Talk to us
by DattoTechBag Intel Page

Datto EDR

Antivirus catches what it already knows. The attack it doesn’t know encrypts a file share at 2 a.m. Detection, response and rollback belong on the same agent — Datto EDR is Kaseya’s endpoint detection and response for MSPs — behaviour and memory analysis, MITRE ATT&CK-mapped alerts, 65+ automated responses and Windows ransomware rollback, with Datto AV on the same agent.

EDR for Windows, macOS and LinuxDatto AV and Windows rollback on one agentQuoted alone or inside Kaseya 365

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public price alone or in Kaseya 365 Endpoint, which starts at 50 endpoints for new customers
Quote
Efficacy
Datto’s figure with Datto AV, from a July 2024 Miercom study that Datto commissioned
99.62%
Telemetry
Searchable endpoint records; alerts are kept a year and quarantined files 180 days
9 months
India
AWS in Virginia, Ireland or Sydney; there is no India storage region
Sydney

Quick answer

Datto EDR is the endpoint detection and response tool from Datto, a Kaseya company. One agent on Windows, macOS and Linux records behaviour, raises MITRE ATT&CK-mapped alerts and runs 65+ automated responses; on Windows it adds ransomware detection and file rollback. Datto AV is the companion antivirus. Both are quote-only, sold alone or in Kaseya 365 Endpoint, with data on AWS in the US, Ireland or Sydney — none in India. Read more ↓ Show less ↑
Part 01 · Orient

The Datto platform family

This page covers Datto EDR — with Datto AV and ransomware rollback folded in. The rest:

Quick facts

30-second orientation
Product
EDR for MSPs, with Datto AV and ransomware rollback folded in
Owner
Kaseya — bought Datto for $6.2B in June 2022
Origin
Infocyte’s EDR technology, which Datto bought in January 2022
Agents
EDR on Windows, macOS and Linux; Datto AV on Windows and macOS
Rollback
Windows 10+ and Server 2012+ only; no reliance on Shadow Copy
Price
Quote only — alone, or inside Kaseya 365 Endpoint
Test claim
99.62% malware efficacy with Datto AV, in a Miercom study Datto commissioned
Analysts
No analyst placement; no public MITRE or AV-TEST result found
India
No India region; data sits in Virginia, Ireland or Sydney
In India via
TechBag — scoping, quote comparison and support
Part 02 · Learn

Understand EDR before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is EDR?

EDR records what happens on each endpoint so attacks that slip past antivirus are still seen, contained and cleaned up.

Signature antivirus and a restore from backup vs Datto EDR — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSignature AV and a restore from backupDatto EDR
What catches an attackSignature AV and a user’s phone callBehaviour, memory and ransomware detection
Alert contextA file name and a hashATT&CK mapping plus mitigation guidance
First responseA technician drives to the siteIsolate, kill or quarantine from the alert
Encrypted filesRestore last night’s backupRoll files back by process or time window
ToolingSeparate AV, EDR and DNS filter consolesDatto AV, EDR and DNS Secure on one agent
What it is NOT—Not a managed SOC; rollback is Windows-only

The cheapest test is a pilot on one client: deploy the agent in alert-only mode, switch on the ransomware policy, and run a rollback drill on a spare Windows PC.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
On every endpoint

Agent

Datto Endpoint Security agent

One agent per device. Attach an EDR, Datto AV or ransomware policy and it installs whatever each needs — no second agent to roll out, and uninstall protection guards it.

02
Where alerts and data live

Instance

Datto EDR cloud instance

A cloud console on AWS in Virginia, Ireland or Sydney. It keeps searchable telemetry for nine months, alerts for a year and quarantined files for 180 days.

03
What runs on each device

Policies

EDR, AV and ransomware policies

A real-time EDR monitor, an alert-only AV policy for first deployments and a ransomware policy that isolates the host and kills the process are switched on by default.

04
What it plugs into

Integrations

Kaseya integrations

Datto RMM syncs sites and deploys the agent, VSA 10 adds console buttons, Autotask and BMS take tickets and billing, and Kaseya MDR can watch the alerts around the clock.

One agent runs EDR, AV and ransomware policies — reporting to an AWS console in Virginia, Ireland or Sydney, none in India.

Part 03 · Evaluate

Nine capabilities. Prevent, detect, respond.

Datto EDR watches every endpoint for attacks antivirus misses, contains them in one click and rolls encrypted Windows files back.

Prevent
Datto AV

Next-gen antivirus beside the EDR

Datto AV scans on access or on demand with machine learning and heuristics, quarantines threats and runs on Windows and macOS 13 or later.

Prevent
DNS Secure

DNS filtering at no extra cost

Built into Datto AV since 2025, DNS Secure blocks malicious domains and risky site categories before a connection opens; it does not run on macOS.

Prevent
Tamper

Tamper and uninstall protection

Tamper protection blocks unauthorised policy changes, and uninstall protection stops even Datto RMM from removing the agent while it is on.

Detect
Behaviour

Behaviour and memory analysis

Behavioural rules and Datto’s patented deep memory analysis look for fileless attacks and process tricks that a signature scan would miss.

Detect
ATT&CK

Alerts mapped to MITRE ATT&CK

Alerts focus on the top 20 critical behaviours, carry ATT&CK context and come with Kaseya’s automated mitigation guidance for each one.

Detect
Ransomware

Ransomware detection on Windows

A ransomware policy watches for mass encryption on Windows 10+ and Server 2012+; new policies default to the stronger Enhanced setting.

Respond
One click

Respond from the alert

From the alert dashboard a technician can terminate a process, isolate the host or quarantine a file in one click, then open the device in RMM.

Respond
Automation

65+ automated responses

Over 65 automated response actions can fire without a person, so the kill chain is cut even when an alert lands at 3 a.m. with nobody watching.

Respond
Rollback

Roll encrypted files back

A minifilter driver tracks file changes so encrypted files roll back by process or time window, without relying on Windows Shadow Copy.

See it, don’t just read it

Watch Datto EDR in action

Two customer stories from Kaseya’s own channel — Datto publishes no Datto EDR product video on YouTube (its demos sit on Wistia), and the second clip credits “Kaseya’s EDR and backup” without naming Datto EDR.

Kaseya (official)·2:35

From No SOC to Full Protection - Ark ICT’s Cybersecurity Transformation with Kaseya

An MSP customer story on getting a SOC and EDR through Kaseya 365 (2025).

Kaseya (official)·2:27

Taming the digital frontier | How the IT Cowboy used Kaseya to stop ransomware in its tracks

A customer credits “Kaseya’s EDR and backup” with stopping ransomware; Datto EDR is not named.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Datto EDR

Every MSP client is one click from ransomware. Datto EDR contains it and rolls the files back.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Rollback that does not trust Shadow Copy

Ransomware deletes Windows Shadow Copies early, so rollback built on them often has nothing left. Datto EDR’s rollback uses its own minifilter driver to track changes and can restore encrypted files by process or time window. It covers Windows 10+ and Server 2012+, is not advised on database servers or domain controllers, and comes with Datto EDR.

02

Alerts a small team can act on

Datto EDR narrows detection to the top 20 critical behaviours, maps each alert to MITRE ATT&CK and attaches Kaseya’s mitigation advice. Over 65 automated actions and one-click isolate, kill and quarantine mean a generalist technician can contain an incident without being a threat hunter first.

03

Already inside Kaseya 365 Endpoint

Datto EDR, Datto AV and ransomware detection are three of the seven components of Kaseya 365 Endpoint, beside the RMM, third-party patching and endpoint backup; Pro adds a managed SOC. Kaseya publishes no current price for it, and new customers start at 50 endpoints. MSPs on Datto RMM get agent deployment and site sync built in.

04

Where it stops

Ransomware detection and rollback are Windows-only, and Datto AV does not run on Linux. The 99.62% headline comes from a study Datto commissioned; TechBag found no public MITRE or AV-TEST result. Integrations are Kaseya-first. Data sits in Virginia, Ireland or Sydney, with no India region, and every price is a quote.

The idea
Detect, contain and roll back from one alert
The bundle
Inside Kaseya 365 Endpoint with Datto AV
The price
Quote only; no public list price
Proof, not promises

The numbers behind the platform

65+ actions
automated response actions that can interrupt an attack without a technician
— Vendor
20 behaviours
critical behaviours the alerting focuses on, to keep noise down
— Vendor
9 months
of endpoint telemetry kept searchable on the Search page
— Vendor
180 days
that quarantined files are retained; historical alerts stay for one year
— Vendor
3 AWS regions
for EDR and AV data: Virginia, Ireland and Sydney — none in India
— Vendor
50 endpoints
the starting minimum for new Kaseya 365 Endpoint customers
— Vendor

What your Datto EDR rollout looks like

Week 1Model

Count endpoints by OS

List Windows, macOS and Linux devices per client; rollback and ransomware detection cover Windows only, so the mix sets scope.

Week 2Decide

Standalone or bundle

Put a Datto EDR and AV quote beside a Kaseya 365 Endpoint quote; the bundle starts at 50 endpoints and adds RMM and backup.

Week 3Pilot

Pilot in alert-only mode

Deploy the agent to one client with the alert-only AV policy, learn what to allowlist, and switch on the ransomware policy.

Month 2Expand

Turn on rollback and RMM

Enable File Recovery on Windows endpoints, connect Datto RMM or VSA 10, and send alerts to Autotask, BMS or Kaseya MDR.

Month 3Commit

Roll out and run drills

Replace the old AV across clients, set uninstall protection, and run a ransomware drill to test isolation and rollback.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
120+ reviews*
82% would recommend
Ransomware rollback4.4
RMM integration4.4
Alert clarity4.2
Mac and Linux depth3.5
Pricing clarity3.1
5★
46%
4★
34%
3★
13%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Managed Services
“A payroll PC started encrypting on a Friday night. The host was isolated and rollback put the spreadsheets back before Monday.”
Security Lead
Managed Services
IT Services
“Each alert names the ATT&CK technique and the next step. Our level-one techs close most of them without escalating to me.”
SOC Manager
IT Services
Engineering
“Rollback only covers Windows, so our two Linux file servers still lean on backups. Know that before you promise clients anything.”
Infrastructure Lead
Engineering
IT Services
“Turning on the policy in Datto RMM deployed the agent to 900 machines overnight. The site sync saved us a week of mapping.”
MSP Owner
IT Services
BFSI
“A Bengaluru lender asked where the telemetry sits. Sydney was the answer, and it went into their outsourcing risk review.”
Compliance Manager
BFSI
Healthcare
“We asked for independent test results and got the Miercom study Datto paid for. Fine as a start; we ran our own pilot too.”
IT Director
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the MSP endpoint security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag MSP Endpoint Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Datto EDRThis page

Kaseya-owned; quoted alone or inside Kaseya 365 Endpoint.

Grid 02 · The architecture

Ransomware Recovery × RMM Fit

The grid nobody publishes — how far each agent can undo ransomware on its own vs how natively it plugs into an MSP’s RMM and PSA.

RMM-native, recovery-lightRMM-native with rollbackStandalone, detection-firstStandalone with rollback
Datto EDRThis page

Windows rollback without Shadow Copy; Datto RMM and Autotask built in.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Datto EDR vs the MSP endpoint-security field

Against SentinelOne, CrowdStrike Falcon Insight, Sophos Intercept X, Bitdefender GravityZone EDR and N-able EDR — on hosting, OS coverage, price, retention, rollback, integrations, support and India.

DimensionDatto EDRSentinelOne SingularityCrowdStrike Falcon InsightSophos Intercept XBitdefender GravityZone EDRN-able EDR
What it isKaseya’s MSP EDR + AVAutonomous EPP + EDREDR inside FalconDeep-learning endpointEDR in GravityZoneSentinelOne, N-able-sold
DeploymentCloud console onlySaaS; on-prem announcedCloud onlyCloud console onlyCloud or on-prem consoleHosted S1 console
OS coverageAV has no Linux agentWin, Mac, Linux, K8sWin, Mac, LinuxWin, Mac, LinuxWin, Mac, Linux, VMsWin, Mac, Linux
Pricing modelQuote, or in a bundlePer endpoint a yearPer device, annualQuote, per userPer device, by packageQuote, via the RMM
Published entry priceNot published$179.99/endpoint/yr$184.99/device/yr~$25–66/user, reportedEDR tier not listedNot published
Included vs add-onAV, DNS, rollback inHunting, MDR by tierSIEM, identity inXDR tier; MDR extraMany paid add-onsMDR, retention extra
Telemetry retention9 months searchable14 or 90 daysDefault not published90-day data lake3 days raw, 90 alerts14 days standard
Ransomware rollbackWindows, no Shadow CopyWindows, needs VSSNo native rollbackCryptoGuard revertsCopies, no Shadow CopyS1 rollback, Windows
IntegrationsDatto RMM, VSA, AutotaskAPI-first, MSP partnersNo native MSP RMMDatto RMM, PSA syncDatto RMM, VSA, NinjaNative in N-central
Governance and SSOKaseyaOne SSO, 3 rolesSSO, RBAC, multi-tenantSAML SSO, Flight ControlFederated sign-in, RBACSAML 2.0, multi-tenantRBAC synced, SSO unclear
India storage regionNo India; Sydney nearestMumbai regionPlanned, no dateMumbai, liveNo India; SingaporeNot published
Support and MDR24/7 support; MDR apartWayfinder MDR add-onFalcon Complete MDRSophos MDR, 24/7Bitdefender MDRManaged EDR + Adlumin
Lock-in and exitBundle-bound valueAnnual, via partners30-day refund, FlexData deleted at exitAuto-renews; 50 minimumTied to the RMM
Best fitKaseya and Datto MSPsRollback plus India dataOne agent, many modulesIndia data, PSA linksValue or on-prem consoleN-able RMM MSPs
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Datto EDR if…

  • ✓Your MSP runs Datto RMM, VSA 10 or Autotask and wants EDR alerts, agent deployment and tickets wired in from day one
  • ✓Windows ransomware is the risk you lose sleep over, and rollback without Shadow Copy is the safety net you want
  • ✓Kaseya 365 Endpoint already pays for the EDR and AV, so switching them on costs nothing extra

Compare alternatives if…

  • ✓You need a documented India storage region — SentinelOne and Sophos both document Mumbai
  • ✓You want public third-party test results rather than a study the vendor commissioned
  • ✓You sign in through your own identity provider — SentinelOne, CrowdStrike, Sophos and Bitdefender document SAML or federated SSO

Do not expect…

  • ✓A public price, alone or in Kaseya 365 Endpoint
  • ✓A managed SOC — that is Kaseya MDR, sold separately or in Kaseya 365 Endpoint Pro
  • ✓Rollback on database servers, domain controllers, USB drives or virtual disk files

Datto EDR is one of 47 endpoint protection products TechBag carries. The Endpoint Protection guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does manual incident clean-up cost you?

Drag the sliders (protected endpoints; technician-hour cost). Estimates model technician time spent triaging alerts, cleaning infected machines and restoring encrypted files at an assumed 1.5 hours per endpoint a year, with 70% of it removed by automated response and rollback. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual incident-handling cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only: Kaseya publishes no current price for Datto EDR, Datto AV or Kaseya 365 Endpoint, which bundles both with an RMM, patching and endpoint backup. New Kaseya 365 Endpoint customers start at 50 endpoints, and the managed SOC is in the Pro tier only. Prices are in US dollars; TechBag sets the quotes side by side before you commit.

Datto EDR and AV, standalone

Best for MSPs adding only endpoint security

  • Quote only — no published list price
  • EDR, AV, ransomware detection and rollback
  • Own console; Kaseya RMM and PSA integrations

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Kaseya 365 Endpoint

Best for MSPs wanting RMM, security and backup

  • Quote only — no current published price
  • RMM, AV, EDR, patching and endpoint backup
  • 50-endpoint minimum; managed SOC on Pro only

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Region

Which AWS region — Virginia, Ireland or Sydney — will hold your telemetry, and do client contracts accept storage outside India?

2
Operating systems

How many Linux and Mac endpoints do you run? Rollback is Windows-only and Datto AV has no Linux agent.

3
Server roles

Which servers are database hosts or domain controllers? Datto does not recommend rollback on high-I/O roles like these.

4
Bundle

Is Datto EDR cheaper alone or inside Kaseya 365 Endpoint? Get both quotes; neither price is published.

5
Minimum

Can you commit to 50 endpoints? New Kaseya 365 Endpoint customers must start at that count.

6
Monitoring

Who reads alerts at night? Datto EDR is a tool; a 24/7 SOC is Kaseya MDR, a separate contract or the Pro tier.

7
Evidence

Will you run your own pilot? The 99.62% figure comes from a study Datto commissioned, not a public lab test.

8
Integrations

Is your PSA Autotask or BMS? Datto documents Kaseya integrations; check any third-party PSA in the pilot.

FAQ

Questions buyers ask

Datto EDR is Kaseya’s endpoint detection and response tool. One agent on Windows, macOS and Linux records behaviour, raises MITRE ATT&CK-mapped alerts and runs 65+ automated responses; Windows also gets ransomware detection and rollback. It grew from Infocyte, which Datto bought in January 2022.

Ready to evaluate Datto EDR?

Count your endpoints by operating system first, or let a TechBag advisor set a Datto EDR quote beside Kaseya 365 Endpoint and the rival EDRs.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.