Your devices sit in offices, homes and pockets. Patching them shouldn’t need a desk visit — Kaseya VSA 10 monitors, patches and fixes Windows, macOS and Linux machines and manages Apple and Android devices, from Kaseya’s cloud or from a server you run yourself, in India if you choose.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Kaseya VSA — VSA 10, SaaS and on-premises, including third-party patching and MDM. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
An agent on every device reports to one console, so a small team can monitor, patch and fix hundreds of machines remotely.
What consolidation actually replaces, dimension by dimension.
| Dimension | Patching by hand, RDP by habit | Kaseya VSA |
|---|---|---|
| Who approves patches | An admin, one update at a time | Global and policy rules, by CVSS or category |
| Fixing a broken PC | A desk visit or an RDP port left open | A remote session, even with no agent installed |
| Repeat jobs | The same steps typed on every machine | One script, run as a task or a workflow |
| Phones and tablets | A second MDM tool and a second login | Apple and Android in the same console |
| Where the data sits | Spreadsheets on someone’s laptop | Kaseya’s SaaS, or your own server in India |
| What it is NOT | — | An EDR, a PSA, or a product with a public price |
The cheapest test is one office: scan it with a probe, push agents, run one full patch cycle with rules, and count what still needed a technician.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A SaaS tenant that Kaseya provisions, or your own install on Windows Server 2016+ with SQL Server 2016+, 8 GB of RAM, .NET 4.8 and a trusted SSL certificate.
Installed on Windows, macOS, Linux or Raspbian, or pushed by a Windows probe after a network scan; agents update themselves within 36 hours of each release.
Monitoring, patch, remote-desktop and MDM profiles attach to policies at organisation, site, group or device level, and since 10.28 can follow dynamic device tags.
Scripts, tasks, workflows and managed files sit in one hub, split into Kaseya’s built-in content, Kaseya content packs and the scripts your own team writes.
One server — Kaseya’s cloud or your own Windows box — sends policies, patches and scripts to agents on every OS.
Kaseya VSA 10 runs every device from one console, on Kaseya’s cloud or on your own server.
One Windows agent acts as a probe, finds the devices on its network and mass-installs the agent with the policies you choose.
Since 10.28 a policy can target devices by tag, and each level shows which policies apply and the settings that win.
Apple devices take MDM profiles, including DDM update rules; Android Enterprise enrolment arrived with 10.27 in June 2026.
Global, policy and single-patch rules approve or reject OS updates by name, category or CVSS score before they deploy.
Since November 2025 the device card lists a Linux machine’s pending packages and installs the ones you tick, important first.
A third-party patching licence, counted per device with an expiry date, adds app titles; custom titles take any hosted installer.
PowerShell, Bash, Batch and VBScript run as one-off tasks, on a schedule, or as steps in a workflow built in the Automation Hub.
Console or shared desktop sessions with file transfer; Remote Control on Demand reaches a PC that has no agent installed.
A behavioural policy spots crypto-ransomware, alerts, isolates the device and tries to stop the processes; Bitdefender and Webroot plug in.
Here’s what genuinely sets it apart — and exactly where it stops.
Datto RMM runs only in Kaseya’s cloud. VSA 10 also installs on your own Windows Server with SQL Server, so inventory, scripts and logs stay in a data centre you pick, India included. Since 10.26 an on-prem server can add a FIPS 140-3 validated nginx proxy, advised up to 5,000 devices.
iPhones, iPads and Macs take MDM profiles, including Apple’s declarative update settings. Android Enterprise arrived in 10.27 (June 2026) with BYOD, fully managed and kiosk enrolment, and 10.28 added location tracking via the Kaseya Go app. Several rival RMMs sell mobile as an add-on.
OS updates pass three layers of rules: tenant-wide global rules, then rules inside each patch policy, then a technician’s call on what is left. Rules can approve by CVSS score or hold back drivers. Since November 2025, Linux machines list and install pending packages from the device card.
No public price, and third-party patching is a separate licence outside Kaseya 365 Endpoint. On-prem means you patch the server and its nginx yourself, and the installer needs internet. Remote control of Azure-hosted devices is unsupported. The 2021 attack hit on-prem VSA 9.5.x; clients will ask.
Weigh where device data must sit; if India, size an on-prem host with Windows Server, SQL Server and 8 GB RAM or more.
Ask for VSA 10 alone and inside Kaseya 365 Endpoint, with third-party patching and the device count written into both.
Set a Windows probe, scan one office, push agents with a baseline policy, and enrol a few Apple and Android devices.
Write global and policy rules, hold back drivers, patch the pilot site including Linux, and record what needed a manual call.
Turn the top ten repeat tickets into scripts or workflows, switch on ransomware detection, and roll out to every site.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our auditors wanted device data kept in our own Mumbai rack. The on-prem server made that a short conversation.”
“A global rule now holds back every driver update. That alone ended the Monday-morning blue screens on our lab PCs.”
“We moved our old VSA 9 procedures to PowerShell during migration. Painful for a month, far easier to maintain since.”
“Android kiosk enrolment let us lock down 300 delivery handhelds from the same console we use for laptops.”
“Remote Control on Demand saved a site visit when a vendor laptop with no agent broke a production line.”
“Budget for the third-party patching licence up front. Our first quote left it out and the gap showed in month two.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the RMM market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
SaaS or on-prem; MDM built in; quote only.
The grid nobody publishes — how much say you have over where the RMM server and its data live, India included, vs how many kinds of device it manages from one console.
Own server or SaaS; Windows, macOS, Linux, Apple and Android.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Datto RMM, NinjaOne RMM, N-able N-central, ConnectWise Automate and SuperOps RMM — on hosting, devices, patching, scripting, price, security, support and India.
| Dimension | Kaseya VSA | Datto RMM | NinjaOne RMM | N-able N-central | ConnectWise Automate | SuperOps RMM |
|---|---|---|---|---|---|---|
| What it is | Kaseya’s own RMM | Kaseya’s cloud RMM | Cloud endpoint platform | Heavyweight MSP RMM | Scriptable MSP RMM | RMM + PSA, India-built |
| Deployment and scale | SaaS or on-prem | Cloud only | Cloud only | On-prem or hosted | Own server or cloud | Cloud only |
| Devices and mobile | Win, mac, Linux + MDM | No phones yet | MDM is an add-on | OS plus SNMP gear | Windows first | MDM in Prime Plus |
| Patching | OS by rule; 3P licensed | Windows; 3P via ASM | OS and 3P included | OS and 3P by policy | Windows rings; narrow 3P | All OS; thinner 3P |
| Scripting and automation | 4 languages, workflows | Components, 4 languages | Five script types | 600+ drag-drop objects | Deepest scripting | Scripts and schedules |
| Pricing model | Quote only | Quote only | Per device, a range | Quote per device | Quote only | Per endpoint or tech |
| Published entry price | None published | None published | $1.50–$3.75/endpoint | None; free trial | None; free trial | $1.50/endpoint/month |
| Included vs add-on | 3P patching extra | ASM extra standalone | MDM, backup, EDR extra | Remote, backup apart | Plugins and installs | PSA in the box |
| Security controls | Ransomware policy, 2FA | Ransomware, BSIMM | SAML SSO, step-up MFA | Tenant-scoped RBAC | Fine roles; you patch | 2FA, IP allow-lists |
| Integrations | Kaseya suite, AV tools | Autotask-native | Vendor-neutral | N-able’s own stack | ConnectWise PSA | Its own PSA |
| India storage region | Self-host in India | Sydney nearest | No India region | Self-host in India | Self-host in India | US or Europe only |
| Support and upkeep | Depends on hosting | No server to run | No server to run | Depends on hosting | You patch the server | India-hours support |
| Lock-in and exit | Standard scripts travel | Datto components | Plain script files | Policies are N-able’s | Automate-own objects | RMM and PSA together |
| Best fit | Self-hosted, mixed fleet | Autotask MSPs, cloud | Breadth, a price range | Walled-off clients | Windows MSPs who script | Small MSPs, open price |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Kaseya VSA is one of 24 rmm & patch products TechBag carries. The RMM & Patch guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints you manage; technician-hour cost). Estimates model technician time spent approving and installing patches by hand, visiting desks and repeating the same fixes, at an assumed 1.5 hours per endpoint a year, with 70% of it removed by patch rules, scripts and remote control. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published. Kaseya prints no price for VSA 10 and asks buyers to request one. It is quoted standalone, where third-party app patching is a separate per-device licence, or as the RMM inside Kaseya 365 Endpoint, which also carries third-party patching, Datto AV, Datto EDR and endpoint backup and needs 50 endpoints for new customers. Neither shows a rupee price. TechBag gets both quotes side by side, then adds GST.
Best for teams that only need the RMM
Best for a broader rollout
Best for buying RMM and endpoint security together
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Must device data stay in India? If so, plan an on-prem server; Kaseya lists no Indian SaaS site for VSA 10.
On-prem: who applies each release and nginx update, and how fast? The installer also needs internet access.
How many Windows, macOS, Linux, iOS and Android devices? Check each OS version against the agent and MDM docs.
Is third-party patching on the quote, and do your top twenty apps appear in the catalogue or need custom titles?
Is Kaseya 365 Endpoint cheaper than VSA 10 plus the add-ons you need? New customers face a 50-endpoint minimum.
Coming from VSA 9? Kaseya says never run the VSA 10 installer on a VSA 9 server; plan scripts to move to PowerShell.
Any devices hosted in Azure? Kaseya does not support its remote-control tools there, so plan another route.
Can your clients see how the server is hardened, 2FA is enforced and the 2021 VSA 9.5.x fixes are long applied?
Decide between SaaS and a server in India first, or let a TechBag advisor get VSA 10 quoted alone and inside Kaseya 365 Endpoint, with every add-on visible.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.