Pre-deployment checklist
Before deploying the Datto EDR agent, confirm that your devices and environment meet the requirements in this checklist. Most deployment failures trace back to a small number of known configuration and environment conditions, all of which can be identified and resolved in advance.
Work through each item before you begin. Each item describes what to verify, why it affects deployment, and where to find the supporting documentation. If you complete the checklist and the agent still does not deploy, the information you gather here, particularly the agent log files in item 12, is what Datto Support will need to investigate further.
What this checklist is and is not
This is a list of known conditions that prevent the agent from deploying. It is not a step-by-step troubleshooting guide.
Not every item applies to every environment. Items 1 and 2 apply only if you deploy Datto EDR through the Datto RMM integration. Item 6 applies only to macOS.
To confirm that your devices and environment meet deployment requirements:
- If you deploy through Datto RMM:
- Verify the Endpoint Security policy has the correct targets.
- What to check: Confirm the devices are included as Targets within the Datto RMM Endpoint Security policy, and that the policy is enabled at the device level.
- Why it matters: Only one Endpoint Security policy can be active on a device at a time. If a second policy is applied, it is forced off and cannot be turned on until the original policy is removed or disabled.
Reference: Datto Endpoint Security Integration (Datto EDR integration in Datto RMM.)
Reference: Policies (Datto RMM policies — Endpoint Security policy and targets.)
- Verify the Datto RMM agent is running and the device is approved.
- What to check: Confirm each of the following on the target device:
- The Datto RMM agent shows as online.
- The "Datto RMM service" is running.
- The device does not have a pending device approval in Datto RMM.
Why it matters: If the Datto RMM agent is offline or its service is stopped, Datto EDR will not install through the Endpoint Security policy. Likewise, if the device still requires approval, the policy is never sent to the device and deployment does not occur.
Reference: Restarting the Datto RMM Agent
Reference: Device approval (in Datto RMM)
- What to check: Confirm each of the following on the target device:
- Verify the Endpoint Security policy has the correct targets.
- Confirm the devices are online.
- What to check: Verify the target devices are powered on and connected to the network.
- Why it matters: An offline device cannot receive the agent. This applies to integrated and stand-alone deployments alike.
- Confirm the operating system (OS) is supported.
- What to check: Compare the device OS and version against the published hardware and OS requirements.
- Why it matters: The Datto EDR agent may install on an unsupported OS, but its behavior cannot be guaranteed. In other cases, an older OS does not include the modules required to install the agent, and installation fails.
Reference: Hardware and operating system requirements
- Confirm required Windows components are installed.
- What to check: On Windows devices, verify the following are present and current:
- Azure Code Signing support
- The Microsoft Visual C++ redistributable
- All available Windows updates
- Why it matters: Missing Azure Code Signing support, a missing Visual C++ redistributable, or an incompletely updated Windows installation can each prevent Datto AV from deploying.
Reference: Hardware and operating system requirements
- What to check: On Windows devices, verify the following are present and current:
- macOS: confirm Full Disk Access is granted.
- What to check: On macOS devices, confirm that Full Disk Access has been granted to the Datto AV agent.
- Why it matters: Full Disk Access is required for the Datto AV agent to deploy and operate on macOS.
Reference: Datto AV for Mac
- For local installs, confirm the install runs as an administrator.
- What to check: If you are installing Datto EDR manually on a Windows device, confirm the install is performed by a service-level account or an administrator.
- Why it matters: A manual installation started by a standard user account does not have the privileges required to complete.
Reference: Deploying the Datto Endpoint Security agent
- Confirm licenses are available and assigned.
- What to check: Review your license allotment and confirm a license is assigned to each device.
- Why it matters: Devices need an assigned license to enable full functionality. The base agent will deploy and policies will be assigned to it, but if the license allotment has been exceeded, the policy will not assign a license — which can look like a failed or partial deployment.
Reference: License management
- Check for Deep Packet Inspection or SSL inspection on the firewall.
- What to check: Confirm whether Deep Packet Inspection (DPI) or SSL inspection is enabled on the firewall covering the target devices.
- Why it matters: DPI and SSL inspection can prevent the Datto EDR application from deploying. Datto EDR traffic must be excluded from inspection for deployment to complete.
- Check for a conflicting security product.
- What to check: Identify any other EDR or antivirus product installed on the device. Where one is present, either allowlist Datto EDR in that product or remove the product entirely.
- Why it matters: Datto EDR is designed to run alongside an antivirus product, but multiple EDR or antivirus solutions can cause unexpected issues. A conflicting product may block installation or interfere with operation afterward.
Reference: Endpoint allowlisting and antivirus considerations for the Endpoint Security agent
- Check for leftover artifacts from a previous EDR installation.
- What to check: On devices that previously had Datto EDR installed, confirm that no files, folders, services, or registry keys from the earlier installation remain.
- Why it matters: A normal uninstall removes these components, but some situations leave files or registry keys behind. Remaining remnants can block a new installation. Remove them before attempting to deploy the agent again.
Reference: Uninstalling the Datto Endpoint Security agent
- Report incomplete uninstalls to Datto Support.
Capture the remnants before you clear them. Once the files and registry keys are deleted, the evidence of what the uninstall missed is gone, and the case becomes much harder to diagnose. A screenshot or a copied list of the paths is enough.
Clearing the remnants will usually let the new agent install, but it treats the symptom rather than the cause. Because a normal uninstall is expected to remove everything, remnants indicate that something interrupted or blocked the removal — and that condition may still be present on the device or repeat across your fleet. Open a case with Datto Support even if the reinstall afterward succeeds.
Information to provide when reporting an incomplete uninstall:- Device name, operating system, and OS version.
- The version of the Datto EDR agent that was previously installed, if known.
- How the uninstall was performed: locally on the device, from the Datto EDR portal, or as part of an upgrade or reinstall.
- The full paths of every file, folder, service, and registry key left behind, captured before you remove them.
- Any error message or operating system error number displayed during the uninstall.
- The agent log files from the device, which record what the uninstall attempted and where it stopped.
- Whether the device was restarted between the uninstall and the reinstall attempt.
- Whether the reinstall failed outright, or installed but did not check in or function correctly.
- Whether any other security product was installed or active on the device at the time of the uninstall.
- How many devices show the same behavior, and whether they share an operating system, image, or deployment method.
Reference: Accessing agent log files
- Collect the agent log files.
- What to check: Locate and collect the agent log files from the affected device, and note any operating system error numbers recorded during the installation attempt.
- Why it matters: Failures encountered during installation are recorded in the log files and often point to a specific cause. Datto Support will need these logs to investigate, so gathering them before you open a case shortens the time to resolution.
Reference: Accessing agent log files When you open a case, have this ready:
- The affected device names and their operating system versions.
- Whether the deployment is through the Datto RMM integration or stand-alone.
- The agent log files from at least one affected device, and any error numbers they contain.
- A list of the checklist items above that you have already confirmed.
| Revision | Date |
|---|---|
| Initial release. | 8/12/26 |