Kaseya MDR Integrations Guide
Kaseya MDR focuses on endpoint and infrastructure monitoring, bringing together telemetry from deployed agents, supported endpoint security platforms, identity providers, network and log-based sources, and select MSP tools into a managed detection and response experience. Integrations below are grouped by category. Full setup instructions are linked from each entry.
The Kaseya MDR documentation organizes integrations by the role each data source plays in detection and investigation, not by vendor or ownership grouping as shown in the product UI. This guide follows that same logic.
Endpoint and infrastructure
Host-level telemetry generated by endpoints, servers, and endpoint security platforms, including RMM tools (which report on managed devices) and agent-delivered detection modules.
NOTE Endpoint Security and RMM are shown as separate tables below for easier scanning. In the underlying Kaseya MDR documentation, both are part of a single Endpoint and Infrastructure category. This split is a presentational choice for this guide, not a distinction the product docs draw.
Endpoint security
| Name | Help Docs |
|---|---|
| Bitdefender GravityZone | |
| CrowdStrike | Integration: Kaseya MDR and CrowdStrike |
| Cylance Monitor (Aurora Endpoint Defense) | Integration: Kaseya MDR and Cylance Monitor (Aurora Endpoint Defense) |
| Datto EDR | Integration: Kaseya MDR and Datto EDR |
| Deep Instinct | Integration: Kaseya MDR and Deep Instinct |
| SentinelOne | Integration: Kaseya MDR and SentinelOne |
| Sophos | Integration: Kaseya MDR and Sophos |
| Webroot Monitor | Integration: Kaseya MDR and Webroot Monitor |
RMM
| Name | Help Docs |
|---|---|
| Datto RMM | Deploying the agent using Datto RMM |
Identity and cloud security
Email security
| Name | Help Docs |
|---|---|
| Graphus | Integration: Kaseya MDR and Graphus |
Dark Web Monitoring
| Name | Help Docs |
|---|---|
| Dark Web ID | Integration: Kaseya MDR and Dark Web ID |
| Have I Been Pwned (Pwnd Monitor) | Integration: Kaseya MDR and Have I Been Pwned |
Identity and cloud platforms
| Name | Help Docs |
|---|---|
| Microsoft 365 | Integration: Kaseya MDR and Microsoft 365 |
Network and log-based sources
Log-based infrastructure and security systems that send telemetry using supported formats such as syslog.
Configured centrally rather than as individual per-vendor connectors. Supported vendors:
Barracuda • Check Point • Cisco ASA • Cisco Firepower Device Manager (FDM) • Cisco Firewall Management Center (FMC) • Cisco IOS • Cisco Meraki • Cisco RV Series • Fortinet • Juniper • MikroTik • Palo Alto Networks • pfSense • SonicWall • Sophos • Ubiquiti • Untangle • WatchGuard • Zyxel
| Name | Help Docs |
|---|---|
| Firewall Log Analyzer | Configuring Firewall Log Analyzer (Firewall log ingestion) |
DNS
| Name | Help Docs |
|---|---|
| DNSFilter | Integration: Kaseya MDR and DNSFilter |
PSA
PSA (Professional Services Automation) tools provide operational and ticketing context rather than primary security telemetry. These integrations are documented in the Administration and configuration section, separately from the core Integrations and data sources section, but are included here for completeness.
| Name | Help Docs |
|---|---|
| Kaseya BMS | Integration: Kaseya MDR and Kaseya BMS |
| Autotask PSA | Integration: Kaseya MDR and Autotask PSA |
|
ConnectWise |
|
| Halo PSA | Integration: Kaseya MDR and Halo PSA |
| Syncro | Integration: Kaseya MDR and Syncro PSA |
Don't see the integration you need?
Submit a request via kb.request@kaseya.com.