Datto EDR Quarantine or Remediation Action Fails to Execute

Issue ID: EDR-05

Applies to: Datto EDR

Environment: Windows, macOS

KB type: Troubleshooting


Overview

This article applies when a Datto EDR quarantine or remediation action is triggered (manually or by policy) but does not appear to execute — the threat remains present, or no confirmation of the action is shown.


Symptoms

  • An alert exists but the associated quarantine/remediation action shows as failed, pending, or has no visible outcome.
  • The flagged file/process is still present on the endpoint after a remediation action was initiated.
  • No error message is shown to explain why the action did not complete.

Cause

A remediation action can fail for the following confirmed reasons in Datto EDR:

  • The endpoint was offline at the time the action was issued.
  • The action targets an invalid file path.
  • The file has already been moved or deleted.

NOTE

These are the only confirmed causes for remediation failure in Datto EDR. Other causes (such as file locked/in use or insufficient permissions) are not supported.


Troubleshooting Prerequisites


Troubleshooting Steps

To resolve this issue, complete the following steps:

  1. Retrieve the alert ID/URL associated with the failed action.
  2. Record the exact action that was attempted (quarantine, kill process, delete, isolate) and when.
  3. Confirm the endpoint was online and checking in at the time the action was issued.
  4. Check if the target file/process still exists on the endpoint.
  5. Review the EDR Agent logs for any indication of failure.
    • There is no published remediation log or error code format; review logs for context around the failed action.
  6. Attempt to re-trigger the action once the endpoint is confirmed online, and record the result.
    • Actions can be retried once. If the retry fails, proceed to escalation.

IMPORTANT

Remediation actions must be re-issued manually when the device is online.


Tips

  • Distinguish “no action was ever taken” (policy/detection issue) from “action was taken but did not remove the threat” (execution issue) early in triage, as escalation paths differ.

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section