Skip to content
Current/ Help Center

Datto Backup: read your whole backup estate into your reviews

6 min read · Updated Jul 17, 2026

Backup health is one of the most persuasive things you can put in front of a customer — "here is every protected system, here is proof last night's backup booted, here are the Microsoft 365 seats we're protecting, here is what's falling behind." The Datto backup family already knows all of it. "Datto Backup" is one Current connection that reads all three products with a single Partner-Portal key pair: BCDR appliances (Unified Continuity — SIRIS / ALTO / NAS and cloud Datto Backup for Azure), SaaS Protection (Microsoft 365 and Google Workspace seat coverage), and Direct-to-Cloud agents. They all live on the same Datto Partner API (api.datto.com), so one key reads everything. Current maps each customer to the right company and makes it available for your Strategic Business Reviews. The connection is read-only in the strictest sense: Current reads Datto and never writes anything back.

Note
One tile now covers BCDR and SaaS Protection
This connection replaces the separate "Datto SaaS Protection" tile — the two backup products are merged into Datto Backup because the same Partner-Portal key reads both. If you connected SaaS Protection before, reconnect here; your previously synced seat data is kept, and one key now powers appliances, SaaS seats, and Direct-to-Cloud together.

Create the API key pair in the Datto Partner Portal

SCREENSHOT — coming soon
The Datto Backup card on Integrations — paste the Public and Secret API keys, Test, done.

Datto Backup authenticates with a Public/Secret API key pair, not a login — and the same pair reads BCDR appliances, SaaS Protection, and Direct-to-Cloud. You generate the pair once in the Partner Portal — it takes a Partner Portal administrator.

  1. 1
    Open the API Keys tab in the Partner Portal
    In the Datto Partner Portal, go to Admin ▸ Integrations ▸ API Keys.
  2. 2
    Create an API key
    Choose Create API Key. Datto issues a Public API Key and a Secret API Key.
  3. 3
    Reveal and copy the Secret key
    The Secret API Key is shown once, behind Reveal — copy it before you leave the page. (Regenerate Key rotates the pair if you ever lose it.)
  4. 4
    Paste both into Current
    In Current's left sidebar open Integrations (under Admin — Tenant Admins only), find the Datto Backup card, paste the Public API Key and Secret API Key, and press Test connection. Current validates the pair live against Datto before storing anything; a bad key is rejected on the spot. Both keys are kept server-side and never shown back to the browser. The same pair covers appliances, SaaS Protection, and Direct-to-Cloud — no second key.
Note
Who can connect it
Connecting, testing, and disconnecting Datto Backup are Tenant Admin actions. Any staff member who reaches the Integrations page can see the connection status; partner (read-only) users never see any of this, and never reach the backup data.

What Current pulls, and how often

The scheduled sync runs every six hours; a large estate drains across a few passes and resumes on its own. It reads three products with the one key — the BCDR device and agent lists, and the SaaS Protection customer roster with per-customer seat counts — and lands them in three places.

Data setWhat it gives you
Appliances (devices)Every BCDR appliance — SIRIS / ALTO / NAS and cloud "Datto Backup for Azure" units: serial, model, name, the client company it's assigned to, local and offsite storage used vs. capacity, share count, and when it last checked in. The executive fleet view.
Protected systems (agents)Each protected server or workstation: hostname, its parent appliance, the last backup time and result, whether the last backup passed screenshot/boot verification, local and offsite recovery-point counts, and whether the agent is paused or archived. The "are backups actually working" view.
SaaS Protection & Direct-to-Cloud (per customer)For each Microsoft 365 / Google Workspace backup customer: seat counts — active, paused, archived, licensed, and how many are actually protected — plus the customer's last backup time and result, and a Direct-to-Cloud agent count where Datto reports one. The "are we protecting every seat we're billing for" view.
Note
Cloud (Azure) appliances leave some fields blank — that's normal
"Datto Backup for Microsoft Azure" units report as model CLDSIRIS and have no local hardware, so fields like internal IP, share count, and local storage come across empty. That's expected, not a sync error.

The read-only guarantee

  • Current calls only GET (read) endpoints on Datto — the device list, the agent list, the SaaS Protection customer roster, and per-customer seats. Every request is checked against that allowlist in code before it's sent, and only GET paths are on it — so no write or management call can be reached even by a bug.
  • The one write in the entire Datto Partner API is a bulk seat change (it can pause or unlicense live, billed Microsoft 365 seats). Current does not use it, ever: it's a PUT, and only GET reads are on the allowlist, so the seat-change endpoint is unreachable in code — not merely hidden in the UI. Connecting Datto Backup can never change, pause, or remove a single seat.
  • Nothing you do in Current changes a Datto record. The Partner Portal key-management actions (Regenerate, Deactivate, Delete) are portal UI, not something this connector can touch.
  • The key pair travels once, on connect, and is stored server-side only. It is never logged, echoed, or returned to the browser.

How a customer finds its company

Datto identifies an end customer by company name — on the appliance for BCDR, and on the SaaS Protection customer record — and there's no stable id shared across your Current companies. Current matches that name to your companies automatically: it normalizes both sides (lowercased, punctuation and Inc/LLC/Ltd-style suffixes stripped) and links a company only when exactly one of yours matches. Anything ambiguous or unmatched is left for you. Because BCDR and SaaS use the same name-based match, a customer who has both a backup appliance and an M365 subscription maps once — one decision covers both.

  1. 1
    Work the Unmatched list on the card
    The Datto Backup card shows how many customers haven't mapped yet. Open it, and for each one either pick the Current company it belongs to, or leave it if there genuinely isn't one.
  2. 2
    A manual mapping always wins
    Once you map a company by hand, the auto-matcher never overwrites it — even if the names look close to another.
Note
Unmapped still syncs
A customer whose company hasn't been mapped yet is still pulled and stored — appliance, agents, and SaaS seats alike — it just doesn't surface on a company record until it's linked. Mapping it later makes its history appear without a re-sync.

When something looks wrong

What you seeWhat it means
Card shows Error, message mentions 401 or 403Datto rejected the key pair. It was most likely regenerated or deactivated in the Partner Portal. Create a fresh Public/Secret pair (Admin ▸ Integrations ▸ API Keys) and reconnect.
An appliance you expected isn't listedA Datto device only returns through the API once it's associated with your Partner Portal account and not still claimed by a vendor. Check its status in the portal. (If it's associated and still missing after a sync, the card may show a scope note — see the SaaS/Direct-to-Cloud row below.)
A customer shows no backup dataTheir company name — on the appliance or the SaaS customer record — hasn't mapped to a Current company yet. Map it from the Unmatched list on the card.
The card shows a SaaS Protection or Direct-to-Cloud noteThe key you connected can read appliances but not SaaS Protection or Direct-to-Cloud — some Partner-Portal keys are product-scoped. Create a NEW API key from Admin ▸ Integrations ▸ API Keys, paste the new pair, and press Test. Reconnecting keeps everything already synced and every mapping — nothing is lost.
SaaS seat counts are missing for a customerThe customer's roster row still mirrors, but its per-seat detail drains across a few passes on a large estate. It fills in on a later sync; a customer with no SaaS Protection simply shows appliance data only.
Rate-limited or slow first syncCurrent paces itself well under Datto's limit and backs off when asked; a big estate drains across several passes and resumes automatically. Come back later rather than re-clicking.
Heads up
Backup figures follow your financial-visibility rules
Storage, appliance, and SaaS seat data live on the company record and obey the same visibility rules as the rest of it. Partner (read-only) viewers never reach this data at all — it's blocked at the database layer, not just hidden.
Note
Disconnecting keeps your data
Disconnect stops the sync; everything already pulled — appliances, agents, and SaaS coverage — stays where it is, and the stored key is kept so you can reconnect without generating a new one. Only a Tenant Admin can connect or disconnect.
Was this helpful?