Device security is key to keeping your Datto RMM account protected. In this week’s Tech Tuesday, we explore the built-in security features you can use to safeguard your environment and reduce risk.
Step by Step:
- Open Datto RMM and navigate to the security settings to review device and agent security best practices.
- Enable device approval (sandboxing) to ensure only authorized devices can connect to your Datto RMM account.
- With device approval enabled, require administrator approval before new devices can run jobs, download components, or accept policies.
- Navigate to Devices → Approval Required in the new UI to review devices awaiting approval.
- Review agent encryption status in the same area to identify agents with missing or incorrect encryption keys.
- Investigate any encryption key mismatches, which may indicate a legitimate agent reinstall or a potential security issue.
- Review agent IP address restrictions and configure access so the agent browser is only reachable from approved IP addresses.
- Confirm malware protection is active on all endpoints.
- Use filters and monitors to detect devices with missing or unhealthy antivirus protection.
- Review antivirus status data, including whether the product is running and up to date.
- Use Datto RMM patch management to deploy Windows updates and monitor devices requiring additional attention.
- Monitor Windows Update service issues as they are reported directly through Datto RMM.
- Verify compatibility with Windows 11 and review patch installation results using the same interface.
- Use the component engine to deploy Windows 11 quality updates when needed.
- Configure software management to keep critical applications updated automatically.
- Push supported software updates to Windows and macOS endpoints as soon as vendors release new versions.
- Run the security audit component on Windows systems to assess overall security health.
- Review the security audit checklist to identify and remediate common security issues.
- Configure agent policies to define how endpoints behave and what actions are allowed.
- Use agent policies to control remote access, job execution, and feature availability on specific devices.
- Apply agent policies independently of user security settings to ensure consistent device behavior.
- Restrict automation or remote access on sensitive devices that should never run jobs or receive remote support.
- Review and adjust these security controls regularly to maintain a strong Datto RMM security posture.