Issue ID: AV-11
Applies to: Datto AV
Environment: macOS only
KB type: Troubleshooting
Symptoms
- Datto AV status shows “Not Running” on a macOS endpoint.
- No clear error is shown to explain why the product is not running.
Resolution Steps
To resolve this issue, complete the following steps:
- Verify the endpoint is running a supported version of macOS and confirm whether it uses Apple Silicon or Intel hardware. Refer to Hardware and operating system requirements.
- Confirm the Datto EDR agent has Full Disk Access enabled in System Settings (or System Preferences on older macOS versions).
- If the endpoint is managed by an MDM solution, verify the MDM profile has been successfully applied and grants the required Full Disk Access permissions and System Extension approval.
- If the required permissions or system extension are not approved, approve them manually or deploy the correct MDM profile. Restart the endpoint after applying the changes.
- If the permissions are correct but Datto AV is still not running, reboot the endpoint.
- If the issue persists, reinstall the Datto EDR agent. Collect the Datto EDR and Datto AV agent logs. Refer to Accessing agent log files
- If the issue persists after confirming requirements, permissions, system extension approval, and reinstalling the agent, escalate the case with the following information:
- macOS version
- Hardware architecture (Apple Silicon or Intel)
- Full Disk Access status
- System Extension approval status
- Datto EDR and Datto AV logs
IMPORTANT: Unassigning a Datto AV license triggers a Datto AV uninstall. This process may remove information needed for troubleshooting. Collect all Datto AV logs from the device before unassigning the license.
IMPORTANT: Removing an antivirus product can temporarily leave an endpoint unprotected. Plan antivirus removal and Datto AV installation as a single maintenance activity whenever possible.
Tips and Tricks
Apple periodically changes system-extension and privacy-permission requirements with major macOS releases — if this started after a macOS upgrade rather than after installing/updating Datto AV, treat the OS upgrade as the likely trigger and check for a required permission re-approval first.