Datto AV Is Corrupted or Partially Installed While Datto EDR Is Running

Issue ID: AV-02
Applies to: Datto AV, Datto EDR
Environment: Windows, macOS
KB type: Troubleshooting


Overview

This article addresses scenarios where Datto EDR is running and reporting normally on an endpoint, but the Datto AV component is not running, appears missing, or is not enforcing protection—indicating a corrupted or partial install state.


Symptoms

  • Datto EDR shows active/healthy status for the endpoint.
  • Datto AV shows not running, missing, or inconsistent status for the same endpoint.
  • No scan activity or signature updates are occurring for Datto AV on that endpoint.

For guidance on interpreting agent status, see Datto EDR & AV Online Help - Agent Status.


Cause

A partial or corrupted install can result from:

  • Interrupted installation or update of the AV component (while EDR updates successfully)
  • File or registry corruption limited to the AV component
  • Corrupted components leftover from improper uninstall

Troubleshooting steps

General troubleshooting

  1. Confirm agent status
    • Review the endpoint in the Datto EDR portal to verify Datto EDR is healthy and Datto AV is Active, Not installed, N/A
    • Reference: Agent Status Documentation
  2. Verify Datto AV services and processes
    • On the endpoint, check for the following services:
      • Endpoint Protection Service
      • Endpoint Protection Secondary Service
    • Confirm if these services are present and running.
  3. Check Datto AV files
    • Verify that core Datto AV files are present on the device.
  4. Collect device logs
    • If available, collect device logs for further analysis.

Resolution

If Datto AV is not running or missing while EDR is healthy, a Datto AV reinstall is typically required unless a documented component repair procedure exists.

To uninstall Datto AV:

  1. Locate the device at the location level in the Datto EDR portal.
  2. Use the ellipses menu and select "Unassign license."
  3. Select only the Datto AV license.
  4. Wait up to 15 minutes for the automated uninstall to be completed.

If reinstalling Datto AV is required, reassign the Datto AV license or follow the documented agent installation procedure: Datto EDR & AV Online Help - Install Agent


Escalation

If the inconsistent state persists after uninstall/reinstall:

  • Provide before/after status details.
  • Include the endpoint's update history.
  • Attach device logs if available.

Tips

  • Mismatched update dates between EDR and AV components are useful evidence for engineering review.
  • Always confirm service/process presence and file integrity before proceeding to uninstall/reinstall.

Related Articles

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section