Datto SaaS Protection Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Datto SaaS Protection Tools
dattosaas_ · 4 tools · Free 3 · Pro 1
Coming soon — cannot currently be configured. Its tools are listed here so the reference stays a complete inventory, but the connector cannot be added to an organization yet and there is no setup guide for it.
Backup reporting for Microsoft 365 and Google Workspace seats. It shares the same host, the same v1 API and the same Partner Portal key pair as Datto BCDR - one Datto API serving two separately sold products - so a partner running both enters the same two secrets twice. Four endpoints is the complete vendor-documented surface. The domain list is the only source of both the SaaS customer id and the external subscription id, and those sit in adjacent path segments on the write, so they are easy to swap by mistake. Paging is _page and _perPage with a leading underscore, capped at 100; plain page and perPage are ignored silently and return an unpaginated result. The single write, a bulk seat change, is destructive: unlicensing strips backup protection from up to 100 end users at once, starts data deletion and changes what the partner is billed. Seat and action types are case-sensitive.
Datto SaaS Protection tool groups
Domains
dattosaas_list_domains details
dattosaas_list_domains details
[Datto SaaS Protection] List every Microsoft 365 and Google Workspace domain the partner protects — the ENTRY POINT for this connector, and the only place its identifiers come from. Each domain carries a saasCustomerId and an externalSubscriptionId. Those are two DIFFERENT values: the customer id is a number identifying the protected customer, the subscription id is a string identifying their Datto subscription. dattosaas_list_seats and dattosaas_list_applications need the customer id; dattosaas_bulk_seat_change needs BOTH, and passing them in the wrong order is the most common failure on this connector. Start here before calling anything else. Takes no arguments and returns every domain in one response — there is no pagination on this endpoint.
Seats
dattosaas_bulk_seat_change details
dattosaas_bulk_seat_change details
[Datto SaaS Protection] Change the backup licensing state of up to 100 seats in ONE call: License them, Unlicense them, or Pause them. DESTRUCTIVE AND BILLABLE — read this before calling. Unlicense STOPS future backups for those people and puts data Datto has already captured on its deletion path for unlicensed seats, and licence counts are what Datto bills the partner on, so any change here alters both protection and cost. There is no undo beyond re-licensing, which does not bring back data already purged. Requires BOTH identifiers from dattosaas_list_domains, and they are different values that sit next to each other: saasCustomerId is the customer number and externalSubscriptionId is the subscription string — swapping them is the most common mistake on this connector. The ids argument takes remoteId values from dattosaas_list_seats (nothing else is accepted), at most 100 per call. seatType and actionType are CASE-SENSITIVE and are rejected locally if misspelled. actionType has no default on purpose: always state it explicitly. Always list the seats first and confirm you are acting on the intended customer and the intended people.
dattosaas_list_seats details
dattosaas_list_seats details
[Datto SaaS Protection] List the protected seats for one customer — the end users, shared mailboxes, sites, team sites and teams Datto is backing up — with each seat's name, type and licensing state. Every seat carries a remoteId, which is the ONLY identifier dattosaas_bulk_seat_change accepts; unlike the applications read, remoteId is included here by default. Requires a saasCustomerId from dattosaas_list_domains. Read this before any seat change so you are acting on current ids and can see what each seat's state is now. Paginated: the response wraps items alongside a pagination object carrying totalPages.
Backups
dattosaas_list_applications details
dattosaas_list_applications details
[Datto SaaS Protection] Read backup status per protected application for one customer — Exchange, OneDrive, SharePoint, Teams, Gmail, Drive and so on — with each application's last backup result and time. This is the tool that answers "is this customer's Microsoft 365 actually being backed up, and did it succeed?". Requires a saasCustomerId from dattosaas_list_domains. Two things worth knowing: daysUntil is a LOOK-AHEAD window in days (Datto defaults to 10 and caps it at 30, and larger values are clamped), and remoteId values are OMITTED unless you pass includeRemoteId=true — without them the results cannot be fed to dattosaas_bulk_seat_change, which accepts nothing else.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team