Offboarding/debooking devices from Datto EDR
NAVIGATION Datto EDR Portal > Organization Management
PERMISSIONS Outgoing MSP partner administrator with access to the client's Datto EDR organization, and RMM administrator access (Datto RMM or Kaseya VSA).
This guide covers how to safely remove Datto EDR agents from client devices during an MSP transition. It is intended for the outgoing MSP, the partner whose Datto EDR organization the devices currently belong to. It addresses two common scenarios: a client leaving for a different MSP, and a new MSP acquiring a client. Steps cover the Datto EDR portal as well as RMM platforms (Datto RMM and Kaseya VSA).
BEFORE YOU BEGIN Read the Before you begin: when not to uninstall section below before proceeding. Do not uninstall the agent if a threat is suspected, if devices are isolated, or if quarantined files still need to be retrieved.
Who this guide is for
This guide applies to the following MSP transition scenarios:
- Outgoing MSP: A client is leaving your organization for a different MSP, and you need to cleanly offboard their devices from your Datto EDR organization.
- Incoming MSP: You are acquiring a client from another MSP. In this case, you cannot remove the previous MSP's agents yourself — those agents are enrolled in the previous MSP's EDR organization, and uninstall protection and tamper protection and the portal uninstall are only available to them. Share this guide with the outgoing MSP and coordinate the handoff. Your role is to verify removal and then deploy your own tooling.
Note that the incoming MSP may not use the same RMM tools as the outgoing MSP. Coordinate between both parties so deployment automation from one side does not conflict with removal from the other.
Before you begin: when not to uninstall
Uninstalling the agent is not a remediation step. Do not uninstall the agent if:
- You think it will release files from quarantine. It will not, and quarantined files are deleted at uninstall (see warning below).
- You think it will revert host isolation. Resolve isolation from the EDR portal first, as uninstalling an isolated host can leave it in an unexpected network state.
- You think it will stop a problem permanently. If a device is generating alerts or you suspect an active threat, investigate and remediate before offboarding. Uninstalling only removes visibility, not the threat.
ALERT Uninstall is destructive and cannot be undone. Uninstalling the agent permanently deletes the agent's local log files and all quarantined files on the device. These cannot be recovered after uninstall. Before offboarding, restore or securely retrieve any quarantined files that are still needed, resolve any host isolation, and export any logs required for compliance or handoff to the incoming MSP.
Offboard devices from the Datto EDR portal
To offboard devices from the Datto EDR portal, perform the following steps in order for the organization being offboarded:
- Disable uninstall protection for the organization so agents can be removed without blocking. In the EDR portal, disable uninstall protection at the organization level for the client being offboarded.
- Disable tamper protection in the EDR policy applied to the organization's devices. This prevents the agent from resisting removal or self-repairing during the offboarding window.
- Disable the method used to deploy the agent: the Datto RMM Endpoint Security policy, a GPO, or a deployment script. If this step is skipped, automation will reinstall the agent after you remove it.
- Uninstall the agent from the EDR portal. Once protection and deployment automation are off, issue the uninstall from the EDR portal for the organization's devices.
- Confirm that all devices report as uninstalled before considering the offboarding complete.
When complete, all targeted devices will no longer appear as active endpoints in your Datto EDR organization.
Remove Datto EDR deployment from Datto RMM
To prevent Datto RMM from redeploying or repairing the EDR agent after removal, complete the following steps:
- Remove the devices (or site) from any endpoint security policy so Datto RMM stops deploying or repairing the EDR agent.
- Disable or unassign any monitoring policies or components for the departing organization that monitor the health of or restart the EDR agent.
- After the EDR uninstall completes, remove or decommission the Datto RMM agent itself if the client is leaving your management entirely.
The client's devices will no longer be managed by your Datto RMM organization after decommissioning.
Remove Datto EDR deployment from Kaseya VSA
To prevent Kaseya VSA from redeploying the EDR agent after removal, complete the following steps:
- Disable any agent procedures, policies, or scheduled tasks that deploy or redeploy the EDR agent to the affected machine groups.
- Remove the devices from any views or machine groups targeted by EDR deployment automation.
- After the EDR uninstall completes, uninstall the VSA agent if the client is leaving your management entirely.
The client's devices will no longer be targeted by EDR automation in your Kaseya VSA environment.
Responsibilities of the incoming MSP
Regardless of tooling, the outgoing MSP is always responsible for the removal itself: disabling protection, disabling their deployment automation, and uninstalling from the EDR portal. The incoming MSP cannot perform these steps because the agents belong to the outgoing MSP's EDR organization.
The incoming MSP should verify that old agents are fully removed (for example, via Windows Apps & Features or their own tooling) before deploying their security stack. Only one installation of the Datto EDR/AV agent can exist on an endpoint at a time.
Handoff checklist
Before completing the offboarding, confirm that all of the following are true:
- You have restored or securely retrieved all quarantined files the client needs.
- No devices remain isolated.
- You have resolved or documented all open alerts and incidents for the incoming MSP.
- You have disabled uninstall protection and tamper protection, and disabled the deployment method (Datto RMM Endpoint Security policy, GPO, or script).
- You have issued the uninstall from the EDR portal and confirmed it on all devices.
Once all checklist items are complete, the offboarding is finished and the incoming MSP can proceed with deploying their own security tooling.
FAQ
No. The agent permanently deletes quarantined files when it uninstalls.
Before initiating any uninstall, restore or securely retrieve any quarantined files that the client still needs. Once the uninstall runs, those files cannot be recovered.
No. Only the outgoing MSP can uninstall agents enrolled in their EDR organization.
Uninstall protection and the portal uninstall are only available to the MSP that owns the EDR organization the agents are enrolled in. The incoming MSP should share this guide with the outgoing MSP, coordinate the handoff, and verify removal before deploying their own tooling.
Deployment automation was still active when the agent was removed.
If deployment automation is still active when the agent is uninstalled, it will reinstall the agent automatically. Ensure the Datto RMM Endpoint Security policy, GPO, or any deployment scripts are disabled or removed for the affected devices before issuing the uninstall from the EDR portal.
| Revision | Date |
|---|---|
|
Initial release |
8/7/26 |