Antivirus catches what it already knows. The attack it doesn’t know encrypts a file share at 2 a.m. Detection, response and rollback belong on the same agent — Datto EDR is Kaseya’s endpoint detection and response for MSPs — behaviour and memory analysis, MITRE ATT&CK-mapped alerts, 65+ automated responses and Windows ransomware rollback, with Datto AV on the same agent.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Datto EDR — with Datto AV and ransomware rollback folded in. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
EDR records what happens on each endpoint so attacks that slip past antivirus are still seen, contained and cleaned up.
What consolidation actually replaces, dimension by dimension.
| Dimension | Signature AV and a restore from backup | Datto EDR |
|---|---|---|
| What catches an attack | Signature AV and a user’s phone call | Behaviour, memory and ransomware detection |
| Alert context | A file name and a hash | ATT&CK mapping plus mitigation guidance |
| First response | A technician drives to the site | Isolate, kill or quarantine from the alert |
| Encrypted files | Restore last night’s backup | Roll files back by process or time window |
| Tooling | Separate AV, EDR and DNS filter consoles | Datto AV, EDR and DNS Secure on one agent |
| What it is NOT | — | Not a managed SOC; rollback is Windows-only |
The cheapest test is a pilot on one client: deploy the agent in alert-only mode, switch on the ransomware policy, and run a rollback drill on a spare Windows PC.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
One agent per device. Attach an EDR, Datto AV or ransomware policy and it installs whatever each needs — no second agent to roll out, and uninstall protection guards it.
A cloud console on AWS in Virginia, Ireland or Sydney. It keeps searchable telemetry for nine months, alerts for a year and quarantined files for 180 days.
A real-time EDR monitor, an alert-only AV policy for first deployments and a ransomware policy that isolates the host and kills the process are switched on by default.
Datto RMM syncs sites and deploys the agent, VSA 10 adds console buttons, Autotask and BMS take tickets and billing, and Kaseya MDR can watch the alerts around the clock.
One agent runs EDR, AV and ransomware policies — reporting to an AWS console in Virginia, Ireland or Sydney, none in India.
Datto EDR watches every endpoint for attacks antivirus misses, contains them in one click and rolls encrypted Windows files back.
Datto AV scans on access or on demand with machine learning and heuristics, quarantines threats and runs on Windows and macOS 13 or later.
Built into Datto AV since 2025, DNS Secure blocks malicious domains and risky site categories before a connection opens; it does not run on macOS.
Tamper protection blocks unauthorised policy changes, and uninstall protection stops even Datto RMM from removing the agent while it is on.
Behavioural rules and Datto’s patented deep memory analysis look for fileless attacks and process tricks that a signature scan would miss.
Alerts focus on the top 20 critical behaviours, carry ATT&CK context and come with Kaseya’s automated mitigation guidance for each one.
A ransomware policy watches for mass encryption on Windows 10+ and Server 2012+; new policies default to the stronger Enhanced setting.
From the alert dashboard a technician can terminate a process, isolate the host or quarantine a file in one click, then open the device in RMM.
Over 65 automated response actions can fire without a person, so the kill chain is cut even when an alert lands at 3 a.m. with nobody watching.
A minifilter driver tracks file changes so encrypted files roll back by process or time window, without relying on Windows Shadow Copy.
Two customer stories from Kaseya’s own channel — Datto publishes no Datto EDR product video on YouTube (its demos sit on Wistia), and the second clip credits “Kaseya’s EDR and backup” without naming Datto EDR.
An MSP customer story on getting a SOC and EDR through Kaseya 365 (2025).
A customer credits “Kaseya’s EDR and backup” with stopping ransomware; Datto EDR is not named.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Ransomware deletes Windows Shadow Copies early, so rollback built on them often has nothing left. Datto EDR’s rollback uses its own minifilter driver to track changes and can restore encrypted files by process or time window. It covers Windows 10+ and Server 2012+, is not advised on database servers or domain controllers, and comes with Datto EDR.
Datto EDR narrows detection to the top 20 critical behaviours, maps each alert to MITRE ATT&CK and attaches Kaseya’s mitigation advice. Over 65 automated actions and one-click isolate, kill and quarantine mean a generalist technician can contain an incident without being a threat hunter first.
Datto EDR, Datto AV and ransomware detection are three of the seven components of Kaseya 365 Endpoint, beside the RMM, third-party patching and endpoint backup; Pro adds a managed SOC. Kaseya publishes no current price for it, and new customers start at 50 endpoints. MSPs on Datto RMM get agent deployment and site sync built in.
Ransomware detection and rollback are Windows-only, and Datto AV does not run on Linux. The 99.62% headline comes from a study Datto commissioned; TechBag found no public MITRE or AV-TEST result. Integrations are Kaseya-first. Data sits in Virginia, Ireland or Sydney, with no India region, and every price is a quote.
List Windows, macOS and Linux devices per client; rollback and ransomware detection cover Windows only, so the mix sets scope.
Put a Datto EDR and AV quote beside a Kaseya 365 Endpoint quote; the bundle starts at 50 endpoints and adds RMM and backup.
Deploy the agent to one client with the alert-only AV policy, learn what to allowlist, and switch on the ransomware policy.
Enable File Recovery on Windows endpoints, connect Datto RMM or VSA 10, and send alerts to Autotask, BMS or Kaseya MDR.
Replace the old AV across clients, set uninstall protection, and run a ransomware drill to test isolation and rollback.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A payroll PC started encrypting on a Friday night. The host was isolated and rollback put the spreadsheets back before Monday.”
“Each alert names the ATT&CK technique and the next step. Our level-one techs close most of them without escalating to me.”
“Rollback only covers Windows, so our two Linux file servers still lean on backups. Know that before you promise clients anything.”
“Turning on the policy in Datto RMM deployed the agent to 900 machines overnight. The site sync saved us a week of mapping.”
“A Bengaluru lender asked where the telemetry sits. Sydney was the answer, and it went into their outsourcing risk review.”
“We asked for independent test results and got the Miercom study Datto paid for. Fine as a start; we ran our own pilot too.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the MSP endpoint security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Kaseya-owned; quoted alone or inside Kaseya 365 Endpoint.
The grid nobody publishes — how far each agent can undo ransomware on its own vs how natively it plugs into an MSP’s RMM and PSA.
Windows rollback without Shadow Copy; Datto RMM and Autotask built in.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against SentinelOne, CrowdStrike Falcon Insight, Sophos Intercept X, Bitdefender GravityZone EDR and N-able EDR — on hosting, OS coverage, price, retention, rollback, integrations, support and India.
| Dimension | Datto EDR | SentinelOne Singularity | CrowdStrike Falcon Insight | Sophos Intercept X | Bitdefender GravityZone EDR | N-able EDR |
|---|---|---|---|---|---|---|
| What it is | Kaseya’s MSP EDR + AV | Autonomous EPP + EDR | EDR inside Falcon | Deep-learning endpoint | EDR in GravityZone | SentinelOne, N-able-sold |
| Deployment | Cloud console only | SaaS; on-prem announced | Cloud only | Cloud console only | Cloud or on-prem console | Hosted S1 console |
| OS coverage | AV has no Linux agent | Win, Mac, Linux, K8s | Win, Mac, Linux | Win, Mac, Linux | Win, Mac, Linux, VMs | Win, Mac, Linux |
| Pricing model | Quote, or in a bundle | Per endpoint a year | Per device, annual | Quote, per user | Per device, by package | Quote, via the RMM |
| Published entry price | Not published | $179.99/endpoint/yr | $184.99/device/yr | ~$25–66/user, reported | EDR tier not listed | Not published |
| Included vs add-on | AV, DNS, rollback in | Hunting, MDR by tier | SIEM, identity in | XDR tier; MDR extra | Many paid add-ons | MDR, retention extra |
| Telemetry retention | 9 months searchable | 14 or 90 days | Default not published | 90-day data lake | 3 days raw, 90 alerts | 14 days standard |
| Ransomware rollback | Windows, no Shadow Copy | Windows, needs VSS | No native rollback | CryptoGuard reverts | Copies, no Shadow Copy | S1 rollback, Windows |
| Integrations | Datto RMM, VSA, Autotask | API-first, MSP partners | No native MSP RMM | Datto RMM, PSA sync | Datto RMM, VSA, Ninja | Native in N-central |
| Governance and SSO | KaseyaOne SSO, 3 roles | SSO, RBAC, multi-tenant | SAML SSO, Flight Control | Federated sign-in, RBAC | SAML 2.0, multi-tenant | RBAC synced, SSO unclear |
| India storage region | No India; Sydney nearest | Mumbai region | Planned, no date | Mumbai, live | No India; Singapore | Not published |
| Support and MDR | 24/7 support; MDR apart | Wayfinder MDR add-on | Falcon Complete MDR | Sophos MDR, 24/7 | Bitdefender MDR | Managed EDR + Adlumin |
| Lock-in and exit | Bundle-bound value | Annual, via partners | 30-day refund, Flex | Data deleted at exit | Auto-renews; 50 minimum | Tied to the RMM |
| Best fit | Kaseya and Datto MSPs | Rollback plus India data | One agent, many modules | India data, PSA links | Value or on-prem console | N-able RMM MSPs |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Datto EDR is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (protected endpoints; technician-hour cost). Estimates model technician time spent triaging alerts, cleaning infected machines and restoring encrypted files at an assumed 1.5 hours per endpoint a year, with 70% of it removed by automated response and rollback. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only: Kaseya publishes no current price for Datto EDR, Datto AV or Kaseya 365 Endpoint, which bundles both with an RMM, patching and endpoint backup. New Kaseya 365 Endpoint customers start at 50 endpoints, and the managed SOC is in the Pro tier only. Prices are in US dollars; TechBag sets the quotes side by side before you commit.
Best for MSPs adding only endpoint security
Best for a broader rollout
Best for MSPs wanting RMM, security and backup
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which AWS region — Virginia, Ireland or Sydney — will hold your telemetry, and do client contracts accept storage outside India?
How many Linux and Mac endpoints do you run? Rollback is Windows-only and Datto AV has no Linux agent.
Which servers are database hosts or domain controllers? Datto does not recommend rollback on high-I/O roles like these.
Is Datto EDR cheaper alone or inside Kaseya 365 Endpoint? Get both quotes; neither price is published.
Can you commit to 50 endpoints? New Kaseya 365 Endpoint customers must start at that count.
Who reads alerts at night? Datto EDR is a tool; a 24/7 SOC is Kaseya MDR, a separate contract or the Pro tier.
Will you run your own pilot? The 99.62% figure comes from a study Datto commissioned, not a public lab test.
Is your PSA Autotask or BMS? Datto documents Kaseya integrations; check any third-party PSA in the pilot.
Count your endpoints by operating system first, or let a TechBag advisor set a Datto EDR quote beside Kaseya 365 Endpoint and the rival EDRs.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.