ENDPOINT360 The intelligent operations layer for ConfigMgr. Coming soon. Now selecting Founding Design Partners for early access.
AIR-GAP NATIVE NO CLOUD DEPENDENCY KERBEROS SSO · ZERO NEW AUTH NIST 800-53 EVIDENCE CISA KEV / BOD 22-01 CLOCKS AUDITABLE PS1 INSTALLER
// From feed to proof

Turn a vulnerability feed into
closed, documented remediation

Most consoles show you the problem. Endpoint360 runs the whole loop, and writes the evidence trail your assessor asks for, while it happens.

A KEV lands at 02:00

The feed ingests (connected fetch or offline bundle, your posture decides), reconciles IAVA → CVE → KB, and measures exactly who is exposed. Live, against your site database.

CRIT CVE-2026-31184 → KB5054321 KEV
CRIT 2026-A-0114 → CVE-2026-31184 KEV
HIGH CVE-2026-30977 → KB5054290
HIGH exposure:  1,412 of 18,240 devices require the fix

A campaign closes with proof

By the time your team sits down, Vanguard has already done everything except decide.

02:00 · CAMPAIGN OPENEDBoth SLA clocks running. Gap snapshot attached.
RA-5CM-4
02:01 · SCORED 92 · READYSix live telemetry checks. Weakest component named.
07:40 · ONE HUMAN DECISIONThe approver gets the brief by email, clicks once.
CM-3AC-5
07:41 · RINGS DEPLOY ON EVIDENCEPilot first; promotion when success is measured, halt if errors spike.
SI-2
CLOSED AT 96.2% · MEASUREDClosure is a measurement, never an assertion.
CA-7
STEP 01 · DISCOVER

See what your tools won't agree on

AdminService, direct SQL, CMPivot and the fast channel: one console over all of ConfigMgr. Vulnerability reconciliation maps IAVA → CVE → KB → deployment gap in seconds, a chain DoD admins have walked by hand for twenty years.

STEP 02 · DECIDE

One decision, fully briefed

The Ready / Review / Blocked confidence score is computed from your own live telemetry: catalog readiness, update hygiene, deployment conflicts, client-estate health, and pilot results, with an honest denominator that discloses what it couldn't measure.

STEP 03 · DEPLOY & PROVE

Evidence writes itself

Every gate stamps the NIST 800-53 controls it satisfies into an assessor-readable trail: who approved, what the exposure was, when each ring promoted, and the measured compliance that closed it. Audit questions become database queries.

72hthe response window governments now set for exploited-in-wild vulnerabilities; Vanguard runs on that clock
0internet dependencies in core operations; feeds ingest as offline bundles
1human decision per campaign with Vanguard Autopilot; everything else is machine
700+Configuration Manager classes reachable through one governed web console
// Flagship · Enterprise edition

Vanguard Autopilot

Attackers are about to move at machine speed. Vanguard is patch governance built to answer at the same speed: automated testing, scoring, and ring promotion on a 72-hour clock, with a human keeping the one decision that matters. Do less. Ship faster. Carry less risk.

SCORE ≥ 85READY
60 – 84REVIEW
< 60BLOCKED

A Blocked verdict stops execution until a named human accepts the risk in writing. Approval is always human. That line is never crossed.

01
KEV lands → campaign opens itselfBoth clocks start before anyone is awake. Unmapped KEVs raise incidents instead of waiting silently.
02
Self-scoring, self-submittingReady-verdict campaigns enter the approval queue with the evidence pre-assembled.
03
The decision comes to the deciderApprovers get an email brief (severity, deadlines, score, exposure) and a one-click link to sign.
04
Rings promote on evidence, not schedulesPilot success promotes the next ring; an error spike halts every deployment and raises the incident itself.
05
Dual authorization, distinct humansTechnical + Authorizing signatures enforced server-side: separation of duties an assessor can verify.
// The philosophy: why machine speed

The exploit window is collapsing. Your patch cycle has to collapse with it.

01 · THE SHIFT
AI changed the attacker's clockFrontier AI systems can already map a domain environment and locate its exploitable weaknesses in hours. As that capability spreads, working exploits will follow disclosures at machine speed, not researcher speed. That diffusion is a when, not an if.
02 · THE SIGNAL
Governments saw it firstFor vulnerabilities known to be exploited in the wild, government response windows have collapsed from 30 days toward 72 hours. That deadline exists because the time between disclosure and live exploitation is disappearing. Commercial estates face the same attackers, just without the mandate.
03 · THE ANSWER
Match machine speed with machine speedYou cannot answer AI-built exploits with a monthly change board. The counter is using AI and automation to compress patch testing, confidence scoring, ring promotion, and evidence to the same clock, while a named human keeps the approval. That is Vanguard.
// Editions & pricing

Turn the ConfigMgr you already own
into a modern operations workspace

In 30 days: overnight problems surfaced before your team logs in, support actions safely delegated to the help desk, recurring client repairs automated, and the admin hours you got back shown on a dashboard. No ConfigMgr replacement. No new endpoint agent. One annual subscription, three editions.

Core

See and Act
$5,000/ year starting
includes 2,500 active endpoints · annual billing

Everything the native console does, done better in a browser. If ConfigMgr can show it or do it today, Core makes it faster, web-native, and audited.

  • Dashboard, 24-hour change digest, Device 360 & inventory
  • CMPivot & Run Scripts web consoles, audited device actions
  • Software Catalog with approval queue
  • Patch visibility and manual deploys
  • Client health, infrastructure health & boundary views
  • Saved report library & ad-hoc SQL
Apply for access
MOST POPULAR

Professional

Automate and Delegate
$15,000/ year starting
includes 10,000 active endpoints · that is $1.50 per endpoint per year

Built for the ConfigMgr admins keeping systems management alive. Endpoint360 works for your team, not instead of it: it clears the repetitive work off your plate, closes tickets faster, and makes everything your team delivers visible to leadership. Compare the price to escalations, weekend patch work, and audit scrambles, not to other software.

  • Everything in Core, plus the capabilities ConfigMgr never shipped
  • Client-health scoring with approved remediation workflows
  • Governed incident records with owner and SLA clock
  • Service Desk delegation: a restricted technician surface
  • App Lifecycle & packaging pipeline
  • OSD Deployment Tracker & Software Portal curation
  • Deployment outlier clustering by model, driver, subnet, DP
  • Third-Party Catalog & Supersedence Guardian
Start as a Founding Partner · $9,500 Year 1

Enterprise + Vanguard

Govern and Prove
$30,000/ year starting
includes 10,000 active endpoints · annual billing

The concepts that exist nowhere in ConfigMgr. The full AI layer and machine-speed patch governance, for estates that answer to an auditor, a cyber insurer, a security framework, or a government mandate.

  • Everything in Professional
  • The complete AI layer: Knowledge Chat, anomaly agents, outlier explanations, NLP report builder, decision briefs. Off by default, provider-pluggable
  • Vanguard: machine-speed patch campaigns with ring promotion, halt controls, and dual authorization
  • Vulnerability reconciliation: CVE to KB, KEV, Tenable / ACAS
  • Evidence ledger: the export your auditor, insurer, or assessor asks for
  • Standard webhook or ITSM integration
Apply for access

The license metric is an active managed endpoint: a device with Configuration Manager activity in the last 45 days, excluding approved lab and test collections. The product measures it for you from the site database. Overage is handled with a warning and a renewal true-up, never a hard operational stop.

Growing past the included endpoints simple per-endpoint pricing, no cliffs
Additional endpoints are added at a simple per-endpoint rate, so one more device never doubles your invoice. Above 25,000 active endpoints, or across multiple hierarchies, air gaps, and high-availability site servers, we write a custom agreement around your environment. Not sure where you land? Apply and tell us your estate size; we will map the fit with you.
// The real question is trust, not price

Everything about how this is built
is a risk reducer

Modernizing ConfigMgr should not mean taking on a new attack surface, a new identity system, or a vendor you have to take on faith. Endpoint360 is deliberately the opposite.

01
Your infrastructureInstalls on the Windows Server and SQL instance you already own. No new servers, no cloud tenancy.
02
No new endpoint agentIt uses the ConfigMgr client already on your devices. Nothing new to deploy, patch, or defend on the estate.
03
Auditable installerOne readable PowerShell script. Government customers review it line by line before it ever runs.
04
Kerberos, no new authWindows Negotiate sign-on, roles mapped from the ConfigMgr security roles you already assigned.
05
AI off by defaultOne global switch, role-gated and audited, and provider-pluggable. Nothing depends on a model to work.
06
Every action auditedEach state-changing action writes an evidence row: who, when, what, and the outcome.
07
Air-gap capableNo internet dependency in core operations. Threat feeds ingest as offline bundles when you need them to.
08
28 years on the lineBuilt by an engineer who has run this product line since SMS 1.0 and supported it inside Microsoft.
≈ $24k/yr

The payback framing that matters: one reliably automated 10-hour-per-week workflow hands your senior admins back roughly $24,000 a year of their time for the work that actually needs them. Endpoint360 pays for itself by making the team you already have more effective, never by shrinking it. That is a case your admins can take to leadership with a straight face.

// Founding Design Partner program

Five partners.
Shape the product, own the price.

Ahead of general availability, we are selecting a small first cohort of production ConfigMgr shops as Founding Design Partners for early access. Real scarcity, not a countdown gimmick: when the five seats are taken, the cohort closes.

Cohort A · 5 seats · Early Access

The offer Cohort A

01Professional at $9,500 for Year 1 (list $15,000), covering up to 10,000 active managed clients, with a 30-day operational proof.
02Enterprise + Vanguard from $17,500 for Year 1 (list $30,000) when you bring strong access, metrics, and reference participation.
03Three-year price protection. The ramp below is agreed up front and does not move under you.
04Full upgrade credit. Your first-year purchase is credited toward Enterprise + Vanguard if you upgrade during the term. Plus a direct line to the engineer who builds the product.
Year 1
$9,500
Year 2
$15,000
Year 3
$15,000

Professional partner ramp, locked for three years. Enterprise + Vanguard ramps the same way from $17,500.

What we ask

01Production use. Endpoint360 runs against a real estate, not a lab curiosity.
02One 45-minute feedback session a month, four times, so we learn where it helps and where it does not.
03Sanitized before and after metrics we can publish, and a named testimonial once acceptance criteria are met.
04Up to two reference calls a year with prospective customers who run estates like yours.

Paid proof of value

A short, scoped, paid engagement with success criteria agreed before install, and fully credited to your annual purchase. We do not run free production pilots.

Core / Professional$2,50030 to 45 days · fully credited
Vanguard$5,000one campaign, end to end · fully credited

Included with every partner seat, on day one

01ConfigMgr Operations Baseline. Endpoint360 automatically produces your starting report: client health, patch status, infrastructure risks, stale deployments, and operational bottlenecks.
02Rapid Deployment Blueprint. Prerequisite checker, installation workflow, service-account guidance, firewall requirements, and validation tests.
03Five operational automation templates. Stale policy remediation, client-service recovery, cache cleanup, pending-reboot campaign, and update-scan recovery.
04Service Desk Role Pack. Prebuilt Tier 1, Tier 2, application-packager, patch-operator, and read-only security roles.
05Executive Value Dashboard. Devices repaired, recurring failures eliminated, technician actions delegated, campaigns completed, and the estimated admin time returned to your team.

Our guarantees

Operational Proof GuaranteeOnce the documented prerequisites are met, Endpoint360 establishes your baseline dashboard and completes one agreed test workflow within 30 days. If it cannot, we keep working at no additional charge until the acceptance criteria are met, or you may take a refund of the paid proof-of-value fee.
Evidence Readiness GuaranteeFor Vanguard pilots: an assessor-readable evidence trail for the campaign we run together. We never guarantee a patch-compliance percentage, because offline devices, maintenance windows, and your own decisions sit outside the product's control.

Apply to the Founding Design Partner program

Endpoint360 is not yet generally available. This is an application for early access, not a purchase. No obligation: it starts a conversation and reserves your place in line while seats remain. Expect a personal reply from the founder within two business days.

Goes straight to the founder. No sales sequence, no reselling your details.
Thanks. Your email client is opening with your application ready to send to hello@EndPoint360Solutions.com. If it did not open, email us directly and mention Founding Design Partner.
// A guided tour

Every module, and why it matters in 2026

One console over your whole Configuration Manager estate. Step through the modules: what each one is, and why an AI-era operations team needs it.

Universal Core

Operations Dashboard

24-hour change digest

The morning briefing for your estate: what changed in the last 24 hours, error trends, infrastructure status, and what needs attention. The whole picture before your coffee is cold.

Why now: WinForms makes you open five nodes to learn if last night went well. One glance replaces the ritual.
Operations dashboard
Enterprise

Vulnerability Intelligence

IAVA → CVE → KB → deployment gap

Reconcile threat feeds against what ConfigMgr has actually deployed. See every exposed device for a CVE or IAVA in seconds, with KEV due dates and CVSS front and center.

Why now: the chain DoD admins walk by hand every Patch Tuesday, automated. The single most-requested feature in every ConfigMgr shop.
Vulnerability Intelligence
Enterprise

Vanguard Autopilot

Governed remediation campaigns

A campaign board that scores, deploys, promotes on evidence, and closes on measured compliance, with dual-authorization and a NIST 800-53 evidence trail written as it happens.

Why now: exploits move in hours; change boards meet on Thursdays. Machine-speed remediation with the human reduced to one decision.
Vanguard campaign board
Universal Core

Patch Command Center

SUGs, rings, blast-radius preview

Compliance by software update group and collection, deployment rings at a glance, and a blast-radius preview that shows exactly what a deployment will touch, recorded as evidence before you commit.

Why now: "deploy and hope" is how outages happen. See the blast radius, then approve it.
Patch Command Center
Professional

App Packaging Pipeline

Drop-folder to ring promotion

Drop a package in a folder; it validates, creates the app, distributes, deploys to a pilot ring, and auto-promotes on success, with an approval gate for the rings that need a human.

Why now: packaging is where deployment errors are born. A pipeline with evidence beats a checklist and a prayer.
Packaging pipeline board
Professional

Supersedence & Outlier Analysis

Catalog hygiene · failure clustering

Find superseded and expired updates cluttering your groups and remediate in one click. Then cluster deployment failures by model, subnet, boundary, or DP to find the one signature behind a wave of tickets.

Why now: supersedence done wrong is a top ticket driver. And failure clustering turns "50 machines failed" into "the Dell 7440 driver." (Enterprise adds the AI that explains the cluster in one sentence.)
Deployment outlier analysis
Professional

OSD Deployment Tracker

Task-sequence progress, live

Watch task sequences move through their state messages in real time (which step, which device, which failure) instead of parsing SMSTS logs after the fact.

Why now: imaging day shouldn't mean log spelunking. See the pipeline, catch the stall early.
OSD deployment tracker
Universal Core

Client-Estate Health

Estate rollup + worst-N

Estate-wide client-health scores, a healthy-percentage trend, and the worst clients first with their actual issues (WMI, ccmexec, inactive) so you fix causes, not symptoms.

Why now: broken clients make every other number a lie. Surface them before they become a compliance gap.
Client health
Professional

Boundary & Infrastructure

Coverage gaps · site health

Overlapping and orphaned boundaries, clients outside any boundary group, distribution-point content status, and site-server health. The plumbing that quietly generates tickets, made visible.

Why now: boundary-group misses are the invisible cause behind "software won't install." Find them before your users do.
Boundary validator

Plus Devices & Device 360, CMPivot and Run Scripts web consoles, Software Catalog, Collection Watchdog, Deployment SLA tracking, Knowledge Chat, the NLP report builder, and the Site Health Map. Every view ships dark and light, responsive to 375px, with real loading, empty, and error states.

// The AI layer

Ask your estate anything.
Trust every answer.

The Enterprise edition ships five AI capabilities that work where AI usually can't. Every answer is grounded in your own site data, never a generic guess. And the whole layer is built for shops where "we ran it through a chatbot" fails the audit.

Off by defaultOne global switch, role-gated and audited. It turns on when your governance says so, not before.
Your providerAzure OpenAI, OpenAI, or AskSage for DoD IL4/IL5. Selected by config, swappable without a code change.
Grounded, not genericAnswers cite your inventory, your compliance data, your incidents. Retrieval runs over your environment, not the open internet.
Degrades by designEvery module is fully functional with AI disabled. Nothing in the console depends on a model to work.
https://endpoint360.yourdomain.local:8360/chat
PatchAdmin · 07:52Patch compliance dropped in the Denver boundary group overnight. Why?
Knowledge Chat · groundedCompliance fell 4.1% at 02:10. 212 clients in DEN-BG-02 missed KB5054321, and all 212 pull content from DEN-DP-01, which failed content validation at 01:55. Anomaly agent AN-114 already opened incident INC-2081 with redistribution as the suggested fix.
v_UpdateComplianceStatusDP HEALTH MONITORINC-2081
> which other DPs share that config
AI-01 ENTERPRISE

Knowledge Chat

Plain-language questions about your environment, answered from your site database, your configuration, and the product docs, with the sources cited inline.

> "why is DEN-DP-01 red?" → validation failed 01:55 · 3 pkgs affected
AI-02 ENTERPRISE

Anomaly Agents

Background agents watch estate signals around the clock and turn a spike into a governed incident with an owner and an SLA clock, not a chart nobody opens.

AN-114: heartbeat drop 6.2σ → INC-2081 opened · owner assigned
AI-03 ENTERPRISE

Outlier Explanations

Deployment failures cluster by model, driver, subnet, and DP. Then the AI names the signature in one sentence a human can act on.

52 failures → 1 cause: Dell 7440 storage driver 10.2.4
AI-04 ENTERPRISE

NLP Report Builder

Describe the report you need and get validated SQL against your site database. The safety layer fails closed: read-only, schema-checked, and audited, so the worst case is "no report," never "wrong data."

> "laptops missing the May CU, by building" → report · 0.4s
AI-05 ENTERPRISE · VANGUARD

Vanguard Decision Briefs

Campaign evidence compressed into the one page an approver actually reads: severity, exposure, confidence score, the weakest check, and the deadline math. The human decision, fully briefed.

CVE-2026-31184 · READY 92 · 1,412 exposed · respond by 07/12 02:00
// Security posture

Runs on your infrastructure.
All of it. Only it.

01A single Windows service on your server: no containers, no sidecars, no agents beyond the ConfigMgr client you already run.
02Threat feeds (MSRC, CISA KEV, DISA IAVM) ingest as offline bundles. Connected fetching is an option, never a requirement.
03Windows Negotiate/Kerberos sign-on; roles map from the ConfigMgr security roles you already assigned. Zero new identity infrastructure.
04The installer is one readable PowerShell script. Government customers audit it line by line, and we like it that way.
05Every state-changing action writes an audit row. AI features are off by default and provider-pluggable, including IL4/IL5 paths.
PS C:\> .\Install-Endpoint360.ps1
[1/6] Prerequisites .......... OK
[2/6] Database (existing SQL) OK
[3/6] Service account ........ OK
[4/6] Windows service ........ OK
[5/6] Console deployed ....... OK
[6/6] Listening on :8360 ..... OK
 
Transcript written for your change record.
Internet connections attempted: 0
// Company

Built by someone
who has lived the tickets

EndPoint360 Solutions

Troy Wilch, founder of EndPoint360 Solutions
Troy WilchFounder · 28 years on this product line

Troy has worked with this product line for 28 years, starting with SMS 1.0 in 1998. He went on to support Configuration Manager at Microsoft itself, across every sector of government and a range of industry verticals, on some of the largest deployments in the world.

"I built this because I have watched too many ConfigMgr admins struggle with a product Microsoft moved on from. The investment went to the cloud and Intune, and now to Copilot, and none of that intelligence is coming back to an on-premises console. Meanwhile Intune has struggles of its own, and millions of endpoints still run on ConfigMgr and the admins who keep it going. So the purpose is simple: if Microsoft will not bring the intelligent, advanced features to this product, EndPoint360 will."

We are in it with the ConfigMgr admin heroes keeping systems management going. That is why Endpoint360 feels different: every feature started as a real ticket, a real Patch Tuesday, or a real audit question. Lean by design, no layers, no bloat, and support that talks to the engineer who built it, not a tier-1 script.

SMS 1.0 → CONFIGMGREX-MICROSOFT SUPPORTGOV + ENTERPRISE SCALE

Where we're headed

EARLY ACCESS · ENDPOINT360 FOR CONFIGMGRThe full console + Vanguard Autopilot, with our first Founding Design Partners.
NEXT · SOFTWARE PORTALA fast, modern self-service catalog for end users.
PLANNED · ENDPOINT360 FOR INTUNEThe same cockpit for cloud-managed estates.
ALWAYS · CLOSE TO THE CUSTOMERFeature requests go straight to the person who builds it.
// Roadmap

In early access, and what comes next

The console and Vanguard are in early access with our first Founding Design Partners. The rest is sequenced by real customer pull, not a marketing calendar. Nothing here is a prerequisite for the early-access cohort.

Early access

Endpoint360 for ConfigMgr

The full web console across all three editions, plus the AI layer and Vanguard Autopilot in Enterprise. In early access with our first Founding Design Partners.

Coming soon

Software Portal

A fast, modern self-service catalog for end users, replacing the aging Software Center experience. Its own lightweight service, curated from the console.

Early access

Service Desk Workspace

A restricted technician surface: find, fix, install on behalf of, and escalate a device with its evidence attached. Included with Professional.

Planned · on customer pull

Endpoint360 for Intune

The same cockpit for co-managed and cloud-managed estates. Built when co-managed shops pull for it.

// Early access

Your ConfigMgr estate deserves a console from this decade

We're selecting Founding Design Partners now, ahead of general availability: enterprise and government, connected or air-gapped. Whether your team says ConfigMgr, SCCM, or MECM, this is the console built for it.

Apply for early access