a while. But once it lands with the right support people the support is excellent. Level 1 support from IBM definitely needs improvement.
Which solution did I use previously and why did I switch?
No other tools were used.
How was the initial setup?
The setup is pretty straightforward provided you have planned well for the deployment. Know the environment well prior to deployment: The architecture needs to be drawn up prior to deployment. Plan the deployment of main server, database server, BigFix application(s), relays, console, and finally the deployment of clients.
What about the implementation team?
We are a BigFix vendor. We rate ourselves as excellent subject matter experts. Given the exposure and experience of handling fairly large deployments on Bigfix, we have gathered vast knowledge in the Patch, Security & Software compliance space.
What was our ROI?
ROI is pretty quick if you consider Security & Software Compliance as your primary use cases as Patch Management and Software Inventory Management. It has worked out to be under six months in many of our deployments. You may not be able to directly attach a ROI for security, but given the fact that Bigfix has been able to address many vulnerabilities that arise out of non patching makes Bigfix a compelling investment
What's my experience with pricing, setup cost, and licensing?
Plan well to ensure you have a stable and scaleable deployment. If you have a need for many use cases: Patch Management, Software Distribution, Remote Control, OS Deployment, Software Asset Management, Vulnerability Management, Security Compliance, and Server Automation, make sure you prioritize your requirements before deployment. You should go about meeting the requirements in phases, not try and burn the entire ocean.
Which other solutions did I evaluate?
No other products evaluated.
What other advice do I have?
Get started with BigFix.
Disclosure: My company has a business relationship with this vendor other than being a customer:
IT Operations Manager at a tech services company with 10,001+ employees
Patch compliance reached 100%, but needs to improve Internet-based client management
Pros and Cons
- "Patch management, because it very much improved the patch compliance and has the capability to manage Windows and non-Windows clients."
- "Needs to improve Network Access Protection (NAP) technologies to prevent computers with vulnerabilities from gaining access to networks."
What is our primary use case?
Server management patch management and software deployment, where we have multiple platforms, such as Windows Servers, Linux, Unix, etc.
How has it helped my organization?
- Patch compliance reached 100%.
- Patch management, because it significantly improved the patch compliance.
What is most valuable?
Patch management, because it very much improved the patch compliance and has the capability to manage Windows and non-Windows clients.
What needs improvement?
- OSD and other features listed in SCCM, like desired configuration management
- Internet-based client management
- Offline patching of virtual machines
- Network Access Protection (NAP) technologies to prevent computers with vulnerabilities from gaining access to networks.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager of Outsourcing Projects Department & ISO20000, ISO27001, ISO22301 Management Representative at a tech services company with 501-1,000 employees
Software deployment in distributed environments, as it provides control over compliance and saves time
Pros and Cons
- "Vulnerability scanning and patch automation."
- "There is no support for patch management on SLES on IBM pSeries (only the Intel platform is supported)."
What is most valuable?
Vulnerability scanning and patch automation.
Also, software deployment in distributed environments, as it provides control over compliance and saves us a lot of time.
How has it helped my organization?
Before an internal IT team performed all these activities manually, which took time and did not guaranteed full control over compliance. These activities required access to a corporate network via LAN, because VPN often generated errors.
Now, the process is centrally controlled, reported, and has an independently formed location (also over Internet).
What needs improvement?
There is no support for patch management on SLES on IBM pSeries (only the Intel platform is supported). This should be improved as soon as possible. It is a stopper for us to roll-out BigFix to all datacenter servers (500+).
For how long have I used the solution?
About three years for PCs and one year for servers.
What do I think about the stability of the solution?
No issues.
What do I think about the scalability of the solution?
No issues.
How are customer service and technical support?
There was a technology consultant available in Poland, who was very helpful, but recently he has left and no one has replaced him.
Which solution did I use previously and why did I switch?
Yes, Itelligence Germany uses HP automation and we had a pilot implementation.
How was the initial setup?
We have complex requirements.
What's my experience with pricing, setup cost, and licensing?
We offer BigFix as a service for our datacenter hosting customers.
Disclosure: My company has a business relationship with this vendor other than being a customer: IBM partner.
Rational Architect, BigFix & MobileFirst Protect Technical Presales at a tech services company with 1,001-5,000 employees
The architecture for patching and the 100% correct reporting makes it stand apart from other solutions
Pros and Cons
- "The architecture for patching and the 100% correct reporting makes BigFix stand apart from other solutions."
- "The new EDR (Endpoint Detection and Response) feature, Detect, is new and still needs a few updates."
What is most valuable?
Patch is a given and it is the flagship feature since the late 1990s. The architecture for patching and the 100% correct reporting makes BigFix stand apart from other solutions. Software Distribution is another powerful and strong feature that automates deploying software and saves a ton of time. The BigFix framework also gives you the ability to remove software and updates files, like configuration.
How has it helped my organization?
Patching is completed usually within a day or two. 98% of the endpoints are patched in the first pass no matter if they are all the corporate or traveling.
What needs improvement?
The new EDR (Endpoint Detection and Response) feature, Detect, is new and still needs a few updates. This is close to being a great addition to help when an attack has occurred.
For how long have I used the solution?
Five years.
What do I think about the stability of the solution?
No stability issues. If relays are not configured correctly, then this can cause a performance issue. An occasional health check is needed to ensure the solution is running at peak performance.
What do I think about the scalability of the solution?
BigFix can scale up to 250,000 endpoints on one server.
How are customer service and technical support?
The deep technical resources are very good and can isolate an issue very quickly.
Which solution did I use previously and why did I switch?
We started with SCCM and decided to switch because of inaccurate reporting, limited OS support, and we were unable to patch remote endpoints.
How was the initial setup?
Initial setup is very simple. With the Web User Interface, it makes the learning curve very short.
What's my experience with pricing, setup cost, and licensing?
I would stay with the Managed Virtual Server license model, which is a 1-to-1 license per OS whether it is virtual or physical.
Which other solutions did I evaluate?
Yes. SCCM, LANDESK, Altiris, and Tanium.
What other advice do I have?
You will not be impressed with the looks of the reports, but they are accurate. The BigFix.me forum is a great place to learn from others.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Senior Desktop Engineer at a tech services company with 501-1,000 employees
Allowed us to proactively seek out issues as well as quickly react to issues and target only computers which needed fixes
Pros and Cons
- "Ability to run custom reports and custom relevance."
- "We need a much better multi-tenant option."
What is most valuable?
Ability to run custom reports and custom relevance.
How has it helped my organization?
It allowed us to proactively seek out issues as well as quickly react to issues and target only computers which needed fixes. It was very easy to streamline down to what was needed.
What needs improvement?
We need a much better multi-tenant option.
We had 60 plus divisions and there was no real way to effectively give those people the help at the division sufficient rights within the console to see just their responsibilities. We wanted Bob at one of our divisions to have console access and only be able to manage his computers. We were not able to find a way to effectively do this. They had a web console that did not really handle our needs.
My current company is a consulting firm. If they had a better way to have multi-tenant access, this could be a product that could potentially do great good for us. As it was, when I last used it, it would not work for us without setting up a new instance for every customer we manage. Not really effective for our needs.
For how long have I used the solution?
I have used it for about four years.
What do I think about the stability of the solution?
Yes, occasionally we did.
What do I think about the scalability of the solution?
Yes, we did find some “quirks” and had to get creative, but we were able to work within the solution to streamline transfer speeds to not saturate networks between sites when synchronizing enormous install packages to our relays scattered around the country. Also, we could not easily scale the management to multiple tenants as we hoped and as we were able to do with other products in the past.
How is customer service and technical support?
I didn’t have to deal with them much. Others did. We frequently found that we were bringing solutions to them.
How was the initial setup?
I did not do the initial setup.
What's my experience with pricing, setup cost, and licensing?
This was not my responsibility.
Which other solutions did I evaluate?
I was not the decision-maker here.
What other advice do I have?
It is a great product. Spend some time really learning about the capabilities and how things are organized within the product. Then, spend some time really planning your structure and how the organizational groups should play out. It will make things a lot easier down the road when you need to send something to just one area of your business. Unfortunately, it is usually after a product is implemented that we truly understand how to best implement for our environment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free BigFix Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Configuration Management Patch Management Unified Endpoint Management (UEM)Popular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
HP Wolf Security
Microsoft Configuration Manager
Workspace ONE UEM
Symantec Endpoint Security
Trellix Endpoint Security Platform
Red Hat Ansible Automation Platform
Tanium
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Buyer's Guide
Download our free BigFix Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between BigFix And Carbon Black Cb Defense?
- SCCM vs BigFix: what are pros and cons?
- What is the biggest difference between BigFix and BMC TrueSight Server Automation?
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?