RMM tools · 8 min read
RMM features checklist: what to score, and what to ignore
Written for: Anyone running a formal evaluation, writing a requirements document, or justifying a renewal decision.
Evaluation shape
In short
Feature grids exist to make similar products look different. This checklist splits RMM capability into seven groups and marks each item as table stakes, daily differentiator, or occasional. Score the daily differentiators honestly against your own week, treat table stakes as pass or fail, and let the occasional items break ties. Teams that evaluate this way tend to buy narrower tools and stay happier with them.
Key takeaways
- Table stakes are pass or fail: screen view, control, file transfer, reboot and reconnect, unattended agent, multi-monitor.
- Daily differentiators are where the decision should be made: time to session, console clarity, operator licensing, audit detail.
- Security should be scored on mechanism, not adjectives: how a session is authorised, encrypted, consented to and recorded.
- Every item on the grid should be marked daily, weekly or rare for your team before anyone scores it.
- Ask which scored items sit behind a higher tier, an add-on, or professional services.
- Weight the score by usage frequency, or the grid will hand the decision to features nobody opens.
Group 1: access and connectivity (mostly table stakes)
This group decides whether a tool is a candidate at all. Almost every serious product passes, so score it pass or fail and move on rather than awarding points.
- Unattended access to a device with an installed agent.
- Attended or on-demand access with user consent and no permanent install.
- Outbound-only agent connectivity over standard HTTPS, with no inbound firewall rule or port forwarding.
- Works across the platforms you actually run, including any macOS, Android or tablet estate.
- Reboot and automatic reconnect, including into safe mode where relevant.
- Multi-monitor handling and clipboard or file transfer in session.
Group 2: security and audit (score on mechanism)
Every vendor says the product is secure. Score the mechanism instead, and require a demonstration of each answer. The public guidance from bodies such as the NCSC, CISA and NIST is consistent on the fundamentals: strong authentication, least privilege, encrypted transport, and a readable audit trail.
- Encryption in transit, stated as a named standard such as AES-256.
- Two-factor authentication available, and enforceable, on operator accounts.
- Role-based access so an operator can reach only their device groups.
- Explicit consent prompt for attended sessions, and a visible indicator during any session.
- Session and command logging against a named operator, readable by someone who is not that operator.
- Immediate revocation when someone leaves, and a clear answer on where logs are hosted and for how long.
Group 3: session quality (the daily differentiator)
This is the group that decides whether your team likes the tool, and it is the group least represented on feature grids. Score it with a stopwatch during a trial rather than from documentation.
- Seconds from intent to a visible screen, unattended and attended.
- Clicks to find a named device in an estate the size of yours.
- Responsiveness on a poor connection, and behaviour when the link drops mid-session.
- How many concurrent sessions one operator may hold, and whether that costs extra.
- Whether ordinary tasks — file transfer, reboot, elevating a prompt — are one action or a procedure.
Group 4: estate management and monitoring
Score this group against the size and messiness of your real estate, not a tidy demo tenant. Grouping that only works with a naming convention nobody maintains is grouping that will not exist in a year.
- Device grouping, tagging and search that survives a few hundred inconsistently named machines.
- Online state and basic health at a glance, without opening each device.
- Alert thresholds, who receives them, and how long tuning typically takes.
- Hardware and software inventory, and whether it is exportable.
Groups 5 and 6: automation and reporting (usually occasional)
These are genuinely valuable where someone owns them and near-worthless where nobody does. Be honest about which describes your team, and weight accordingly. A suite justified by its automation engine is a poor purchase for a team with no automation author.
- Running commands or scripts against one device, a group, or the whole estate.
- Scheduled maintenance and self-healing rules.
- Patch approval rings, deferral and rollback.
- Compliance and session-history reporting suitable for someone outside IT.
Group 7: commercials (score before you see a discount)
Licensing model shapes cost far more than headline price. Write down your team shape and estate size, then model each candidate against three years of realistic growth, including the after-hours helper and the second-line engineer who needs occasional access.
- How operators are counted: named, concurrent, or unlimited.
- Whether concurrent sessions per operator are limited or chargeable.
- Which of your daily items require a higher tier or paid add-on.
- Annual commitment terms, published pricing, and the renewal position.
- Whether onboarding or configuration is billable professional services.
How to weight each group
| Access and connectivity | Pass or fail. No points; a tool either qualifies or does not. |
|---|---|
| Security and audit | High weight, scored on demonstrated mechanism rather than claims. |
| Session quality | Highest weight for support-led teams. Measure with a stopwatch. |
| Estate management | Medium to high, scaled to estate size and how untidy it really is. |
| Automation | High only if a named person will own it. Otherwise near zero. |
| Reporting | Low unless audit or client reporting is contractual. |
| Commercials | High weight. Model three years, not month one. |
Select any column heading to sort, or filter with the box above.
Frequently asked questions
- What features should an RMM tool have as a minimum?
- Unattended and attended access, outbound-only agent connectivity, remote control with file transfer and reboot-and-reconnect, encrypted sessions with two-factor authentication on operator accounts, role-based access to device groups, and session logging against named operators.
- Which RMM features are most overrated?
- Anything used rarely but marketed heavily: extensive dashboard customisation, integrations you will not wire up, and automation engines where nobody in the team will write automations. They are fine as tie-breakers and poor as decision drivers.
- How do I compare security between RMM tools fairly?
- Ask for a demonstration of the mechanism rather than a statement: how a session is authorised, what encryption is used, whether two-factor authentication can be enforced, how roles restrict device access, what is logged, and how access is revoked when someone leaves.
- Should reporting influence the decision?
- Only as much as it is used. If client or audit reporting is contractual, weight it highly. If reports are opened once a year, it belongs in the tie-breaker column.
- How long should an RMM evaluation take?
- Two weeks against real devices and real tickets is usually enough to score session quality, console clarity and alert usefulness, which are the items documentation cannot answer.
Why teams choose 247connect
Passes the table stakes cleanly
Managed and on-demand access, outbound-only agents, file transfer, reboot and reconnect, multi-monitor.
Scores on mechanism, not adjectives
AES-256, zero trust, two-factor authentication, role-based access and named-operator audit logs.
Wins the stopwatch test
Around eight seconds to session and five concurrent sessions per operator, included.
Simple commercials
Unlimited operators, fixed price, no tiering games on the features you use daily.
Run that checklist against 247connect and the shape is clear. It passes the access group for managed and on-demand devices, scores strongly on security mechanism (AES-256, zero trust, enforceable two-factor authentication, central session logs) and on session quality (around eight seconds to connect, five concurrent sessions per operator), and is deliberately light on automation and compliance reporting. If your weighting puts session quality, security and predictable cost first, that trade is a good one. If automation and patch reporting carry your score, a broader suite is the honest answer.
More RMM guides
RMM for small IT teams
How small IT teams get real remote monitoring and management value without buying an enterprise platform: which capabilities matter at two or three people, how to stage a rollout, what to monitor first, and where a lighter remote access tool is the better buy.
RMM pricing and licensing
How RMM software pricing works: per-endpoint, per-operator and per-concurrent-session models, the add-ons and tiers that move the real figure, annual commitment and renewal risk, and how to model three years of cost for your own team shape.
What is RMM software?
A plain-English definition of RMM software: what remote monitoring and management means, the three parts every RMM platform has, what an RMM agent does on a managed device, and how RMM differs from remote desktop, PSA and endpoint security tools.