Issue ID: EDR-08
Applies to: Datto EDR
Environment: Windows, macOS
KB type: Troubleshooting
Overview
This article addresses two distinct issues in Datto EDR environments:
- Duplicate device entries in the Datto EDR console for a single endpoint.
- Multiple Datto EDR agent processes running simultaneously on the same endpoint.
These issues are unrelated and require separate troubleshooting workflows.
Symptoms
Duplicate Device Entries
- The same physical or virtual endpoint appears as two or more separate devices in the Datto EDR console.
- Multiple entries may display an Active status.
- The reported license or seat count is higher than the actual number of protected endpoints.
Multiple Agent Processes
More than one Datto EDR agent process is running on the endpoint.
- Windows
- Service:
HUNTAgent - Process:
agent.exe
- Service:
- macOS
- Launch daemon:
HUNTAgent.plist
- Launch daemon:
Overview
Duplicate Device Entries
- Can occur when an endpoint is cloned, reimaged, or deployed from a golden image with Datto EDR already installed.
- May also result from:
- Registry key duplication.
- MAC address reuse.
- Device renaming.
- Reinstalling the Datto EDR agent.
- On Windows, the Datto EDR portal identifies endpoints using a UUID stored in the following registry key:
HKLM\SOFTWARE\Datto\EDR
Multiple Agent Processes
- May occur following:
- A failed agent upgrade.
- Multiple Datto EDR agent installations.
- Tamper Protection preventing the agent from shutting down normally.
- Multiple agent processes are not correlated with duplicate device entries in the Datto EDR portal.
Troubleshooting Steps
Duplicate Device Entries in the Datto EDR Console
- Identify duplicate entries.
- Record the device ID, last check-in time, hostname, and IP address for each entry.
- Determine which entry is actively checking in to the Datto EDR portal.
- Remove stale entries.
- Confirm which device entry is active before removing any duplicates.
- Remove stale entries from the Datto EDR portal.
- If you are unsure which entry is active, or if removing an entry may impact endpoint protection or licensing, contact Kaseya Support.
- Prevent future duplicate entries.
- Before cloning or reimaging an endpoint, uninstall Datto EDR and Datto AV (if installed).
- Delete the following registry key:
HKLM\SOFTWARE\Datto\EDR
- Disable Tamper Protection, if enabled.
- Restart the endpoint after uninstalling the agent and deleting the registry key.
- Reinstall Datto EDR after the restart.
Multiple Datto EDR Agent Processes Running Simultaneously
Windows
- Open Task Manager and locate all Datto EDR agent processes (
agent.exe) and theHUNTAgentservice. - If more than three agent processes are running:
- Run the Datto EDR maintenance component.
- If the issue is not resolved, restart the endpoint.
- If Tamper Protection is enabled, disable it before troubleshooting, as it may prevent the agent from shutting down normally.
- If the issue persists after restarting the endpoint:
- Collect the Datto EDR agent logs.
- Contact Kaseya Support.
macOS
- Open Activity Monitor and locate the
HUNTAgent.plistlaunch daemon. - If multiple instances are present:
- Restart the endpoint.
- If the issue persists after restarting the endpoint:
- Collect the Datto EDR agent logs.
- Contact Kaseya Support.
Important Notes
- Duplicate device entries may temporarily increase the reported license or seat count until stale entries are removed.
- Before removing a device entry, confirm which endpoint is actively checking in to the Datto EDR portal.
- If you cannot determine which entry is active, contact Kaseya Support before removing any devices.