How to inventory a small office network (2026)
By Husanjon Ruzaliev · Updated September 24, 2026
Most small office networks were never designed. They grew: a router from the internet provider, a switch someone bought when the ports ran out, a printer here, a NAS there, and a cupboard of cables nobody has labelled. The person who ends up looking after all of it is usually not a network engineer — they are the office manager who became the IT contact, or the developer who sits nearest the server. This guide is for that person. It walks through building an accurate inventory of what is actually on your network, using tools you can get for free, without assuming you already know the jargon.
An inventory answers three questions you will eventually be asked: How many devices do we have? What is that unfamiliar thing on the network? Is anything shared that should not be? You cannot secure, budget for, or troubleshoot a network you cannot see, so seeing it clearly is the first job.
Before you scan: a one-line rule
Scan only networks and hosts you own or have explicit, written permission to assess. On your own office LAN that is normally straightforward, but if you manage sites for someone else, get it in writing first. Our network scanning authorization checklist covers this in more detail — it takes two minutes and saves awkward conversations.
Step 1 — Work out your address range on paper
Before running anything, find out what range your network uses. On a Windows machine, open a command prompt and run ipconfig; on macOS or Linux, run ifconfig or ip addr. Look for your computer’s IPv4 address and subnet mask. A typical small office looks like 192.168.1.x with a mask of 255.255.255.0, which means every device sits somewhere between 192.168.1.1 and 192.168.1.254.
Write down three things: the network range, the router’s address (usually .1), and the mask. That range is what you will hand to a scanner. Planning it on paper first means you scan the whole network once, rather than guessing and missing half of it.
Step 2 — Choose a scanner and sweep the range
A network scanner sweeps every address in your range, notes which ones answer, and reports what it can learn about each: IP address, hostname, MAC address, and often the hardware manufacturer inferred from the MAC. For a Windows-centric office, Advanced IP Scanner is a common starting point because it also lists shared folders and offers remote actions. If you work across macOS and Linux too, Angry IP Scanner is cross-platform and just as quick. For deeper, scriptable work later on, Nmap is the industry standard.
Whichever you choose, get it from the vendor’s own official site and verify the file before you run it — network tools are among the most impersonated software online. Our where to download page has the thirty-second checklist. Then enter your range, press Scan, and let it finish. On a small network this takes seconds.
Step 3 — Read the results table
A scan result is only useful if you can read it. The columns that matter most:
- Status — whether the host answered. A device that is powered off simply will not appear, which is why one scan is a snapshot, not the whole truth.
- IP address — where the device sits in your range. Note which addresses are handed out automatically (DHCP) and which are fixed.
- Name / hostname — often the most human-readable clue to what a device is, when it is set.
- MAC address and manufacturer — the hardware fingerprint. The manufacturer prefix is frequently how you identify a mystery device: “Hewlett Packard” is probably that printer; “Ubiquiti” is probably an access point.
- Shared folders, where the tool reports them — the fastest way to spot a share that is open to the whole office when it should not be.
We cover the subtleties — phantom hosts, duplicate names, devices that hide from ping — in the companion guide on reading a network scan.
Step 4 — Turn the scan into a written inventory
A scan on screen is not an inventory; a saved, annotated list is. Export the results (most tools export to CSV or a similar format) and, for each device, record four things a raw scan cannot tell you: what it is, who owns or uses it, where it physically lives, and whether it should be there at all. That last column is the one that earns its keep — it turns a device list into a security document.
Keep the file somewhere the whole IT function can reach it, and date it. The first inventory always takes the longest, because you are identifying things for the first time. Every scan after that is a comparison.
Step 5 — Chase the unknowns
Every first inventory turns up at least one device nobody can account for: a MAC address with no obvious owner, a hostname that means nothing, an IP that should be free. Do not ignore it. Note the MAC manufacturer, check whether the address is inside DHCP’s range or statically assigned, and physically trace it if you can — a managed switch will tell you which port a MAC is on. If a result really matters, confirm it with a second scanner that discovers hosts a different way; two tools agreeing is a fact, one tool is an observation.
Step 6 — Make it a routine
An inventory is only accurate on the day you take it. Networks change — someone plugs in a personal laptop, a new printer arrives, a contractor connects a device and leaves. The fix is not a bigger scan; it is a regular one. A weekly sweep that takes four minutes, compared against last week’s, surfaces changes while they are still small. We lay out exactly that habit in a weekly network-scan routine.
Where this leads
Once you can see every device and keep that picture current, the next questions answer themselves: which machines need patching, where an unexpected share is exposing files, whether that “spare” IP is really spare. Larger or multi-site networks eventually outgrow on-demand scans and move to continuous network monitoring — but the discipline is the same, and it starts with a scan you can read and an inventory you keep.