Overview
By integrating Kaseya SaaS Protection with MSPortal.ai, you can:- Monitor 24-hour backup coverage for Exchange, OneDrive, SharePoint, and Teams per client
- Track protected seats (users, shared mailboxes, sites, and Teams)
- See daily backup success trends across your customer base
- Include SaaS Protection health in client reports
Prerequisites
- A Kaseya SaaS Protection account with Datto Partner Portal access
- MSPortal.ai integration management permission
Part 1: Get Your API Keys
1
Open the Datto Partner Portal
Log in to the Datto Partner Portal.
2
Navigate to API Keys
Go to Admin > Integrations > API Keys.
3
Copy Both Keys
Copy the Public Key and the Secret Key. MSPortal stores both only in Vault.
Part 2: Setup Wizard
Go to Settings > Integrations, find the Kaseya SaaS Protection card, and click Configure. The wizard has four steps: Connect, Configure Sync, Map Domains, and Status.Step 1: Connect
1
Enter Your Keys
Enter your keys in the Public API key and Secret API key fields.
2
Test the Connection
Click Test Connection. On success you’ll see a confirmation such as “The API accepted these credentials and returned [n] accessible domains.”If the test fails:
- A rejected key message means the public or secret API key is incorrect
- A rate limiting message means Kaseya is throttling connection tests; try again shortly
- A timeout or unreachable message means the Kaseya API did not respond; try again in a moment
3
Create the Integration
Click Create Integration. The first sync starts automatically.
Step 2: Configure Sync
Choose what MSPortal fetches. Customer domains are always discovered for mapping; detailed data is fetched only for domains linked to an MSPortal company.
Click Save sync settings when done.
Step 3: Map Domains
Link the SaaS Protection domains you want to report on to MSPortal companies. The mapping table shows each domain’s Microsoft 365 domain, Seats, and 24h backup percentage.- Use Quick Match to auto-match domains to companies by name
- Map remaining domains manually, or create new companies on the spot
- Domain discovery normally completes in less than a minute
Only mapped domains get detailed seat and backup health data. Unmapped domains appear for mapping only.
Step 4: Status
The Status step confirms the setup is active and shows live counts that refresh automatically:- Mapped domains (mapped / total)
- Protected seats
- Services backed up (backed up / active)
- Workload summaries
Sync Schedule
Mapped domains sync automatically every hour. Syncs also run when you first connect and after you map domains. Backup trend history is retained on a rolling window of roughly 45 days.The SaaS Protection Health Page
Once the integration is active, a SaaS Protection tab appears in the Backup module. It shows Kaseya backup health across Microsoft 365 workloads, scoped to your current company selection.Health States
Page Sections
- Overall health summary: Aggregate status, customers in scope, last synced time, and tiles for Backed up in the last 24 hours, Services in initial backup, and Last 100% successful backup.
- Workload health: Four cards for Exchange, OneDrive, SharePoint, and Teams showing current 24-hour protection coverage.
- Backup result trend: A daily successful-service coverage chart with one line per workload, switchable between 10 days and 30 days.
- Customer backup health: A table of your portal companies and their mapped Kaseya domains, with per-workload ratios, initial-backup counts, and the last full success date.
Reporting
Three SaaS Protection blocks are available in the report builder: health summary, trend, and customer table, so you can include backup coverage in client reports.Troubleshooting
Security & Privacy
- Credential storage: Your API keys are encrypted in Supabase Vault and never exposed in logs or responses
- Disconnecting: Removing the integration deletes the connection and its stored Vault credentials; this cannot be undone
Related Resources
Backup
Monitor backup protection across devices and Microsoft 365
Reporting
Include backup health in client reports