Upcoming Datto AV VDF update — September 30, 2026
What's happening
As part of a regular maintenance cycle (occurring roughly twice a year), Datto AV will perform a signature database reorganization on September 30, 2026. This is a larger-than-usual Virus Definition File (VDF) update, with an expected download size of up to 130 MB, compared to the typical few-KB/MB daily updates.
What this means for you
- This is a maintenance change, not a new detection ruleset. Existing detection rules are being consolidated and optimized for storage.
- The update is delivered automatically through the standard VDF update mechanism. No configuration changes are required.
- Standard, smaller VDF updates will resume immediately afterward.
Should you expect false positives?
Datto AV does not anticipate a broad increase in false positives from this update. However, as with any signature update, Datto AV cannot guarantee zero false positives. For customers who want to take extra precautions during the update window, consider the following:
Enabling alert only mode (real-time protection off, Quick/Full scans only)
Enable alert only mode during the update window while signatures are new, so you can review activity before enforcing.
IMPORTANT In alert only mode, real-time protection will not automatically quarantine or inspect files as they load into memory. Detections are still raised as alerts in the console, and files can be quarantined manually from there via alert response actions.
- As general guidance, if full scans complete for a few days after the update with no unexpected alerts, it is reasonable to return to normal protection settings. Full scans provide the most complete coverage for this purpose, since quick scans check only a subset of the file system. If you prefer a more conservative approach, running Alert Only mode through a full week of scheduled full scans can provide additional confidence before re-enabling full enforcement.
-
For more information on setting up Datto AV alert only mode, refer to Configuring Datto AV alert only mode.
Submitting unexpected detections for review
Be prepared to submit unexpected detections through the Datto AV false positive submission process so they can be reviewed and adjusted as needed. For more information, see Datto AV File Submission .
FAQ
No. This update is delivered through the standard mechanism and applies to all agents automatically.
No. Agents will attempt to download the VDF update automatically. Confirm the required Datto AV allowlisting URLs are permitted per the allowlist documentation: Endpoint firewall and networking requirements for the Endpoint Security agent.
No performance or protection-level impact is expected. This is a storage and organization change to the signature containers, not new detection content.
Because rules are being moved and consolidated between containers, agents need to download a refreshed, complete signature base rather than an incremental patch. This is a one-time effect of the reorganization. Normal small updates resume right after.
Submit the file through the Datto AV false positive submission process. The team will review and respond, and you can add a temporary exclusion in the meantime if needed to avoid disruption.
Approximately twice a year, as part of routine signature database maintenance.
Yes, this is expected periodically (semi-annually) as part of routine signature database maintenance. Datto will announce future occurrences in advance.