Lavawall® vs. Datto RMM
Lavawall® vs. Datto RMM: remote support, RMM, and security compared
Lavawall® and Datto RMM are both RMMs. Lavawall® also includes Microsoft 365 and Google Workspace breach detection, compliance evidence, Windows administrator elevation, and a password vault on the same agent, and offers end-to-end encrypted remote sessions in which the relay holds no key.
Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams, with patching, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance built into the same agent and console. Lavawall® is made in Canada by ThreeShield Information Security Corporation.
Install Lavawall® through Datto RMM with a ready-made component, run both agents side by side, and move companies over when your team is ready.
Start a 14-day free trialSee the comparison
14-day trial of the full platform, no credit card. Then month-to-month, with no long-term contract and no high-water-mark billing.
Side by side
The short version: Datto documents Web Remote for Windows and macOS devices with a Managed Agent installed, uploads of up to 1 GB per file, and IT Glue, a separate product, for passwords in sessions. Lavawall® offers ad-hoc sessions for computers without the agent, uploads of up to 2 GB, a built-in password vault, and patching for more than 7,400 applications on Windows, Mac, and Linux from one catalogue. Datto's documentation also says its Advanced Software Management patching add-on is Windows only, is not supported on ARM-based devices, and can close some programs without warning; Lavawall® waits for the program to close, warns the user, or updates at reboot. Every Datto fact below links to Datto's own documentation.
| Capability | Lavawall® | Datto RMM | NinjaOne |
|---|---|---|---|
| Is it an RMM? | Yes | Yes | Yes |
| Browser-based remote control | Yes, including from a phone | Yes, HTML5 Web Remote (Datto help) | Yes (NinjaOne FAQ) |
| Computers that can be remotely controlled | Windows and Mac | “Only Windows and macOS devices with a Managed Agent installed” (Datto help) | Windows and macOS (NinjaOne FAQ) |
| Linux computers | Scripts, patching, and monitoring; no remote desktop | See Datto documentation | Remote command execution (NinjaOne FAQ) |
| Support a computer that has no agent installed | Yes, ad-hoc sessions from the same console | Controls only devices with a Managed Agent installed (Datto help) | Quick Connect, for devices without the NinjaOne agent (NinjaOne docs) |
| File upload size per file | Up to 2 GB | “Limited to 1GB per file upload” (Datto help) | Not stated in NinjaOne documentation |
| Technicians in one session | Several, with control hand-off | “Up to four” (Datto help) | Multiple administrators (NinjaOne FAQ) |
| Session record | Session logging: every connection and command, with optional screen captures on the ticket | See Datto documentation | Session playback (NinjaOne FAQ) |
| Restrict where technicians connect from | By country (on by default) and by IP address | See Datto documentation | IP allowlist (NinjaOne FAQ) |
| Third-party and OS patching | 7,400+ applications on Windows, Mac, and Linux, kept up to date daily; waits for the program to close, warns the user, or updates at reboot; ARM supported | Broader catalogue through the Advanced Software Management add-on: Windows only, not supported on ARM-based devices, some programs “forcibly close without warning,” and up to 10 business days for Tier 3 applications (Datto help) | See NinjaOne documentation |
| Password vault | Included; the server never sees stored passwords | Separate product: IT Glue, integrated with Web Remote (Datto help) | See NinjaOne documentation |
| Secrets for servers and scripts | Server secret manager: each server pulls only the secrets it needs, encrypted so only that server can open them | Input variables set as environment variables at run time; types are selection, string, date, and Boolean (Datto help) | Secure custom fields, hidden by default, that scripts can be permitted to read (NinjaOne docs) |
| FIPS 140-3 validated cryptography for remote sessions | Relay and Windows and Mac agents (Go Cryptographic Module, CMVP #5247); YubiKey 5 FIPS (#5291) for technician sign-in | See Datto documentation | See NinjaOne documentation |
Competitor information is taken from each vendor's public documentation as of September 2026 and linked above. Tell us if something has changed and we will correct it.
Also on the Lavawall® agent
Neither vendor's linked documentation describes these in a way we can compare line by line, so check with them for their current offering.
| Capability | Lavawall® |
|---|---|
| Installs through your current RMM | Datto RMM component, or a script for NinjaOne, ConnectWise, Kaseya, Intune, or any tool that runs one |
| Admin tools without disturbing the user | Admin Workspace: 19 Windows tools and 3 shells; root zsh on Mac |
| Admin tools one click away with administrator rights, without elevating the user | 50 Windows tools |
| Shell as the logged-in user, in their environment, without disturbing them | PowerShell (Windows) |
| End-to-end encrypted sessions, relay holds no key | Available |
| Hardware security key required before a session | Available |
| Built-in administrator elevation (just-in-time admin) | Included, Windows |
| Microsoft 365 and Google Workspace breach detection | Included |
| Compliance evidence collected automatically from the RMM | 70+ frameworks; GRC and RMM can also be used separately |
| Daily security checklists with live evidence | Included |
| Event logs and per-process history ready when you open a device | Included |
| File download size | No fixed limit |
Security questionnaires become a lookup, not a fire drill
GRC (compliance management) and RMM are tightly integrated in Lavawall®, and each can be used on its own. When a client questionnaire, a cyber-insurance renewal, or a SOC 2 or CMMC assessment asks for patch status, disk encryption, endpoint protection, and administrator rights on every computer, the RMM has been collecting that all along. The GRC module turns it into dated evidence for that company, so you look up the answer instead of gathering screenshots from several tools and rebuilding a spreadsheet.
Need compliance first? Start with GRC and turn on the RMM when you are ready.
Evidence collected from the RMM includes:
- managed device inventory;
- patch state by device;
- disk encryption state;
- endpoint protection coverage;
- administrator rights, and administrator elevation rules and decisions;
- compliance console access, access reviews, and control attestations;
- password vault collections and sharing;
- security training completion and phishing simulation results;
- published policies and their attestations.
Each file records what was collected, the filter used, when it ran (UTC), and for which company, so it still makes sense to an auditor a year later. The evidence maps to 70+ compliance frameworks, including CMMC 2.0, HIPAA, SOC 2, and ISO 27001. Lavawall® is built by ThreeShield, a CISSP and CISA cybersecurity audit firm.
Remote support in detail
For the technician
- Remote control from any modern browser, with nothing to install on the technician's side, including from a phone or tablet with an on-screen keyboard, Ctrl, Alt, Tab, and Esc keys, and Bluetooth keyboard support.
- Full-screen mode with its toolbar, choice of monitor on multi-monitor computers, clipboard sending and fetching, and the remote computer's real cursor shape.
- File transfer in both directions: uploads of up to 2 GB per file, and downloads with no fixed size limit.
- Chat with the person at the computer, inside the session.
- Several technicians in the same session, with hand-off of control.
- Ad-hoc support: connect to a computer that does not have the Lavawall® agent installed, for a one-off session.
- Scripts on Windows, Mac, and Linux, including imported Datto RMM scripts. A company can also be limited to the signed script library built into the agent, so a stolen console session cannot push an arbitrary script.
- Push notifications to the technician's phone for requests that need a decision.
For the customer and the security team
- The person at the computer can be asked for consent before a session, set per company, and can end sharing at any time.
- Per-technician access scope: which companies each technician may reach at all.
- Technician access limited by IP address and by country. Country restriction is on by default.
- Sign-in with passkeys or hardware security keys, and technicians can be required to use a hardware key before a session starts.
- End-to-end encrypted sessions are available. The relay carries encrypted traffic and holds no key for it. Each computer has its own key, held in the TPM on Windows and the Secure Enclave on Mac, and it cannot be exported.
- Session logging: every connection and every command sent is logged, and screen captures can be attached to the ticket when the technician wants a record.
- Every session and administrative action is written to a tamper-evident activity log.
- Data residency in Canada, the United States, Europe, or Australia, and a US-only path for tenants that need one.
What Datto RMM documents
Datto RMM's own Web Remote documentation describes it as “a browser-based HTML5 remote control, chat, and PowerShell tool.” It says “Only Windows and macOS devices with a Managed Agent installed can be controlled,” that up to four users can connect to a single Windows or macOS device at the same time, and that “File uploads are limited to 1GB per file upload.” It also describes multiple-monitor support on Windows devices and a Privacy Mode that prompts the end user to accept or decline.
Lavawall® uploads files of up to 2 GB, twice the 1 GB per-file limit in Datto RMM's Web Remote documentation, and downloads files with no fixed size limit.
If your team pays for a separate tool beside Datto RMM to help computers without the agent, such as Splashtop SOS, ConnectWise ScreenConnect, or LogMeIn Rescue, Lavawall® ad-hoc sessions cover that from the same console. For passwords, Datto documents inserting them into Web Remote from IT Glue, a separate product that must be integrated; Lavawall® includes its own password vault.
Patching: Datto’s Advanced Software Management compared
Datto RMM’s broader Windows third-party catalogue is its Advanced Software Management add-on. Datto’s own documentation and published catalogue set out its limits:
- Programs can close without warning. Datto says that during Advanced Software Management updates, “certain software applications will forcibly close without warning.” Lavawall® waits until the program is closed, warns the user, or installs the update at the next reboot.
- No ARM devices. Datto says Advanced Software Management “is not currently supported for use on ARM-based devices.” Lavawall® supports ARM-based computers.
- Windows only. Datto says it is “currently only supported for Windows OS devices.” Lavawall® patches Windows, Mac, and Linux from the same agent.
- Up to 10 business days for most applications. Datto sorts applications into three tiers, updated within 1, 5, or 10 business days, with Tier 3 covering “less critical” software and everything not placed in a higher tier. By our count, most entries in the catalogue are Tier 3. Lavawall® keeps applications up to date daily.
- A smaller catalogue than the count suggests. On 18 September 2026, Datto’s catalogue listed 315 entries. By our count, 115 of them are versions of Microsoft software, such as Office, .NET, and Visual C++, which Lavawall® updates through Microsoft, leaving about 200. Dozens of those are separate 32-bit and 64-bit entries for the same product, and 16 are marked discontinued. Lavawall®’s public catalogue lists more than 7,400 applications.
- No proxy-configured agents. Datto says Advanced Software Management “does not currently support proxy-configured Datto RMM agents.”
Quotes are from Datto’s Advanced Software Management and catalogue pages, read 28 September 2026; the catalogue counts are ours, from the catalogue as published on 18 September 2026. Tell us if something has changed and we will correct it.
Where Datto RMM may fit better
Datto RMM may fit better if you already have a large investment in Kaseya products such as Autotask, IT Glue, and Datto backup, and value having them from one vendor. It also has a long track record at very large scale, which some buyers weigh heavily.
If that describes you, the side-by-side start still works: keep Datto RMM for what it does well today, and try Lavawall® on one site.
Remote sessions protected by FIPS 140-3 validated cryptography
Remote sessions are protected by FIPS 140-3 validated cryptography in the relay and the Windows and Mac agents (Go Cryptographic Module, NIST CMVP certificate #5247), and end-to-end encrypted sessions are available: in an end-to-end encrypted session, the relay holds no session key and cannot read the session. Technicians can be required to sign in with a YubiKey 5 FIPS hardware key (CMVP certificate #5291) before a session starts.
A useful question for any remote support vendor: who, at your company or in your cloud, can see my customer's screen? With an end-to-end encrypted Lavawall® session, the relay in the middle carries encrypted traffic and has no key for it. See FIPS 140-3 support for exactly what each validated module covers.
50 Windows admin tools, each one click away with administrator rights
In any Windows remote session, from a desktop or a phone, the technician opens an admin tool with one click and it runs with administrator rights. The user's account is never elevated, there is no UAC prompt, and there is no local administrator password to look up.
- Command Prompt
- PowerShell
- File Explorer
- Task Manager
- Services
- Registry Editor
- Event Viewer
- Device Manager
- Disk Management
- Computer Management
- Hyper-V Manager
- Task Scheduler
- Local Users & Groups
- Group Policy
- Local Security Policy
- Performance Monitor
- Resource Monitor
- Windows Defender Firewall with Advanced Security
- Control Panel
- Programs & Features
- Shared Folders
- Certificates (computer)
- Print Management
- System Properties
- System Information
- System Configuration
- User Accounts
- Component Services
- WMI Control
- Resultant Set of Policy
- TPM Management
- ODBC Data Sources
- Driver Verifier
- Memory Diagnostic
- Windows Features
- Disk Cleanup
- Optimize Drives
- Network Connections
- Windows Defender Firewall (Control Panel)
- Power Options
- Sound
- Internet Options
- Security & Maintenance
- Date & Time
- Remote Settings
- Remote Desktop Connection
- DirectX Diagnostic
- Character Map
- About Windows
- Camera, microphone and speaker use check
Some tools appear only where Windows provides them, for example Hyper-V Manager on Windows Server and Resultant Set of Policy on domain-joined computers.
Administrator elevation, built in
Lavawall® includes just-in-time administrator rights for Windows users on the same agent. When a standard user hits an administrator prompt, Lavawall checks the request against the company's rules and approves it, denies it, or sends it to a technician, who can approve it from a phone notification. Nobody needs standing administrator rights.
- Rules can match a publisher's code-signing certificate, a thumbprint, a file hash or a path. Certificate rules are preferred and survive routine certificate renewals.
- An MSI installer can be approved for one specific package, not all of msiexec.
- Ringfencing: an elevated program can be blocked from starting other programs, reading files, or using the network.
- Execution prevention: a curated block list of the tools ransomware commonly uses, such as the ones that delete shadow copies or clear logs, rolled out in audit mode first. Enforcement is allowed only after the audit shows what would have been blocked.
- Offline approval with a one-time code when the computer has no connection.
- The rule set each computer follows is signed, and the computer verifies the signature before applying it.
- It installs automatically through the Lavawall® agent, with no separate enrolment code.
Administrator elevation is available for Windows. See administrator elevation for the details.
The Admin Workspace: fix it without disturbing the user
The Admin Workspace gives the technician a private workspace on the remote computer with administrator rights, while the person at the computer keeps working and sees nothing on their screen.
- PowerShell (system)
- PowerShell (logged-in user)
- Command Prompt (system)
- Task Manager
- Performance Monitor
- Windows Defender Firewall with Advanced Security
- About Windows
- Startup apps
- Registry Editor
- File Explorer
- Services
- Programs & Features
- Event Viewer
- Task Scheduler
- Device Manager
- Windows Features
- Local Users & Groups
- Disk Management
- Memory Diagnostic
- Reliability History
- Active Connections
- Disk Cleanup
Files move both ways from the same place: upload files of up to 2 GB each to the computer, and download files with no fixed size limit (large files stream straight to disk in Chrome and Edge).
On a Mac, the Admin Workspace gives a zsh shell with root access, without disturbing the user. macOS asks the user to allow screen and audio access; our Mac setup guide shows what to click.
Shells at system level or as the logged-in user
On Windows, a technician can open PowerShell with system rights, PowerShell as the logged-in user, or Command Prompt with system rights. The user-level PowerShell runs inside that person's own session, profile, and environment, so per-user installs (for example with winget), mapped drives and user settings work, and nothing appears on their screen.
On a Mac, a zsh shell with root access runs in the Admin Workspace. Each shell opens in seconds as a live terminal in the browser, including from a phone, with Ctrl, Alt, and the other special keys. Linux computers run scripts.
Morning security checklists
Daily, weekly and monthly checklists, on a morning, evening or any other schedule, for each company. Live panels bring the evidence to each check, such as monitored services and service-provider status, so the technician confirms rather than goes looking. Answering "same as last time" or "the rest are good" is one click, and each check rests until it is due again.
Event logs and process history, ready before you ask
Lavawall® collects and sorts Windows event logs and per-process resource use in the background. When a technician opens a device, the important events are already sorted and each running process has a chart of its CPU and memory use over time. There is no waiting for Event Viewer or Task Manager to load on a slow computer, and it works when the computer is too busy to use comfortably.
Secrets for servers and scripts
Scripts often need a password, an API key, or a service account. Lavawall® keeps those out of script bodies in two ways.
- The server secret manager. Secrets that servers and automation depend on live in the Lavawall® vault. A Windows or Linux server pulls exactly the secret it needs, encrypted so only that server can open it, with nobody at the keyboard; Lavawall®'s servers store only encrypted data they cannot open.
- A signed script library. Scripts can be your own, including imported Datto RMM scripts. A company can also be limited to the signed script library built into the agent, with typed parameters, so a stolen console session cannot push an arbitrary script to its computers.
See remote support and security and privacy for how the server secret manager works.
Making the case to your team
One line for your partners or manager: We can try Lavawall® on one client in minutes through Datto RMM with the ready-made component, without changing anything in Datto RMM. There is no credit card to start, it is month-to-month after that, and if it does not earn its place we uninstall it.
Before you compare prices, list what you pay for today beside Datto RMM: a remote support tool for computers without the agent, a password manager, administrator elevation, compliance evidence, security awareness training, and Microsoft 365 configuration backup. Compare that total with Lavawall® pricing.
How to switch, or run both during the move
Your first step is small. Lavawall® deploys in minutes through the RMM you already run, on one company or on all of them, and works alongside it while your staff build comfort with it, starting with the features you need most. Moving is quick when you are ready: the Datto RMM component and the install scripts for other RMMs take minutes, and Datto RMM scripts import into Lavawall® with their variables detected automatically. Most organizations that start this way end up running their RMM work in Lavawall®, one company at a time, once they have used the two side by side. If it does not earn its place, uninstall it: Lavawall® installs no kernel driver, so the agent comes off cleanly.
Start with the ready-made Windows and Mac components (see installing Lavawall through Datto RMM). Both agents run side by side, so you can move remote support, patching, monitoring, and scripts over one company at a time, then retire the Datto agent when you are ready. The integration also runs the other way: Lavawall® can deploy Datto RMM agents from a Datto Site GUID.
Start a 14-day free trialTalk to a human
14-day trial of the full platform, no credit card. Then month-to-month, with no long-term contract and no high-water-mark billing.
Frequently asked questions
- Is Lavawall an RMM?
- Yes. Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams. It includes monitoring, patching for more than 7,400 applications, scripting, and browser-based remote support, along with security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance evidence on the same agent.
- Can Lavawall replace Datto RMM?
- Yes, for most MSPs and IT teams that manage Windows and Mac computers, with Linux covered by scripts, patching, and monitoring. You do not have to do it all at once: start with the Datto RMM component, use the Lavawall features you need first, and import your Datto RMM scripts with their variables detected automatically.
- Is Lavawall a Datto RMM component?
- No. Lavawall® is its own RMM, made by ThreeShield Information Security Corporation in Canada. It has a ready-made Datto RMM component that installs the Lavawall agent on the computers Datto RMM already manages, and it installs through NinjaOne, ConnectWise, Kaseya VSA, Intune, or any tool that runs a script. Many teams start that way, use the Lavawall features they need first, and move remote support, patching, and scripts over when they are ready.
- How does Lavawall patching compare with Datto RMM Advanced Software Management?
- Lavawall patches more than 7,400 applications on Windows, Mac, and Linux. Datto's documentation also says Advanced Software Management is not supported on ARM-based devices, can forcibly close some applications without warning, and takes up to 10 business days for Tier 3 applications. Lavawall keeps applications up to date daily, waits for the program to close, warns the user, or updates at reboot, and supports ARM.
- Can Lavawall and Datto RMM run on the same computers?
- Yes. Both agents run side by side while you move over, so there is no cut-over weekend. Lavawall installs no kernel driver, so the agent uninstalls cleanly if you decide not to keep it.
- Can we bring our Datto RMM scripts?
- Yes. Datto RMM scripts import into Lavawall®, and their input variables are detected automatically.
- Do we pay for both while we move?
- You pay for Lavawall only for what you add to it, month-to-month, with no long-term contract and no high-water-mark billing, so your Lavawall bill grows as companies move over. Modules can be bought individually if you want to start with one. Paid tiers have a starting size; the pricing page lists current rates in Canadian and US dollars.
- How much will our technicians need to learn?
- Less than you might expect. The console runs in a browser, including on a phone, and the Admin Workspace opens the Windows tools technicians already use, such as Task Manager, Services, the Registry Editor, and Event Viewer. Starting with one company lets them learn on real tickets while your current RMM keeps running.
- What if we decide Lavawall is not for us?
- There is no long-term contract and no minimum term, your data is yours to export, and the agent uninstalls cleanly because Lavawall installs no kernel driver.
- How does Lavawall remote support compare with Datto RMM Web Remote?
- Both run in the browser. Lavawall's remote support includes end-to-end encrypted sessions in which the relay holds no key, ad-hoc sessions for computers without the agent, an Admin Workspace with 19 Windows tools and three shells, 50 Windows admin tools one click away with administrator rights, technician access limited by country by default, and uploads of up to 2 GB. Datto's documentation says Web Remote controls Windows and macOS devices with a Managed Agent installed, allows up to four users on one device at a time, and limits uploads to 1 GB per file.
- Can Lavawall be used for compliance without replacing our RMM?
- Yes. GRC and RMM are tightly integrated but can be used separately. Many teams start with the RMM, and when an assessment or a client security questionnaire comes up, the evidence the RMM has been collecting is ready to use. Others start with GRC and turn on the RMM later.
- Is Lavawall FIPS 140-3 validated?
- Lavawall uses FIPS 140-3 validated cryptographic modules in specific components: the Go Cryptographic Module (CMVP certificate #5247) in the relay and the Windows and Mac agents, and YubiKey 5 FIPS (certificate #5291) for hardware technician authentication. The product as a whole is not a cryptographic module and has no certificate of its own.
- Who makes Lavawall, and where is it hosted?
- Lavawall is built in Canada by ThreeShield Information Security Corporation, a CISSP and CISA cybersecurity audit firm founded in 2006. Data can be hosted in Canada, the United States, Europe, or Australia.
Datto and Datto RMM are trademarks of Kaseya. NinjaOne is a trademark of NinjaOne, LLC. Splashtop is a trademark of Splashtop Inc. ConnectWise and ScreenConnect are trademarks of ConnectWise, LLC. LogMeIn and LogMeIn Rescue are trademarks of GoTo Group, Inc. Lavawall is not affiliated with any of them.