1. Create a user and an API token for Neo
1
Add a dedicated user for Neo
In Datto EDR, open Admin > Users & Tokens and add a user for Neo. The token acts with that user’s role:
Datto’s role table lists every action per role.
2
Create the token
Open API Tokens, click Create new token for that user, and copy the token. Datto EDR shows it once.
3
Copy your console address
Copy the address you open Datto EDR at from the browser, for example
https://yourcompany.infocyte.com.2. Add the token in Neo
1
Open Integrations
In the Neo Dashboard, open Integrations → Datto EDR, under Security.
2
Save the console address and the token
Paste the console address and the API token and click Save settings. Neo checks them against your console before saving, so a wrong address or token is rejected straight away.
3. Turn Datto EDR on per agent
1
Open the agent
In the Neo Dashboard, open the agent and its Integrations tab.
2
Choose an access profile
Under Datto EDR, choose a profile, or set each permission group by hand.
3
Tell the agent what to do
Add a line to the agent’s instructions, for example: “When a ticket is a Datto AV quarantine, find the alert and the quarantined file in Datto EDR, judge whether it is a false positive, and write what you found in an internal note.”
These always ask a technician, under every profile:
- Restoring or deleting a quarantined file, and flagging a file or an application
- Every response action: isolate or restore a device’s network, kill a process, delete or quarantine a file, run a command, reboot, ransomware rollback
- Every exclusion, policy, policy assignment, suppression rule and detection rule change
- Uninstalling an agent, removing its licence, approving or denying an agent or a network scanner, and any direct edit of a device record
- Deleting an organization or a location
- Every change to users, roles, settings, PSA and RMM integrations and webhooks
