Skip to main content
You connect Datto EDR once at the MSP level. One API token covers every organization its user can see, for both Datto EDR and Datto AV.

1. Create a user and an API token for Neo

1

Add a dedicated user for Neo

In Datto EDR, open Admin > Users & Tokens and add a user for Neo. The token acts with that user’s role:Datto’s role table lists every action per role.
2

Create the token

Open API Tokens, click Create new token for that user, and copy the token. Datto EDR shows it once.
3

Copy your console address

Copy the address you open Datto EDR at from the browser, for example https://yourcompany.infocyte.com.
A Datto EDR token expires one year after you create it. Create a new token before then and save it here.

2. Add the token in Neo

1

Open Integrations

In the Neo Dashboard, open Integrations → Datto EDR, under Security.
2

Save the console address and the token

Paste the console address and the API token and click Save settings. Neo checks them against your console before saving, so a wrong address or token is rejected straight away.

3. Turn Datto EDR on per agent

1

Open the agent

In the Neo Dashboard, open the agent and its Integrations tab.
2

Choose an access profile

Under Datto EDR, choose a profile, or set each permission group by hand.
3

Tell the agent what to do

Add a line to the agent’s instructions, for example: “When a ticket is a Datto AV quarantine, find the alert and the quarantined file in Datto EDR, judge whether it is a false positive, and write what you found in an internal note.”
These always ask a technician, under every profile:
  • Restoring or deleting a quarantined file, and flagging a file or an application
  • Every response action: isolate or restore a device’s network, kill a process, delete or quarantine a file, run a command, reboot, ransomware rollback
  • Every exclusion, policy, policy assignment, suppression rule and detection rule change
  • Uninstalling an agent, removing its licence, approving or denying an agent or a network scanner, and any direct edit of a device record
  • Deleting an organization or a location
  • Every change to users, roles, settings, PSA and RMM integrations and webhooks