Secure Edge Android beta
The Secure Edge android beta is released and available for all Secure Edge customers. All Secure Edge accounts are invited to participate in the beta via the Google Play Store.
BEFORE YOU BEGIN Using third-party VPN and DNS filtering applications with the Secure Edge solution may cause unexpected or undesirable behavior. We recommend disabling these utilities for endpoints that leverage the Secure Edge client.
Features
The Android client will have the same set of features and end user experience as found in the Windows and MacOS versions, with two exceptions:
- The Android clients cannot be installed using Datto RMM or VSA 10.
- The Andorid clients cannot be checked with the SafeCheck with Datto RMM feature. There is an optional configuration parameter to allow unverified Androids while continuing to provide SafeCheck for MacOS and Windows clients.
Supported OS
-
Android versions 13, 14 and 15
Installation
-
Go to the Google Play Store and navigate to the Secure Edge client.
-
Select to install the Secure Edge client.
-
Once it completes the install, open the Datto Secure Edge Client.
-
Enter in the Organization Code.
NOTE When using IdP, an additional prompt for the credentials will be required. For more information on the Authentication Settings, please review: Authentication Settings .
The client is now in a pending state and needs to be approved inside the Provisioning page inside of Network Manager. This extra step is a security measure to prevent the creation of unwanted softclients.
Approving the softclient
The following steps will need to be completed by an administrator with Partner Portal access.
-
Log into the Datto Partner Portal.
-
Navigate to Networking Status > Network Manager > Manage > Secure Edge > Provisioning > Pending Clients. Then, select the boxes next to the clients you'd like to approve.
-
Select Approve and the Assign Subscriber & Approve Client(s) modal will appear. Ensure that each client listed in the Hostname drop-down menu has a corresponding subscriber assigned in the Subscriber drop-down menu.
-
Return to the newly-added workstations. Within five minutes, the softclient will connect to the service. The subscriber is now protected by Secure Edge.
After the user has been provisioned, the count in the Subscriptions in Use section of the Network Manager will be increased accordingly.
The User will also be listed under the Provisioning section, where it can be managed.
-
Once the client has been approved, return to the client device and select Login to complete the setup.
Once the setup has been completed
Datto recommends checking the following to confirm setup has completed properly and everything is working as intended. For more information on these configurations, refer to: Configure your Cloud Gateway.
-
Verify that client works with the configured Always On or User based authentication.
-
Verify that Security Policies work as expected:
- Tunnel Settings
- DNS Filter
- Application Control
-
Test end user experience with applications.
If you experience any problems, please reach out to Datto Technical Support.
Frequently Asked questions

No. Each Secure Edge subscriber license allows for up to 3 concurrent connected sessions per subscriber license

The Datto Networking Support team is ready to support you. Please open a case with the Support team

Yes, you can submit feedback via any of the following options.
- This online form
- Email to: Secure_Edge_Beta@datto.com

No longer than 90 days.

No. The Secure Edge client will operate the same regardless of the connection type.
Please be aware standard data rates by your mobile provider may apply, depending on your service plan and if you are roaming outside of your coverage area while using this client.
Known Issues

After a month of use, the security key will expire, resulting in the client getting stuck in a "Connecting" state. This will also trigger an alert stating;
You have been logged out.
Restarting the device will resolve this issue.

The Secure Edge client does not show a device notification if the Android client authentication is rejected from the administrator or SafeCheck. In app messaging will provide an update if the soft client was not approved.
If the client is rejected due to failing SafeCheck, the in app message does not specify that it was rejected due to SafeCheck being enabled. Instead it displays the same messaging as if it was rejected by the administrator.
Access has been rejected for this device. Please contact your administrator for additional questions.

Disabling the Secure Edge notifications inside App notifications will cause the client to disconnect.