> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Datto EDR API

> Investigate Datto AV quarantines and Datto EDR alerts: find the alert, the quarantined file, its reputation and the device; restore a file, respond on a device, manage exclusions

The Datto EDR API tool gives Neo agents access to your Datto EDR console, which covers Datto EDR and Datto AV. The common use is a ticket about a Datto AV quarantine or a Datto EDR alert: the agent finds the alert, reads the quarantined file, its reputation and the device, judges whether it is a false positive, and writes its verdict in an internal note.

<Info>
  Automatically enabled when you configure Datto EDR permissions in your agent workflow.
</Info>

## What It Does

* Find the alert behind a ticket: from the Alert URL of a Datto EDR Autotask ticket, from the device and time of a Datto RMM alert ticket, or from an alert email
* Read the quarantine record, the file's reputation (engine detections, signer, threat score), your own file flags and how many devices have the file
* Read the device, its policies and its other alerts
* List new quarantines since a time, for a scheduled agent
* Archive (acknowledge) an alert and add a comment
* Restore or delete a quarantined file, isolate a device or restore its network, and run response extensions
* Scan devices, locations and organizations; manage devices, device groups, organizations and locations
* Read and change exclusions, policies, suppression rules and detection rules

## How the agent handles a quarantine ticket

The agent finds the alert id: Datto EDR's own Autotask ticket carries it in the Alert URL field, and an alert email in its link. A ticket from Datto RMM (the path for Halo and ConnectWise, which Datto EDR does not ticket into) carries the hostname and the time, so the agent reads the RMM alert first when it has Datto RMM, then finds the Datto EDR alert by device and time. It reads the quarantine record, the file's reputation and the device, weighs the signer, the engine count, the path and the device's other alerts, and writes what it found in an internal note.

## Permission Groups

| Group | Covers |
| - | - |
| Alerts | Alerts, alert details, the archive, comments and AI assist answers |
| Quarantine and Files | Quarantined files, file reputation, file flags, prevalence and Datto AV lab submissions |
| Response Actions | Isolation and network restore, response extensions and their results, AV alert actions, ransomware rollback |
| Devices | Devices, device groups, applications, licences, scans and scan tasks, network scanners |
| Exclusions, Policies and Rules | Datto AV exclusions, policies and their assignment, suppression rules, detection rules |
| Organizations and Locations | Organizations (your clients) and locations (their sites) |
| Scan Data | Datto EDR scan data (processes, modules, autostarts, connections, accounts) and searches |
| Account and Integrations | Console users and roles, tenant settings, PSA and RMM integration set-up, webhooks, reports and notifications |

Each group is Disabled, Read Only or Read / Write.

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read | Every write |
| **IT Admin** | Alert archive and comments, scans, searches, lab submission, file retrieval, licence assignment, device and organization and location housekeeping, reports | The writes that always ask (below) |
| **Full Automation** | Every write except those below | Only the writes below |

## Safety Controls

| Control | Behavior |
| - | - |
| **Quarantine** | Restoring or deleting a quarantined file, and flagging a file or an application, always ask a technician |
| **Response actions** | Isolating a device or restoring its network, killing a process, deleting or quarantining a file, running a command, rebooting and ransomware rollback always ask a technician |
| **Exclusions and policies** | Every exclusion, policy, policy assignment, suppression rule and detection rule change always asks a technician |
| **Devices** | Uninstalling an agent, removing its licence, approving or denying an agent or a network scanner, and any direct edit of a device record always ask a technician |
| **Clients** | Deleting an organization or a location always asks a technician |
| **Account** | Every change to users, roles, tenant settings, PSA and RMM integrations and webhooks always asks a technician. Reports and your own notifications follow the access profile |
| **Named records** | A bulk action that selects its records with a filter or a list must name them by id, and an isolation or a response must name its device or alert. Neo does not send one that could reach every record |
| **Refused** | Neo does not read or create API tokens, agent deploy keys or uninstall tokens, sign in on a user's behalf, write the records Datto EDR keeps itself (endpoint callbacks, device telemetry, the audit log), download or upload files, read secrets in clear, or bulk-delete by filter. Credentials in your PSA and integration set-up are removed from what Neo reads |

## How to Configure

<Steps>
  <Step title="Connect Datto EDR">
    Save your console address and API token in the Neo Dashboard under the **Security** integrations category. See [Connecting Datto EDR to Neo](/integrations/datto-edr/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or set each permission group by hand.
  </Step>
</Steps>

<Tip>
  Start with **Read Only**. Investigating a quarantine needs only reads in Datto EDR; the note on the ticket is written with the PSA tools.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.