Uninstalling the Datto Endpoint Security agent

PERMISSIONS   Datto EDR subscription with administrator-level platform access or Datto AV subscription with administrator-level platform access

PERMISSIONS   Service account or administrator-level rights on the target endpoint

IMPORTANT  Uninstalling the Endpoint Security Agent is not a recommended troubleshooting step, as it can complicate the support process and require additional effort to restore full functionality.

IMPORTANT  RMM integrations: Offboarding an agent integrated via RMM requires steps in both Datto RMM and the Datto EDR portal. For complete uninstall instructions, see the section "Offboard a client" in the RMM Help article Integration: Datto RMM and Datto EDR.

This article describes the methods for uninstalling the Endpoint Security agent from an endpoint.

Uninstalling from the EDR platform

If you need to uninstall the EDR agent, it is highly recommended that you do so from within the EDR platform for the following reasons:

  • You will already be authenticated in the platform, and therefore, won't have to provide additional security information, like an uninstall token.
  • The agent will be removed from the Devices table.
  • The licenses assigned to the agent will released and made available to be assigned to another device.

Device Status

When uninstalling a device from the EDR platform, the Status of the device affects the uninstall process.

  • Online: The uninstall process completes in approximately 10 minutes.
  • Offline: A device that is Offline cannot check-in with the EDR platform. Therefore, the uninstall process will be queued on the EDR server until the device is back Online.

To uninstall an EDR agent from the EDR platform:

  1. Navigate to the Organizations page.
  2. In the navigation pane, click Devices. The Devices page is displayed with the Devices tab selected.
  1. To filter for specific devices:
    • Filtering options are available for each column. Options vary by column type and may include text search, checkboxes, or predefined lists. For example, you can filter devices by location to identify and delete all devices associated with a specific organization location.
    • Alternatively, you can click in the field above the table and select filtering options.
  2. To uninstall all devices at the same time:
    1. Select the check box in the column header row (to the left of Device).
    2. To the right of the Scan button, click the ellipses.
    3. Select Uninstall.
    4. In the confirmation modal, click OK.
    5. For each device, Pending Removal is indicated in the Status field and Unlicensed is displayed in the Licensed field.
  3. To uninstall a single device:
    1. At the end of the applicable device's row, click the ellipses.
    2. Select Uninstall.
    3. In the confirmation modal, click OK.

IMPORTANT  An offline device will be uninstalled if it is back online within six months of the start of the uninstall process. If the device checks in after the six month time frame, it will reappear on the Devices page and need to go through the uninstall process again.

IMPORTANT   If a device does not have network connectivity, it cannot be uninstalled regardless of the method used (EDR platform or locally).

NOTE  Performing the uninstall steps in this article should not leave any agent remnant files. If remnant files are present, submit a support ticket.

Revision Date

Added IMPORTANT note at top: Uninstalling the Endpoint Security Agent is not a recommended troubleshooting step.

4/9/25
Updated all uninstall manually PRs. Updated Devices table screens. 12/20/25
Added Note: Performing the uninstall steps in this article should not leave any agent remnant files. 6/22/26
Updated Device Status values. To uninstall an EDR agent from the EDR platform - Step 3: Added - You can filter devices by location to identify and delete all devices associated with a specific organization location. 8/21/26
Added Important: RMM integrations - Offboarding an agent integrated via RMM requires steps in both Datto RMM and the Datto EDR portal. 9/3/26