> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Datto EDR to Neo

> Create a Datto EDR API token and save it in Neo with your console address

You connect Datto EDR once at the MSP level. One API token covers every organization its user can see, for both Datto EDR and Datto AV.

## 1. Create a user and an API token for Neo

<Steps>
  <Step title="Add a dedicated user for Neo">
    In Datto EDR, open **Admin** > **Users & Tokens** and add a user for Neo. The token acts with that user's role:

    | Role | What the role allows in Datto EDR |
    | - | - |
    | **Admin** | Every action, including AV exclusions and policy changes |
    | **External Analyst** | Restore or delete quarantined files and run alert responses, only in the organizations you assign to the user |
    | **Analyst** | Respond to alerts and isolate devices; it cannot restore quarantined files |

    Datto's [role table](https://edr.datto.com/help/Content/01-getting-started/add-users.htm) lists every action per role.
  </Step>

  <Step title="Create the token">
    Open **API Tokens**, click **Create new token** for that user, and copy the token. Datto EDR shows it once.
  </Step>

  <Step title="Copy your console address">
    Copy the address you open Datto EDR at from the browser, for example `https://yourcompany.infocyte.com`.
  </Step>
</Steps>

<Warning>
  A Datto EDR token expires one year after you create it. Create a new token before then and save it here.
</Warning>

## 2. Add the token in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **Datto EDR**](https://dashboard.neoagent.io/integrations?open=datto_edr), under Security.
  </Step>

  <Step title="Save the console address and the token">
    Paste the console address and the API token and click **Save settings**. Neo checks them against your console before saving, so a wrong address or token is rejected straight away.
  </Step>
</Steps>

## 3. Turn Datto EDR on per agent

<Steps>
  <Step title="Open the agent">
    In the Neo Dashboard, open the agent and its **Integrations** tab.
  </Step>

  <Step title="Choose an access profile">
    Under **Datto EDR**, choose a profile, or set each permission group by hand.
  </Step>

  <Step title="Tell the agent what to do">
    Add a line to the agent's instructions, for example: "When a ticket is a Datto AV quarantine, find the alert and the quarantined file in Datto EDR, judge whether it is a false positive, and write what you found in an internal note."
  </Step>
</Steps>

| Group | Covers |
| - | - |
| Alerts | Alerts, alert details, the archive, comments and AI assist answers |
| Quarantine and Files | Quarantined files, file reputation, file flags, prevalence and lab submissions |
| Response Actions | Isolation, response extensions, AV alert actions, ransomware rollback |
| Devices | Devices, device groups, applications, licences, scans and scan tasks |
| Exclusions, Policies and Rules | Datto AV exclusions, policies, suppression rules, detection rules |
| Organizations and Locations | Your clients' organizations and their locations |
| Scan Data | Datto EDR scan data and searches |
| Account and Integrations | Users, roles, settings, PSA and RMM set-up, webhooks, reports |

| Profile | Runs on its own | Asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read | Every write |
| **IT Admin** | Alert archive and comments, scans, searches, lab submission, file retrieval, licence assignment, device, organization and location housekeeping, reports | The writes below |
| **Full Automation** | Every other write | The writes below |

These always ask a technician, under every profile:

* Restoring or deleting a quarantined file, and flagging a file or an application
* Every response action: isolate or restore a device's network, kill a process, delete or quarantine a file, run a command, reboot, ransomware rollback
* Every exclusion, policy, policy assignment, suppression rule and detection rule change
* Uninstalling an agent, removing its licence, approving or denying an agent or a network scanner, and any direct edit of a device record
* Deleting an organization or a location
* Every change to users, roles, settings, PSA and RMM integrations and webhooks


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.