Isolating a device and reverting isolation

Host isolation cuts a device off from the network so a threat cannot spread, communicate with an attacker, or move laterally to other endpoints. The Datto EDR agent stays connected to the EDR cloud throughout isolation, so the device keeps checking in, keeps reporting telemetry, and can still receive further response actions — including the command to come back online. Isolation is fully reversible.

Key capabilities

  • Three isolation methods. Isolate a device directly from an alert, from the Device Details page, or automatically through a Ransomware or Automated Response policy.
  • Bulk isolation and revert. Select multiple devices from the Devices list and isolate or revert them in a single action.
  • Continuous telemetry during isolation. The Datto EDR agent maintains its cloud connection while the device is isolated, so investigation and further response actions continue uninterrupted.
  • Automatic isolation by policy. Automated Response and Ransomware policies can isolate a device the moment a qualifying alert fires, with no analyst involvement.
  • Cross-product isolation awareness. Built-in indicators identify whether Datto EDR, Datto RMM, or RocketCyber applied the isolation, preventing incorrect revert attempts.

How it works

When you isolate a device, Datto EDR instructs the agent to apply network restrictions on its next check-in. If the device is offline, the action is queued and applies when the device reconnects. The agent enforces a short allowlist of addresses, primarily the EDR cloud, so management and telemetry continue while all other network traffic is blocked. To release the device, you revert isolation from the same product that applied it. Reverting from a different product does not remove the original restrictions.

Before you begin

  • Your organization must have an active Datto EDR license.
  • Your role must be Admin or Analyst. External Analyst users cannot access the Respond section.
  • The Host Isolation and Host Isolation Restore response extensions must be present and active in Admin > Extensions.

How to...

Isolate a device from an alert

Use this method when you are actively working an alert and want to contain the affected host without leaving the alert detail page.

Isolate a device from the Device details page

Use this method when you know which device you want to contain and do not need to work through an alert. This method also supports isolating multiple devices at once.

Configure automatic isolation by policy

Datto EDR can isolate a device automatically, with no analyst action, when a qualifying alert fires. This is the fastest form of containment and is the recommended configuration for ransomware scenarios.

Determine which solution isolated a device

Three Kaseya products can isolate an endpoint: Datto EDR, Datto RMM, and RocketCyber. Always revert isolation from the same product that applied it. A device isolated by Datto RMM cannot be released from Datto EDR, and vice versa.

NOTE  Using the wrong product to revert isolation does not release the device. The product that attempted the revert reports success, while the original product's restrictions remain in force. The device stays offline and the real cause is obscured behind a misleading "successful" revert. Identify the source first, then revert.

Revert isolation

Reverting isolation restores the device's normal network access. Within Datto EDR, the same control reverts both manual and automatic (policy-driven) isolations.

NOTE  Before you revert, confirm that Datto EDR is the product that isolated the device. See "Determining which solution isolated a device" above.

Before you begin

  • Your role must be Admin or Analyst.
  • Confirm that Datto EDR applied the isolation. Reverting in Datto EDR has no effect if another product holds the isolation.
  • The Host Isolation Restore extension must be present and active in Admin > Extensions.

Troubleshooting

Symptom What to do
Reverted isolation, but the device is still cut off. Another product is holding the isolation. Work through "Determining which solution isolated a device" above. In most cases, Datto RMM applied the isolation, and the device shows Needs Attention rather than Isolated in the RMM console.
Error: "the agent is already in isolated state" (or "restored state"). The device is already in the state you requested. Refresh the page to see the current status. If you are acting in bulk, deselect the devices named in the error prompt and retry.
Nothing happens after confirming isolation or revert. Isolation and revert are delivered on the agent's next check-in. If the device is offline the action stays queued. Check the Status column in the Devices list.
Isolate or Revert Isolation is not visible. External Analyst users cannot isolate from the Device details page. Confirm your role and confirm that the organization has an active Datto EDR license.
A device keeps getting re-isolated. An automated response or ransomware policy is still matching the underlying condition. Review the policy assigned to the device and the alert that triggered it. Address the root detection rather than repeatedly reverting isolation.
Respond is unavailable (greyed out) on an alert. The Respond action is unavailable for compliance-sourced alerts and requires an active Datto EDR license. Confirm the alert type and license status.

 

Revision Date

Initial release.

8/25/26