Connect Datto EDR
Datto EDR is Kaseya's endpoint detection and response platform. An agent on each machine collects forensic detail — running processes, loaded modules and drivers, autostart entries, local accounts,…
Written By Christopher Scaminaci
Last updated 6 days ago
Datto EDR is Kaseya's endpoint detection and response platform. An agent on each machine collects forensic detail — running processes, loaded modules and drivers, autostart entries, local accounts, network connections and what is in memory — and Datto EDR judges what it finds, raises alerts, and gives you the containment verbs to act on them. It was built as Infocyte HUNT and acquired by Datto in 2022, which is why the addresses and some of the vocabulary still say Infocyte. StackJack talks to it through the API on your own Datto EDR instance.
Connecting Datto EDR to StackJack gives your AI assistant a family of dattoedr_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Work the alert queue — list alerts and read the detection behind each one, and reach back past 30 days into the alert archive for quarterly and annual reviews
- Reconcile coverage — list installed agents with their last check-in, so you can answer whether every endpoint you bill for is actually protected and reporting in
- Investigate an incident — read the forensic detail a scan collected: processes, loaded modules, drivers, memory findings, autostart and persistence entries, network connections, local accounts, scripts and installed software
- Judge a file — look up a file's reputation by hash, and see how long it has been sitting in the estate, which is often the difference between a contained incident and a long-running one
- Report for a QBR — vulnerability advisories linking installed software to known CVEs, compliance results down to the individual failed check, and the audit log of who did what
- Follow work in flight — every scan and containment action returns a task; read its status, its per-machine progress, and the results it produced
- Scan on demand (on Pro plans) — sweep a single machine or an entire target group, and run network discovery to find machines that have no agent yet
- Contain a threat (on Pro plans) — isolate a compromised machine from the network, restore it once it is clean, terminate a process, collect evidence, and recover files
- Tune and organize (on Pro plans) — manage target groups, scheduled scans, discovery queries, detection rules, extensions, triage flags and investigation notes
How StackJack authenticates to Datto EDR
Datto EDR uses a single API token that you create inside the product. There is no client ID, no second secret and no sign-in flow — you give StackJack the address you sign in to and the token, and that is the whole setup.
Decide whose account creates the token
This is the one decision worth making carefully, because it is the only control you have over what StackJack can reach.
A Datto EDR token has no permissions of its own. It can do exactly what the person who created it can do. An administrator's token reaches everything; an analyst's token reaches less; an external analyst's token less again. There is no per-token permission screen, and the reach cannot be narrowed afterwards — the only way to change it is to create a new token from a different account.
Steps
- Choose the account. Decide which Datto EDR user's level of access you want StackJack to have, per the point above.
- Create the token. Sign in to Datto EDR. Administrators create tokens for any user under Admin > Users & Tokens > API Tokens; everyone else creates their own under My Settings > API Tokens.
- Copy it immediately. The token is shown exactly once and cannot be retrieved afterwards. Copy it before you close the panel and store it as you would a password.
- Note the date. Datto EDR tokens stop working one year after they are created and cannot be renewed. Put a reminder in your calendar a few weeks ahead of that date.
- Enter both values in StackJack. Open the Datto EDR connector, paste the address you sign in to and the token, and save.
- Test the connection. A failure here is almost always a token truncated on copy, or a typo in the address.
Your account address
The address you sign in to ends in infocyte.com, not datto.com — for example https://acme.infocyte.com. The help site lives on a Datto address, but the product itself does not, and entering a datto.com address will not connect. You can paste the full address or just the subdomain; StackJack fills in the rest. Enter the host only, with nothing after it.
The one-year token expiry
Worth repeating on its own, because it is the single most common way a working Datto EDR connection stops working.
Datto EDR tokens expire one year from the day they are created. There is no renewal, no warning inside the API, and no way to extend one. When the token lapses, Datto EDR begins refusing every request, and StackJack switches the connector off after a few consecutive failed checks — so an integration that has run quietly for a year goes quiet without anyone touching it.
The fix is quick: create a fresh token in Datto EDR, paste it into StackJack, and the connector comes back. The important part is knowing to expect it. Diary the anniversary of every token you create.
What your AI can and cannot do
Reads are on the Free tier: alerts, agents, forensic results, file reputation, vulnerabilities, compliance and the audit log. They change nothing, but they return your customers' incident detail, so grant them deliberately.
Everything that changes something is Pro, and StackJack additionally marks the actions that reach a live machine as destructive. That covers isolating a host, restoring one, terminating a process, collecting evidence, recovering files, uninstalling an agent, launching a scan or a network sweep, scheduling a recurring scan, and every delete. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.
Two are worth calling out because their risk is not obvious from the name:
- Restoring an isolated host is treated as carefully as isolating one. Putting a machine back on the network during a live incident re-exposes everything it can reach, so it carries the same marking.
- Importing or publishing an extension hands Datto EDR a script it will run on your customers' endpoints. It is the highest-risk action on this connector. Read anything you import, and prefer doing it in the Datto EDR interface where you can review it properly.
There is no test mode on this API. Every action is real, on real machines.
Things worth knowing before you rely on an answer
Alerts older than 30 days are somewhere else. Datto EDR keeps the last 30 days in its main alert list and moves everything before that into a separate archive. A quarterly or annual review that only reads the main list sees empty months. Ask for archived alerts when your window goes back further than a month.
Results cover the last 7 days unless you say otherwise. Datto EDR groups scan results into pre-computed rollups — Global or one target group, over 7, 30 or 90 days. If your question does not name one, StackJack reads from your Global Last 7 Days rollup, so the answer quietly covers only the last week. Name the rollup you mean when the question is about a longer period or a single customer. Ask for the list of rollups first if you are not sure which one you want. If your account has no Global rollup at all, the answer covers every rollup instead, so ask for one by name when the window matters.
Scans and containment actions do not return their results. Each one starts a task and hands back a task reference. Your AI follows the task to completion and then reads the findings from the scan, alert and extension-result tools. This is how the product works rather than a limitation, but it means "isolate that machine" is answered by "the isolation has started", with confirmation a moment later.
Narrow your questions. Datto EDR warns that broad, unfiltered queries slow its database down, and the forensic tables on a large estate are very large. A question scoped to a customer, a machine or a date range is faster and kinder to the platform than one that is not.
Plans and limits
Read tools are available on the Free tier. Everything that writes, contains, scans or changes configuration is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Datto EDR tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Datto EDR publishes no rate limit, so StackJack paces requests defensively and backs off on its own if the platform pushes back. A large read is usually slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Several customers
Every customer has their own Datto EDR account. Add one connection per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.
Troubleshooting
"Datto EDR rejected the API token" — the token has almost certainly expired. Tokens last one year from creation and cannot be renewed, so on a connection that used to work this is the first thing to check. It can also mean the token was revoked, mistyped, or that the user who created it was removed from Datto EDR. Create a new token, paste it in, and run a Test Connection.
"Datto EDR accepted the token but refused this operation" — the account that created the token cannot reach that area. Because a token inherits its creator's access and has no settings of its own, the fix is to create the token again from an account with more access. There is no permission to switch on.
The connector switched itself off on its own — StackJack disables a connector after several consecutive failed checks. On Datto EDR the usual cause is the one-year token expiry arriving. Create a fresh token and re-enter it; the connector re-enables when the check passes.
"Could not find that record" — check the identifier still exists in Datto EDR, and check the instance address saved in StackJack matches the one you sign in to. Both look the same from outside. If you were looking for an older alert, remember the 30-day split.
A containment action reported that an extension is missing — the containment verbs run response extensions that have to be present in your instance. If the isolation extension has never been imported, or was deleted, StackJack refuses rather than starting an action that would quietly do nothing. Import the extension in Datto EDR and try again.
A machine shows no scan results — check it has an active agent, or a reachable address in the target group. A machine Datto EDR cannot reach looks the same as a machine with nothing to report.
Datto EDR tools
dattoedr_ · 96 tools · Free 61 · Pro 35
Platform
Alerts
Endpoints & Estate
Scan Credentials
Scans & Scheduling
Response Actions
Forensic Results
Threat Intelligence & Triage
Vulnerabilities & Compliance
Detection Rules & Extensions
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team