Issue ID: AV-09
Applies to: Datto AV, Windows Defender
Environment: Windows only (Windows Defender is Windows-specific)
KB type: Best practice
Overview
Running more than one antivirus solution on the same device is not recommended. Assigning both Datto AV and Microsoft Defender antivirus policies to the same endpoint can create conflicts, performance issues, false positives, and increased troubleshooting complexity.
While Datto EDR can manage both Datto AV and Microsoft Defender, administrators should ensure that a device group receives either a Datto AV policy or a Defender policy, not both.
Why Overlapping Antivirus Policies Are Not Recommended
Applying multiple antivirus solutions to the same endpoint can result in:
- Conflicts between antivirus engines.
- Increased CPU, memory, and disk utilization.
- Duplicate scanning of files and processes.
- False-positive detections.
- Reduced operational effectiveness.
- More complex troubleshooting and support scenarios.
Recommended Practice Steps
Datto AV policies and Microsoft Defender policies can coexist within the same Datto EDR tenant. However, they should be assigned to separate device groups.
Recommended practices:
- Decide which antivirus solution will protect each group of devices.
- Create separate device groups for Datto AV-managed devices and Defender-managed devices.
- Assign only one antivirus policy type to each device group.
- Review policy assignments regularly to prevent accidental overlap.
- Verify onboarding workflows place devices into the appropriate device group before antivirus policies are applied.
Important: Do not assign both a Datto AV policy and a Microsoft Defender policy to the same device group. |
Using Device Groups to Prevent Antivirus Policy Overlap
Device Groups can be used to segregate endpoints based on the antivirus solution that will manage them.
Example:
| Device Group | Assigned Policy |
| Workstations - Datto AV | Datto AV Policy |
| Workstations - Defender | Defender Policy |
| Servers - Datto AV | Datto AV Policy |
| Servers - Defender | Defender Policy |
A device can belong to only one Device Group within a Datto EDR tenant. Because of this, preventing overlap is primarily accomplished through correct policy assignment to the device group.
Assigning Antivirus Policies
- Navigate to the Device Group that will receive antivirus protection.
- Review all policies currently assigned to the group.
- Determine whether the group will use Datto AV or Microsoft Defender.
- Assign the appropriate antivirus policy.
- Confirm that a policy for the other antivirus solution is not assigned to the same device group.
- Save the configuration and allow policy synchronization to complete.
Validating Policy Assignments
After assigning antivirus policies:
- Open the Device Group configuration.
- Review all assigned policies.
- Confirm that only one antivirus policy type is assigned:
- Datto AV or
- Microsoft Defender
- Select a device within the group.
- Review the device's effective policy configuration.
- Confirm the device is receiving the intended antivirus policy.
Troubleshooting
A device appears to have both Datto AV and Defender policies
- Identify the device's assigned Device Group.
- Review antivirus policies assigned to the Device Group.
- Review antivirus policies assigned at the Location level.
- Review antivirus policies assigned at the Organization level.
- Identify whether both a Datto AV policy and a Defender policy are being applied.
- Remove the unintended antivirus policy assignment.
- Verify that the device receives only the intended antivirus policy.
New devices are receiving the wrong antivirus policy
- Verify the Device Group used during onboarding.
- Review antivirus policies assigned to that Device Group.
- Review Organization-level and Location-level assignments.
- Update assignments as required.
- Confirm newly onboarded devices receive the correct antivirus policy.
Performance issues after antivirus deployment
- Confirm which antivirus policy is assigned to the device.
- Verify that both Datto AV and Defender antivirus policies are not being applied simultaneously.
- Review recent policy changes.
- Collect logs and device details if the issue persists.
Escalation Guidance
Escalate to Kaseya Support if:
- Policy inheritance behavior is unclear.
- A device continues receiving multiple antivirus policies after assignments are corrected.
- Devices receive unexpected antivirus policies during onboarding.
- Policy assignment behavior does not match the expected Device Group, Location, or Organization configuration.
When escalating, provide:
- Description of the observed behavior
- Name of affected device(s)
- Intended Device Group name
- Assigned policies
- Screenshots of policy assignments