Handling Datto AV False Positives and Releasing Safe Files

Issue ID: AV-03

Applies to: Datto AV

Environment: Windows, macOS

KB Type: Troubleshooting


Overview

Use this article when Datto AV flags, quarantines, or blocks a file that has been verified as legitimate. The objective is to restore access to the file, prevent repeat detections, and submit the file for review so future false positives can be evaluated by Datto AV security engineers.


Symptoms

  • A legitimate file is quarantined or blocked by Datto AV.
  • The same trusted file is repeatedly detected.
  • Users cannot access a business-critical file.
  • Multiple devices report detections for the same trusted file.

Cause

False positives can occur when antivirus signatures, heuristics, or behavioral detections identify a legitimate file as malicious.


Resolution Steps

Identify the detection:

  1. Locate the detection in the Datto EDR portal.
  2. Record the file name, path, hash (if available), detection name, and device name.
  3. Confirm with the customer that the file is legitimate and expected in the environment.

 

Restore the quarantined file:

  1. Sign in to the Datto EDR portal.
  2. Navigate to Respond.
  3. Select Quarantined Files in the left navigation pane.
  4. Select the alert(s) using the check boxes to the left.
  5. Click Restore Files.
  6. Confirm that the file is restored successfully.]

Important: Restoring a file from quarantine automatically creates a durable exclusion for that file on that device. If the file is used across multiple devices, consider a policy-level or Universal AV Exclusion.

 

Verify file availability:

  1. Confirm the file has been restored to its original location.
  2. Open or access the file from the endpoint.
  3. Verify normal operation.

 

Prevent future detections:

  1. Determine whether additional file, folder, or process exclusions are required.
  2. Use Universal AV Exclusions when the exclusion should apply broadly.
  3. Use wildcard exclusions carefully and only when necessary.

 

Submit the file as a false positive:

  1. Navigate to Policies > Datto AV File Submission.
  2. Create a submission and upload the affected file.
  3. If the file has already been detected as malicious, submit it as a password-protected ZIP using the password infected.
  4. Submit the request for review.

Troubleshooting

File is detected again after restoration:

  1. Restart the Datto EDR Agent or reboot the device.
  2. Confirm the file remains present after restart.
  3. Review the new detection details.
  4. Determine whether the file name, path, or hash changed.
  5. If used on multiple devices, create a policy-level or Universal AV Exclusion.
  6. Review existing exclusions for correct scope.
  7. Escalate to Datto Support if the same file continues to be detected.

 

Exclusions are not persisting:

  1. Validate the exclusion type.
  2. Verify the exclusion value and formatting.
  3. Confirm Universal AV Exclusion is enabled when required.
  4. Save the policy and verify synchronization.

 

File cannot be restored:

  1. Verify the quarantined item is visible in Respond > Quarantined Files.
  2. Verify that the original destination folder still exists on the endpoint.
  3. Confirm the associated Datto AV policy is still active.
  4. Check for restoration errors.
  5. Attempt the restore operation again.
  6. Escalate to Datto Support if restoration continues to fail.

Tips and Considerations

  • Finance-related PDFs are a recurring false-positive pattern, particularly after signature updates.
  • Submit recurring false-positive files through Datto AV File Submission.
  • Use the most specific exclusion possible to minimize security impact.
  • A local exclusion resolves the issue in the local environment, while file submission helps improve detections for all customers.

Related Articles

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section