Datto RMM's version 15.0.1 `cagservice.exe` was falsely flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint due to a misclassification in a Microsoft security intelligence update, causing affected devices to go offline in Datto RMM. Microsoft resolved the misclassification in security intelligence update version 1.453.344.0, but since Microsoft does not automate file quarantine reversals, manual remediation was required to bring affected devices back online. Partners were advised to update to definition version 1.453.344.0 or later and manually restore quarantined files using provided PowerShell and CMD commands.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
This incident has been resolved.
A fix has been implemented and we are monitoring the results.
The Kaseya R&D team confirmed with Microsoft counterparts that the issue was caused by misclassification of the 15.0 Datto RMM version's cagservice.exe in a recent security intelligence update for Microsoft Defender Antivirus and other Microsoft antimalware.
This issue was fixed in the security intelligence update version 1.453.344.0, and the issue should no longer occur as long as the device is on this definition version or later. Microsoft currently does not offer an automated way to revert the quarantining of a file, therefore manual action is required to bring affected devices back online in Datto RMM.
We recommend our partners to ensure that devices are updated with security intelligence version 1.453.344.0 or later to avoid the agent being falsely flagged as malicious by Microsoft antimalware.
Users can use the below commands and instructions to ensure that the latest security intelligence update is installed on the device to prevent the behavior:
Updating the security intelligence version:
- PowerShell: Update-MpSignature
- Command Prompt (CMD): MpCmdRun.exe -SignatureUpdate
After running the update, users can verify the installed version with the following command:
- Get-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated
The issue has been identified and a fix is being implemented.
We are continuing to investigate this issue.
We are aware of a problem where Datto RMM's 15.0.1 Cagservice.exe is being flagged as malicious (Rapidstop) by Microsoft Defender for Endpoint.
The Kaseya R&D Team are investigating this issue.
Subscribe to the Kaseya Status Page for up-to-date information at https://status.kaseya.com/
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with