Integration: Kaseya MDR and Datto EDR

Overview

This integration connects Datto EDR to Kaseya MDR and makes endpoint telemetry available for investigation and correlation.

Datto EDR activity is associated with organizations through mapping. Once mapped, endpoint activity becomes available in alerts and investigations. This integration focuses on connection, organization mapping, and data availability.

This article does not describe detection logic, response actions, SOC workflows, or Datto EDR administration.

Relationship to endpoint and infrastructure sources

Datto EDR is an endpoint data source that provides endpoint and infrastructure telemetry to Kaseya MDR.

In Kaseya MDR, endpoint and infrastructure sources contribute device‑level and system activity used for investigation and correlation. Datto EDR provides this type of telemetry as part of the broader set of endpoint and infrastructure data sources.

For an overview of how endpoint and infrastructure sources appear in Kaseya MDR, how endpoint activity becomes visible, and how endpoint telemetry differs from other data source types, see Endpoint and infrastructure sources.

Prerequisites

Before configuring the integration:

  • You must have administrative access to Datto EDR.

  • You must be able to create an API token in Datto EDR.

  • You must have permission to manage integrations or organization applications in Kaseya MDR.

Use case

A managed service provider uses Datto EDR across multiple customer environments.

By connecting Datto EDR to Kaseya MDR once at the partner level and mapping each customer organization, endpoint telemetry becomes available during investigations.

For example:

  • A login alert is investigated in Kaseya MDR

  • Endpoint context from Datto EDR is associated with the alert

  • The analyst uses that context to better understand device state and activity

How Datto EDR integration works in Kaseya MDR

When connected to Kaseya MDR, Datto EDR provides endpoint activity that can be associated with one or more organizations for investigation and correlation.

Datto EDR is connected once at the partner level. Customer onboarding is performed through organization mapping, which determines where Datto EDR activity is visible.

Kaseya MDR observes Datto EDR-generated activity. It does not manage Datto EDR policies, agents, or enforcement settings.

For information about how endpoint‑based detections are used in detection workflows, see Configuring Datto Ransomware Detection.

How to...

After completing the connection

Data availability

After configuration:

  • Datto EDR telemetry is associated with mapped organizations

  • Activity appears within alerts and investigations

  • Data is scoped by organization mapping

  • Synchronization is not immediate

NOTE  It can take up to 15 minutes for organizations and devices to update after mappings are added or changed, even after the connection shows as successful.

Connection status and synchronization

After Datto EDR is connected, the Integrations list shows a high‑level connection status (for example, Connected).

Selecting View details displays the current synchronization stage.

The detailed view shows a connection status panel that reflects the current synchronization stage. This may include steps such as initializing the connection, checking permissions, retrieving users, processing security data, or refreshing authentication tokens.

A status of Done indicates that the connection process has completed. It does not mean that all users or devices have finished synchronizing. Organization and device data may continue to update in the background after the connection is marked complete.

Accounts tab

After Datto EDR is connected, the integration details include an Accounts tab.

The Accounts tab displays the list of accounts and identities associated with the Datto EDR integration. This view provides visibility into which accounts are included and how they are categorized and displayed within Kaseya MDR.

From the Accounts tab, you can:

  • View accounts associated with the Datto EDR integration

  • Search and filter the account list

  • Export the list for review

  • See account attributes and status indicators as shown in the UI

The Accounts tab is informational and administrative. It does not control Datto EDR detection behavior, alert generation, response actions, or SOC workflows.

Troubleshooting

Customer Organization does not appear in the mapping dropdown

Cause: The organization has not been created in Datto EDR, or the API hasn't refreshed the list yet.

Solution: Ensure the customer exists as a distinct Organization in Datto EDR (not just a Group or Location). If it was recently created, click the Refresh or Sync button in the Kaseya MDR integration settings to force a new pull of the organization list.

All devices are showing up under a Default RMM Org

Cause: Datto EDR is configured using a flat structure (Locations/Groups) rather than the multi-tenant Organization structure.

Solution: To gain granular visibility, devices should be associated with a specific organization within the Datto EDR console. Kaseya MDR requires the organization-level boundary to map telemetry to the correct customer context.

Connection status says Connected but no data is appearing

Cause: The API Token may have insufficient permissions or the initial sync is still in progress.

Solution:

  • Verify the API Token in Datto EDR has Admin or Full Read permissions.

  • Wait at least 30 minutes for the initial handshake and data ingestion to complete.

  • Check the Accounts tab; if it is empty, Kaseya MDR is not receiving identity data from the EDR.

Duplicate Event alerts are appearing in the SOC

Cause: Datto EDR was accidentally added as a new application at the organization level while the partner-level connection was also active.

Solution: Delete the application from the individual Organization > Applications list. Ensure you are only using the Mapping tab to link the client to the master connection.

Related articles