Issue ID: EDR-01
Applies to: Datto EDR
Environment: Windows, macOS
KB type: Troubleshooting
Overview
This article provides step-by-step guidance for resolving issues where a Datto EDR agent's status displays as Stale or Inactive in the Datto EDR console, even though the endpoint appears to be powered on and connected to a network.
Symptoms
- Endpoint shows as “Stale” or “Inactive” in the Datto EDR console.
- The agent has not checked in for an extended period, even though the device is online.
Cause
Loss of communication between the Datto EDR agent and the Datto EDR cloud backend is typically caused by one or more of the following:
- A firewall, proxy, or network security appliance blocking required outbound URLs or ports.
- The local agent service is not running.
- Corruption of the agent installation.
For the official list of required URLs and ports, refer to Endpoint firewall and networking requirements for the Endpoint Security agent.
Resolution Steps
Follow these steps to diagnose and resolve the issue:
1. Confirm agent status and device details
- In the Datto EDR console, identify the affected endpoint(s) and note the exact status (Stale, Inactive).
- Record the hostname and the “Last Seen” or “Last Check-In” time for the endpoint.
2. Verify device connectivity
- Ensure the endpoint is powered on and connected to the network.
- Confirm the device has outbound internet access.
3. Check agent service status
- On the endpoint, verify that the Datto EDR agent service is running:
- Windows/macOS: Service name is HUNTAgent
- Linux: Service name is HUNTAgent.service
- For more details, see Deploying the Datto Endpoint Security agent and Datto RMM Agent > Agent modules > Datto EDR module.
4. Confirm network requirements
- Ensure the endpoint can reach all required Datto EDR cloud endpoints and ports.
- Reference the full allowlist at Endpoint firewall and networking requirements for the Endpoint Security agent.
- If a firewall, proxy, VPN, or other network security control was recently added or changed, review and update rules as needed.
5. Attempt agent repair
- If the agent service is running and network requirements are met but the status does not update:
- For Windows endpoints, run the Datto EDR Maintenance Component [WIN] from the Datto RMM
- Local uninstallation is not recommended. See Datto EDR: Local agent uninstallation is not recommended
6. Monitor agent status
- After performing the above steps, allow time for the agent to check in and the status to update.
- The agent sends telemetry every 2 minutes typically.
- The dashboard typically refreshes every hour or four hours, and the “Last Check-In” time indicates the most recent update. See Getting started with the Dashboard page.
- If the status resolves, document which step corrected the issue and monitor for recurrence.
7. If unresolved, contact Kaseya Support
- If the agent remains stale or inactive after completing all steps above, please contact Kaseya Support.
- Please provide the following for Kaseya Support:
- Endpoint hostname
- Status observed
- Last Check-In time
- Steps already completed
- Any recent network or security changes
- Datto EDR agent logs, reference Accessing agent log files
- Please provide the following for Kaseya Support:
Notes
- Agent status changes are not always instantaneous after a network fix. Confirm the endpoint has checked in again before concluding the issue persists.
- When triaging, distinguish between endpoints that have never checked in (likely deployment or connectivity issues) and those that were checking in, then stopped (often due to network changes, firewall updates, or agent issues).
Related Articles
- Endpoint firewall and networking requirements for the Endpoint Security agent
- Deploying the Datto Endpoint Security agent
- Datto RMM Agent > Agent modules > Datto EDR module
- Datto EDR: Local agent uninstallation is not recommended
- Getting started with the Dashboard page