Integration: Datto RMM and Datto EDR

Datto RMM and Datto Endpoint Detection and Response (EDR) integrate to let you deploy and manage the Datto Endpoint Security agent across your managed endpoints from a single console. Once connected, Datto RMM sites sync to Datto EDR as locations, endpoint security policies control agent deployment, and high and severe EDR alerts flow into Datto RMM automatically.

Kaseya 365

If you have the following Kaseya 365 subscription, this integration is included in your subscription:

To learn about Kaseya 365, refer to Kaseya 365 overview in the KaseyaOne Help.

Automations powered by this integration

  • Deploy Datto EDR from Datto RMM
  • Deploy and Manage Datto AV from Datto RMM
  • One-Click EDR Host from Datto RMM
  • One-Click AV Host from Datto RMM
  • True-Sync for Datto EDR and Datto RMM
  • Endpoint Shortcut for EDR
  • Datto EDR Event Dashboard in Datto RMM
  • EDR Security Event Alerts in Datto RMM

Details on these and more automations are available in the Automation Center in Kaseya One. Refer to Automation Center.

Prerequisites

  • An active Datto RMM subscription and an active Datto EDR or Datto Antivirus (AV) subscription.
  • Administrator-level access to both the Datto RMM console and the Datto EDR portal.
  • The Datto RMM agent already installed and checked in on any device before you deploy the Datto Endpoint Security agent to it. Installing the RMM agent first ensures the device is assigned to the correct site before the EDR sync occurs.
  • If a standalone Datto EDR agent was previously deployed outside of Datto RMM, uninstall it and redeploy through Datto RMM. Deploying through Datto RMM on top of a pre-existing, non-RMM-managed agent is not supported.

What happens automatically after enabling the integration

After you enable the integration and map the two products, the following occurs automatically:

  • Every Datto RMM site syncs to Datto EDR as a location and is grouped under a default Default RMM organization.
  • Any endpoint with the Datto Endpoint Security agent installed syncs to Datto EDR as a device under its matching location.
  • Datto EDR checks for new or changed sites and endpoints roughly every four hours.
  • High and Severe EDR alerts replicate from Datto EDR into Datto RMM. This replication is one-directional (Datto EDR to Datto RMM only).

Known limitations

  • You cannot rename or delete an RMM-synced location from within the Datto EDR portal. Rename sites on the Datto RMM side.
  • Devices cannot be moved between locations in Datto EDR once synced. The location a device lands in is determined by its RMM site.
  • The integration does not automatically deduplicate sites if the same client exists in Datto RMM under more than one site.
  • Uninstall Protection on the endpoint prevents Datto RMM or any other method from removing the Datto Endpoint Security agent directly. Uninstall must be done from the Datto EDR portal. Refer to Offboard a client below.

How to...

FAQ