Endpoint allowlisting and antivirus considerations for the Endpoint Security agent
SECURITY Service account or administrator-level rights on the target endpoint
To enable real-time security scanning, Datto EDR has several binaries that you'll need to allowlist for execution in the security tools on your target endpoints. You can implement the exclusions by hash or by file and path.
This article describes the files you'll need to add to your exception policies. To learn about networking requirements for the Endpoint Security agent, refer to Endpoint firewall and networking requirements for the Endpoint Security agent.
Installation and agent executables
Add the following paths to your security allowlists.
NOTE For customers utilizing Datto RMM and Datto EDR, you will need to allowlist both agent paths listed in this table as Datto RMM now deploys EDR its in traditional directory. For more informationabout this change refer to the RMM 13.9 release notes.
Platform | Path |
Windows |
%SystemDrive%\Program Files\Infocyte\Agent\agent.exe Datto RMM customers: %SystemDrive%\ProgramData\CentraStage\AEMAgent\RMM.AdvancedThreatDetection\agent.exe |
Linux |
Opt/infocyte/agent/agent.exe Datto RMM customers: |
macOS |
/usr/local/infocyte/agent/agent.exe Datto RMM customers: |
RMM |
%SystemDrive%\ProgramData\CentraStage\AEMAgent\ RMM.AdvancedThreatDetection\agent.exe AND %SystemDrive%\Program Files\Infocyte\Agent\agent.exe |
NOTE You can allowlist the executables by hash if your antivirus solution supports doing so. You can find a list of hashes in your EDR instance at > Organizations > select an organization > select a location >
> Download Agent.
Agent application folder
NOTE For customers utilizing Datto RMM and Datto EDR, you will need to allowlist both agent paths listed in this table as Datto RMM now deploys EDR its in traditional directory. For more information about this change refer to the RMM 13.9 release notes.
While rare, you may find that you need to allowlist the agent application folder in your antivirus solution. You can allowlist the following directories or use the hashes found under the download section to specify the specific files.
Platform | Path |
Windows |
%SystemDrive%\Program Files\Infocyte\Agent Datto RMM customers: %SystemDrive%\ProgramData\CentraStage\AEMAgent\RMM.AdvancedThreatDetection\ |
Linux |
/opt/infocyte/agent Datto RMM customers: |
macOS |
/usr/local/infocyte/agent Datto RMM customers: |
Revision | Date |
---|---|
Updated platform paths. | 7/8/25 |