start portlet menu bar

HCLSoftware: Fueling the Digital+ Economy

Display portlet menu
end portlet menu bar
Close
Select Page

Your operators can now run HCL BigFix by describing what they want in the AI client they already use. The HCL BigFix Platform MCP Server brings the power of autonomous, AI-driven automation to HCL BigFix, packaged for what makes sense in your environment, so your team can query the environment, build content, and run actions in plain language.

Your team remediates faster and spends less time on repetitive query and authoring work, getting more out of the operators and skills you already have.

Available now with HCL BigFix Platform 11.0.6 or later.

How It Works

You install and deploy the HCL BigFix MCP Server, and it runs as a service between your AI client and the BigFix Root Server. Your AI client is whatever LLM your team has deployed and already works in. The server handles two things:

First, it talks to HCL BigFix for you. When your LLM asks for something, the MCP Server turns the request into a call to HCL BigFix's native Platform REST APIs, so it works against your live environment instead of a separate copy of your data.

Second, it stays inside your security model. Every request carries your HCL BigFix REST API token. The MCP Server forwards that token to the Root Server, which checks it against your existing operators, roles, and permissions before anything runs. Your role-based access control still prohibits any user from escalating or doing anything they could not already do in the console.

What You Can Do With It

Your imagination is the limit. Point your LLM at the MCP Server and ask for what you need. A few examples:

Find and fix vulnerabilities. Ask your LLM to retrieve a list of vulnerabilities you care about, whether from the CISA KEV catalog, your security team's tooling, or AI-driven discovery like Anthropic's Project Glasswing, and find which Fixlets apply. It returns the exposed endpoints and a ranked action plan. Ask it to build the remediation plan and execute it with your approval.

Report for management. Ask for a critical-exposure summary with the methodology, the findings, how far past due you are, and what to fix first. Use the same chat to visualize the data for a reporting request, and if the first cut looks rough, tell it to clean up the formatting.

Review your action lifecycle. Ask for every expired or stopped action in the last 30 days, then ask for more detail on any one of them, including its status and execution details.

Manage roles and access. Ask the LLM to list your HCL BigFix roles in a table with role ID, name, Master Operator status, and whether each can create actions. Then build a new role without opening the console. Before anything is written, the human-in-the-loop dialog shows you the exact request. Approve it, and the role is created. Ask to flip CanCreateActions to true later, and you get the same review step.

Author and deploy a Fixlet. Point the LLM at your Windows computer details and ask it to build and deploy one. The LLM builds a schema-valid Fixlet and stages the deployment. The approval dialog shows the exact action before it runs, so you can check the targeting and the script. Approve it to deploy, then ask it to delete the action and the Fixlet when you are done.

Secure by Default

You decide exactly what the LLM can reach.

The MCP Server is read-only by default. It blocks every create, update, retry, stop, and delete before the request reaches the Root Server. An administrator can optionally enable using the “allow-write-operations” setting, which will allow users to execute write operations. Control how HCL BigFix can be utilized with MCP by what makes sense in your environment. Future improvement will allow for more granular control of allowable write actions.

When writes are on, the user must approve each one. The MCP Server stages the exact request and asks you to allow, deny, or cancel it. That is where you check the relevance and the targeting before anything runs, not after. Deny is the default answer. Each approval works once and expires after five minutes.

The rest is locked down by design. Every request runs as the operator behind its token, so RBAC governs what is possible. Repeated failed requests lock out the source IP for five minutes. TLS protects the connection both ways. Security decisions go to an audit log, and tokens are never written to it.

Use the AI You Already Have

The MCP Server runs on the Model Context Protocol, an open standard for connecting AI clients to outside tools. Any client that supports remote MCP servers over HTTP can connect, whether that is GitHub Copilot in VS Code, Claude, or ChatGPT. Set the endpoint once and your LLM finds the HCL BigFix tools on its own.

That is the value of building on an open standard. HCL BigFix becomes one more capability inside the assistant your team already works in, next to the other tools it reaches. You choose the AI that fits your environment, and the full strength of BigFix comes with it.

What Comes Next

This release is the start. The MCP Server connects your AI client to the HCL BigFix Platform APIs today, and we are working to extend it to query HCL BigFix Remediate, Compliance, Inventory, and more, so the same assistant can reach across your HCL BigFix estate.

Getting Started

You need HCL BigFix Platform 11.0.6 or later. The MCP Server runs on Windows Server 2022 or later, or Red Hat Enterprise Linux 9 or 10, either on the Root Server or on a separate endpoint that can reach it. Install it with Task 6073, "Install HCL BigFix MCP Server (Version 1.0.0)," from BES Support site version 1514 or later. The Task sets up the service, handles the certificates, and starts it in read-only mode. HCL BigFix Ambassadors who tested the release found it quick to deploy.

Read the HCL BigFix Platform MCP Server guide for setup and configuration.

Give it a try and tell us what you build. Share your prompts, your wins, and your feedback in the comments or on the BigFix forum.

Start a Conversation with Us

We’re here to help you find the right solutions and support you in achieving your business goals.

Your Employees Are Already Using AI. The Real Question Is How Much You Can See.
  |  August 7, 2026
Your Employees Are Already Using AI. The Real Question Is How Much You Can See.
Shadow AI is spreading faster than IT can track. Learn why endpoint and browser AI visibility, not just SaaS discovery, is the foundation of enterprise AI governance and software asset management.
The 2026 Verizon DBIR Just Confirmed What Endpoint Security Teams Have Been Saying for Years
  |  June 22, 2026
The 2026 Verizon DBIR Just Confirmed What Endpoint Security Teams Have Been Saying for Years
The 2026 Verizon DBIR reveals rising vulnerability exploitation, ransomware trends, AI-assisted attacks, and patch management challenges. Learn the five key lessons for endpoint security leaders.