Datto EDR is a cloud-based endpoint detection and response platform from Kaseya. It monitors computers and servers, analyzes endpoint activity for suspicious behavior, and helps IT teams investigate, contain and remediate threats such as malware, ransomware and fileless attacks.

This summary reflects product information checked on. Datto EDR supports three operating systems: Windows, macOS and Linux. The platform is aimed mainly at managed service providers and IT teams that need centralized security monitoring across multiple customer or organizational endpoints.

Datto EDR at a glance

Attribute Datto EDR
Full name Datto Endpoint Detection and Response
Provider Kaseya, formerly Datto
Primary purpose Detect, investigate and respond to endpoint threats
Deployment model Cloud-based platform with an endpoint agent
Supported platforms Windows, macOS and Linux
Typical users MSPs, IT administrators and security teams
Available as Standalone software or part of Kaseya 365 Endpoint
Key integrations Datto RMM and the wider Kaseya ecosystem

Datto EDR is available as a standalone subscription and through Kaseya 365 Endpoint, according to Datto's product documentation.

How Does Datto EDR Work?

Datto EDR works by installing an agent on each protected endpoint. The agent collects system-level information, including process activity and other endpoint behaviors, then sends that information to the cloud platform for analysis. Detection rules and behavioral analysis help Datto EDR identify potentially malicious activity.

When Datto EDR detects a threat, an administrator or automated policy can:

  • Isolate the affected host
  • Terminate a malicious process
  • Quarantine or remove a file
  • Investigate endpoint activity
  • Review forensic information
  • Apply automated response rules

Datto EDR refers to its combination of continuous monitoring, live forensics and response capabilities as Real-Time Security. Its documentation states that response functions require an active Endpoint Security agent on the target machine.

What Is the Difference Between Datto EDR and Antivirus?

Antivirus focuses mainly on preventing or removing known malware, while Datto EDR detects suspicious behavior, investigates incidents and responds to threats that may bypass traditional antivirus.

Datto Antivirus Datto EDR
Blocks known malware and malicious files Detects suspicious endpoint behavior
Commonly uses malware intelligence, reputation and scanning Uses endpoint telemetry, rules and behavioral analysis
Primarily prevents and removes infections Investigates, contains and remediates incidents
Usually provides less historical context Provides more detail about endpoint activity

Datto recommends using Datto AV and Datto EDR together. Datto AV provides antivirus protection, while Datto EDR adds monitoring and response capabilities.

Datto EDR does not necessarily replace antivirus. In a layered endpoint security setup, antivirus can block threats while EDR helps detect, investigate and respond to activity that gets through the first layer.

What Are Datto EDR's Main Features?

Datto EDR's main features include endpoint monitoring, behavioral detection, automated response policies, investigation tools and integration with Datto RMM.

Continuous Endpoint Monitoring

Datto EDR monitors endpoint activity and collects information about suspicious processes, files and behavior. This gives security teams more context than a single malware detection alert.

Behavioral Threat Detection

Datto EDR is designed to detect abnormal behavior linked to advanced persistent threats, ransomware and fileless attacks. Kaseya also identifies behavioral analysis and deep memory analysis as part of the platform's detection capabilities.

Automated Response Policies

Administrators can configure detection rules to perform recommended actions automatically when Datto EDR detects a threat. These policies can shorten the time between detection and containment, but teams should test them before broad deployment. Poorly tuned policies can disrupt legitimate activity.

Investigation and Threat Hunting

Datto EDR provides endpoint data and context for investigating suspicious activity. Security teams can review alerts, search for related behavior and assess whether an incident has spread.

Integration With Datto RMM

Datto EDR integrates with Datto RMM, allowing MSPs to deploy and manage endpoint security through the Kaseya ecosystem. Kaseya also promotes unified alert management and one-click response actions across its integrated product environment.

Who Is Datto EDR Best Suited To?

Datto EDR is suited to:

  • Managed service providers protecting multiple customer environments
  • IT teams that already use Datto RMM
  • Organizations that need centralized endpoint visibility
  • Businesses that need more than traditional antivirus scanning
  • Teams that need endpoint isolation and automated remediation options

Datto EDR is not a complete security program on its own. It focuses on endpoint detection and response, so organizations may need additional controls for patch management, identity protection, email security, backup and security awareness training. It may be a weaker fit for a business looking for one platform to cover email, identity, network traffic, cloud applications and backups.

Is Datto EDR an MDR Service?

No. Datto EDR is an endpoint security platform, not a fully managed detection and response service.

Datto EDR provides endpoint monitoring, alerts, investigation tools and response actions. An MDR service adds a security operations team that monitors alerts, investigates incidents and may coordinate response for the customer.

Datto EDR can support an MSP's broader security or MDR offering, but the software does not replace human security operations by itself.

Bottom Line

Before choosing Datto EDR, confirm that its endpoint coverage, response controls and alert workflow match your team's operating model. Also check the requirements for Datto RMM or Kaseya 365 integration, the operating systems in your environment and whether your organization needs a separate MDR service.