Product
One agent, one console, the whole fleet.
OKTO RMM brings monitoring, patching, automation, remote desktop, a software library, vulnerability management and compliance for a fleet of Windows, Linux and macOS devices into a single console. The agent reports every 60 seconds and answers 134 commands. Every screen on this page exists in version 34.83.
The console tells you before the client calls.
Twenty-one condition types, combinable with AND and OR: CPU, memory and free-space thresholds per volume, stopped service, missing process, Windows event, expiring certificate, critical vulnerability, pending reboot, script result, antivirus health, encryption, uptime. Alerts escalate, cool down, correlate and stay quiet during maintenance.
- 281 ready alert templates, in French and English, across 39 families
- 58 monitoring packs by role: a SQL server, a domain controller or a Docker host is monitored in one click
- Output by email, SMS, Teams, Slack, Discord, webhook, Pushover, PagerDuty, or straight into your PSA
- SNMP network monitoring, ping, TCP, HTTP and DNS probes, network discovery
- Dependencies between devices: the switch goes down, the 40 devices behind it stay quiet
Six package managers, one policy.
Windows Update through the native API, apt on Debian and Ubuntu, Homebrew and Apple updates on macOS, winget and Chocolatey for third-party applications. The policy decides what gets approved, when it installs and whether the device reboots. It is inherited from a partner baseline to the organization, then to the device.
- Automatic approval by severity and category, with deployment rings
- A patch of unknown severity waits for a human, by design
- Known-bad patch list, automatic retry on failure
- Reboot: if required, never, or scheduled; cancellable; user notice before, during and after
- The Windows agent closes Microsoft's automatic channel: nothing installs behind your back
35 of 38 devices done · 0 failures · 3 reboots scheduled
A library that arrives full, not empty.
350 PowerShell, Bash, Python and CMD scripts for Windows, Linux and macOS, versioned, categorized, with parameters and run statistics. 92 automations ready to switch on. Four triggers: on a schedule, on an event (sign-in or sign-out, non-compliant device, patch available, device offline), by webhook, or by hand.
- Run as SYSTEM or in the user's session, with no visible window
- Credentials in an encrypted vault, injected at run time
- Auto-remediation: an alert carries its script, fixes itself and closes
- Playbooks per device, Windows scheduled tasks driven remotely
- On failure: stop, continue or notify, with every device's log
One policy, fifteen sections, and inheritance does the rest.
Patches, alerts, monitoring, maintenance, automations, event logs, software policy, warranty, remote system tools, vulnerability scanning, OKTO panel, software, tools, assignments. Each section is set once in a baseline policy, inherited down to the device and overridden where needed. A policy is bound to a device class.
- 39 alert conditions in a workstation policy, each with its severity, cooldown and remediation
- Patch approval rings, schedule by day and hour, reboot behaviour
- Maintenance windows: muting, reboots, notices to the user
- Assignments by organization, site, tag or device; “effective configuration” readable on every device page
Windows Workstation
ActivePolicy details
Patches inherited, overridden
Alerts 39 conditions
Monitoring
Maintenance window
Automations 4 active
Built into the agent, not bolted on.
Remote desktop is written in Go inside the agent, on WebRTC. DXGI capture on Windows, DisplayStream on macOS, H.264 encoding by NVIDIA, AMD, Media Foundation or VideoToolbox, software fallback otherwise. Adaptive bitrate, changed rectangles only, cursor and audio. The native viewer shows bitrate, latency, jitter, codec and network path live.
- Native viewer for Windows and macOS, opened from an oktoremote:// link on the device page
- Session toolbar: clipboard, files, user session, lock, script, chat, screenshot, keyboard, settings, full screen
- Unattended access, consent gate set by policy, wallpaper kept
- In-house TURN relay, temporary signed credentials valid ten minutes
- Full history: who, which device, start, end, duration, bytes
- Bitrate
- 499k
- Frames
- 21/s
- Latency
- 12 ms
- Jitter
- 6 ms
- Loss
- 0
- Dropped
- 0
- Codec
- H264
- Path
- srflx/udp
- Screen
- 1920×1080
- Scale
- 100%
- Buffer
- 1 ms
- IDR
- 0
The whole device, readable and actionable, without disturbing the user.
Current session, logged-in user, CPU and memory for the last hour, hardware, addresses, agent version, and the device's full activity: every command, patch, reboot and session, with who and when. Some thirty tabs behind it: software, services, registry, scheduled tasks, logs, security, compliance, scripts, changes.
- Kill a process, restart a service, edit a registry key, run a task, without opening a desktop
- Software inventory matched against the 24,160-application catalogue
- Wake-on-LAN, lock, shutdown, reboot into safe mode
- Per-device documentation and runbook, custom fields, tracked changes
PC-ACCT-03
24,160 applications, installed silently, without disturbing anyone.
WinGet and Chocolatey in a single search, background installation as SYSTEM, packs by role, version tracking, and “My installers” for your own MSI and EXE files, signed and hosted by you. Deployment to one device, one organization or the whole fleet.
- Packs: a group of applications for a role, in one deployment
- Tracking: who has what, in which version, and what is waiting for an update
- Software policies: allow list, banned software, requirements per organization
- Approved applications show up in the user's assistant, self-service
Your users get a button. Not your cell number.
In the notification area of every device, the OKTO assistant opens a menu the user understands at first glance: ask for help, see the device's status, install an approved application, update their software, manage their access. The help request becomes a ticket in OKTO PSA, HaloPSA, ConnectWise or Autotask, device and diagnostics attached.
- Approved applications install self-service, through the agent, without administrator rights
- About this device: name, status, last heartbeat, diagnostics
- Update my applications: the user picks the moment, the agent does the rest
- Client portal and support one click away, dark mode, no flashing black window
OKTO Solutions looks after your infrastructure, your users and your peace of mind.

Four vulnerability feeds, a score per flaw, a fix per line.
The software inventory of every device is matched against CISA KEV and EPSS, Microsoft MSRC, NIST's NVD and SOFA for Apple. Each CVE found on your devices is prioritized by real risk: a CVSS score adjusted by whether it is actively exploited (KEV) and by its likelihood of exploitation (EPSS), with the affected software, the version that fixes it and the devices concerned.
- A feed that stops syncing is flagged: silently frozen results are worse than no results
- “Critical vulnerability” alert wired into your automations and your PSA
- Remediation: the patch or version that fixes the flaw is named on every line
- Vulnerability scanning set by policy, per organization
Antivirus, encryption, firewall and benchmarks, in one place.
The agent reads Microsoft Defender and third-party antivirus through Windows Security Center, BitLocker, the firewall, firmware and detected threats. It applies CIS benchmarks for Windows, macOS and Linux, on demand or on a schedule, remediates under approval and keeps the score over time. It searches for sensitive data, controls USB peripherals and manages temporary privilege elevation.
- Bitdefender GravityZone, SentinelOne and Huntress connected: isolation, threats, sync
- NextDNS filtering deployed by policy, events surfaced in the console
- One-time secrets: a password sent through a link that expires and opens once, encrypted in your browser
- Incident response: evidence collection and device containment
One-time secrets
Send a password, a key or an identifier to a client through a link that expires and opens only once. Encrypted in your browser, unreadable by the console, useless to a database thief.
https://rmm.your-domain.ca/s/7kd9-Qx2m-...
Your clients, your technicians, your rules.
Partner, organizations, sites, enrolment keys per client. Isolation is written into the database itself, not only the interface. Roles are composed from 55 permissions on 21 resources, and cloned. A ready-made client role gives your customer a view of their devices and remote access, nothing else, with two-factor authentication enforced.
- Client portal with your logo, favicon, three colours, domain and CSS
- Interface in French and English, per user
- SSO OIDC and SAML, Entra ID proven, permission-scoped API keys, 1,009 documented routes
- Modules switched on one by one: you only show what you sell
Who did what, on which device, and what the device saw.
The audit trail records every action by a user, an API key, an agent or the system, with the action, the resource, the address, the result and an integrity checksum per entry. The Windows event logs of every device flow into the console, searchable by ID, source or word without opening a session, and feed 63 ready alert templates.
- Filter by actor, action, device, period; export
- Configurable retention, never under 30 days
- System, Application, Security and custom logs, on one device, one organization or the fleet
- Remote desktop and terminal sessions logged with duration and bytes
Questions
What we get asked about the product.
Which operating systems does the OKTO RMM agent support?
How long does the agent take to report a change?
Can I run my own PowerShell scripts?
Does remote desktop get through firewalls?
How does policy inheritance work?
Do users see anything on their device?
Next step
Have a question about a specific screen? We answer it.
Write us what you are trying to fix in your fleet. We reply within the business day, with the real price.