Automatically enabled when you configure Datto EDR permissions in your agent workflow.
What It Does
- Find the alert behind a ticket: from the Alert URL of a Datto EDR Autotask ticket, from the device and time of a Datto RMM alert ticket, or from an alert email
- Read the quarantine record, the file’s reputation (engine detections, signer, threat score), your own file flags and how many devices have the file
- Read the device, its policies and its other alerts
- List new quarantines since a time, for a scheduled agent
- Archive (acknowledge) an alert and add a comment
- Restore or delete a quarantined file, isolate a device or restore its network, and run response extensions
- Scan devices, locations and organizations; manage devices, device groups, organizations and locations
- Read and change exclusions, policies, suppression rules and detection rules
How the agent handles a quarantine ticket
The agent finds the alert id: Datto EDR’s own Autotask ticket carries it in the Alert URL field, and an alert email in its link. A ticket from Datto RMM (the path for Halo and ConnectWise, which Datto EDR does not ticket into) carries the hostname and the time, so the agent reads the RMM alert first when it has Datto RMM, then finds the Datto EDR alert by device and time. It reads the quarantine record, the file’s reputation and the device, weighs the signer, the engine count, the path and the device’s other alerts, and writes what it found in an internal note.Permission Groups
Each group is Disabled, Read Only or Read / Write.
Access Profiles
Safety Controls
How to Configure
1
Connect Datto EDR
Save your console address and API token in the Neo Dashboard under the Security integrations category. See Connecting Datto EDR to Neo.
2
Configure permissions
In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
