Views:

Configure the integration with Kaseya VSA to automate the deployment of TrendAI Vision One™ Endpoint Security agents to your managed customers’ endpoints and monitor agent status directly from TrendAI Vision One™ for Service Providers.

Important
Important
The instructions for Kaseya VSA are valid as of March 2026. For further help, check your Kaseya VSA documentation.

Procedure

  1. In TrendAI Vision One™ for Service Providers, go to Workflow and AutomationThird-Party Integrations.
  2. Locate and click the Kaseya VSA integration card.
  3. Connect your Kaseya VSA account to TrendAI Vision One™ for Service Providers.
    1. Generate an API credentials token in Kaseya VSA.
      For more information, see Obtain Kaseya VSA API token credentials.
    2. On the TrendAI Vision One™ for Service Providers console, click Connect Kaseya VSA in the integration screen.
    3. Paste the Token ID obtained from Kaseya VSA.
    4. Paste the Token Secret obtained from Kaseya VSA.
    5. Click Test connection to verify your connection.
    6. Click Connect to save your settings and establish the connection.
      Once connected, managed customer data is synchronized from Kaseya VSA with TrendAI Vision One™ for Service Providers.
  4. Map your customers to Kaseya VSA-managed customers, and select the appropriate Protection Manager for deployment.
    1. Under Step 2, click the edit icon (editIcon=6e8dd682-4c7a-4aaa-8aed-6c50cfa750b2.png) to begin matching your customers with Kaseya VSA.
      The Customer mapping window displays a list of your managed customers in alphabetical order.
    2. Use either automatic matching or manual matching to map your managed customers to those managed by Kaseya VSA.
      Mapping method
      Description
      Automatic match
      Click Run auto-match and wait for a few moments.
      Customers with exact spelling matches between TrendAI Vision One™ for Service Providers and Kaseya VSA are automatically matched, indicated by a magic wand icon MagicWand=41232b6b-236f-4fb6-b1fb-e0c7d390e459.png.
      Manual match
      Use the Mapping status drop-down to easily identify unmatched customers.
      For each customer, use drop-down menu in the Kaseya VSA-managed customer column to select the corresponding Kaseya VSA-managed customer.
      Important
      Important
      Any new customers added after the initial mapping must be mapped to ensure proper agent deployment. For customers that do not have a corresponding Kaseya VSA-managed customer, TrendAI Vision One™ does not install Endpoint Security agents on their endpoints.
    3. In the Standard Endpoint Protection Manager and Server & Workload Protection Manager columns, select the appropriate Protection Manager to manage deployments.
    4. Click Save.
  5. Under Step 3, select the Protection type you want to use to create a deployment script and workflow.
    You can create deployment scripts and workflows for each of the TrendAI Vision One™ Endpoint Security agent protection types by repeating the following steps for Standard Endpoint Protection, Server & Workload Protection, and Sensor-only deployments.
    After selecting a Protection type, the information for device scope, deployment script, and workflow automatically populates for that protection type.
    Important
    Important
    When a step requires you to copy and paste a value from TrendAI Vision One™ for Service Providers to Kaseya VSA, copy all values exactly without any changes. Changing any values might cause deployment and management to fail.
  6. Create a device scope to control which devices deploy agetns with the selected protection type.
    You must create a device scope before creating the deployment script and workflow. These steps include the recommended process of creating a workflow for Custom Fields batch deployment, allowing the scope to be determined based on the Custom Field criteria.
    1. In the Kaseya console, go to AutomationCustom Fields and click Create Custom Field.
    2. Specify a Display Name that allows you to identify the Custom Field easily.
      KaseyaScopeCustomField-01=36599a36-f5e2-4982-a384-cdcde538c640.png
    3. Under Contexts, select System.
      KaseyaScopeCustomField-02=38373d9f-db1b-4c36-bf68-313738bdda5f.png
    4. Click Create.
    5. Go to AutomationAutomation HubUser DefinedWorkflows.
    6. Click Create and select Create New.
    7. Specify a unique Name for the workflow.
    8. Set the Status to Active.
    9. For Trigger Type, select Ad-hoc and Scheduled.
    10. Click Next.
    11. Select Ad-hoc.
    12. Enable Skip if offline.
    13. Click + New Step and select Set Custom Field Value.
    14. For Name, select the name you specified for the Custom Field.
    15. For Context, select System.
    16. For Operation, select Set Value.
    17. For Value, specify which TrendAI Vision One™ Endpoint Security agent protection type the scope applies to.
      Such as Standard Endpoint Protection, Server & Workload Protection, or Sensor-only.
      KaseyaScopeWorkflow-01=cf7d7f4a-666a-4c01-b30a-fb1b5d5472cc.png
    18. Click Confirm, then click Save.
    19. Go to DevicesScopes and click Create Scope.
    20. For Name, copy the Scope name provided by TrendAI Vision One™ for Service Providers.
    21. Locate Custom Fields and click Edit Custom Fields Rules.
    22. Select the Custom Field you created, set the operator to is equal to, and specify the Value you provided for the workflow.
      KaseyaScope-03=ab28cdd5-5685-4a86-887d-402b8accd2de.png
    23. Click Confirm.
    24. Complete any other required field such as Tags or Description as needed.
    25. Click Save.
  7. Create a script to deploy the agetns on supported OS platforms.
    1. In the Kaseya console, go to AutomationAutomation HubUser DefinedScript and click Create Script.
    2. For Name, copy the Kaseya script name provided by TrendAI Vision One™ for Service Providers.
    3. Enable each operating system select the Script type based on your protection type

      Setting
      Standard Endpoint Protection
      Server & Workload Protection
      Sensor-only
      Windows
      • Enable: On
      • Script type: PowerShell
      • Enable: On
      • Script type: PowerShell
      • Enable: On
      • Script type: PowerShell
      Linux
      • Enable: Off
      • Enable: On
      • Script type: Bash
      • Enable: On
      • Script type: Bash
      macOS
      • Enable: On
      • Script type: Bash
      • Enable: Off
      • Enable: On
      • Script type: Bash
      KaseyaScripts=830c4af8-db32-4aff-9e79-449cdfee23cc.png
      Example for Standard Endpoint Protection
    4. For each enabled operating system, copy and paste the script provided by TrendAI Vision One™ for Service Providers.
    5. Click Save.
  8. Create a workflow that automates running the deployment script.
    1. In the TrendAI Vision One™ for Service Providers console, on the Kaseya VSA integration screen, click Download to download the deployment workflow.
    2. In your Kaseya VSA console, go to AutomationAutomation HubUser DefinedWorkflows.
    3. Click Create and select Import Workflow.
      KaseyaImportWorkflow=384b5e9f-e58d-477b-90ee-df9ae071763d.png
    4. Select the file you downloaded from TrendAI Vision One™ for Service Providers.
    5. Specify a unique Name that is identifiable.
    6. Set Status to Active.
    7. For Context, select Scope and select the scope you created for this deployment script.
    8. Click Save.
  9. Repeat the steps for scope, script, and workflow as needed for each protection type.