Enable screen capture protection in Azure Virtual Desktop & Windows 365

Screen capture protection, alongside watermarking, helps prevent sensitive data from being captured on client devices using specific operating system (OS) features and APIs. When you enable screen capture protection, remote content is automatically blocked in screenshots and screen sharing. This feature can be applied to Azure Virtual Desktop virtual machines and Windows 365 Cloud PCs.

When Screen Capture Protection (SCP) is enabled to block screen capture on the client, users can continue to share their remote desktop or individual applications using supported collaboration experiences such as Microsoft Teams. Compatibility between SCP and Teams screen sharing depends on the use of supported client configurations. When unsupported configurations are used, protected content may appear as a black screen during sharing. For current compatibility requirements and configuration guidance with Teams, see here.

Important

Screen capture protection doesn't provide Digital Rights Management (DRM)-level protection. It prevents screen capture through standard OS features and APIs and isn't a substitute for DRM solutions. For comprehensive data protection, use screen capture protection as part of a broader defense-in-depth security strategy that includes other controls, such as conditional access policies, data loss prevention, and endpoint management.

Tip

  • To increase the security of your sensitive information, you should also disable clipboard, drive, and printer redirection. Disabling redirection helps prevent users from copying content from the remote session. To learn about supported redirection values, see Device redirection.

  • To discourage other methods of screen capture, such as taking a photo of a screen with a physical camera, you can enable watermarking, where admins can use a QR code to trace the session.

Determine your configuration

The steps to configure screen capture protection depend on where you configure it, which platforms your users are connecting from and what scenario you want to achieve.

  • Windows and macOS devices: you prevent screen capture by configuring virtual machines (Azure Virtual Desktop) or Cloud PCs (Windows 365) using an Intune device configuration policy or Group Policy. Windows App or the Remote Desktop client enforces screen capture protection settings without further configuration.

    When you configure screen capture protection on virtual machines or Cloud PCs, there are two further settings you can configure to help meet your requirements:

    • Block screen capture on client: prevents screen capture from the local device of applications running in the remote session.

    • Block screen capture on client and server: prevents screen capture from the local device of applications running in the remote session, but also prevents tools and services within the virtual machine or Cloud PC capturing the screen.

    In this scenario, here's the outcome when connecting from each platform type:

Platform Connection allowed Screen capture blocked
Windows
macOS
iOS/iPadOS   ✅¹   ✅¹
Android   1   1
Web   1   1

1. Hybrid enforcement (iOS/iPadOS/Android/Web): When Screen Capture Protection is enabled on the virtual machine or Cloud PC, connections from managed iOS/iPadOS and Android devices are allowed when protected by an Intune MAM app protection policy that blocks screen capture. On the web, connections from Microsoft Edge for Business are allowed when the Edge work profile receives an Intune MAM app protection policy that enforces screen capture protection through the Edge data loss prevention (DLP) features. Hybrid enforcement isn't applicable on platforms that don't support Intune MAM.

Note

Hybrid enforcement requires the following minimum app versions:

  • iOS/iPadOS: Windows App version 11.2.4
  • Android: Windows App version 11.0.0.94 (or later supporting hybrid enforcement)
  • Web: Enforcement supported on Edge for Windows
  • Android, iOS/iPadOS, and web connections: Screen captures are prevented by configuring local devices using Microsoft Intune mobile application management (MAM). It doesn't prevent tools and services within the virtual machine or Cloud PC capturing the screen. For more information, see Manage local device redirection settings with Microsoft Intune.

    In this scenario, here's the outcome when connecting from each platform type:

Platform Connection allowed Screen capture blocked
Windows
macOS
iOS/iPadOS
Android
Web   1

1. On the web, screen capture protection is enforced by the Edge for Business data loss prevention (DLP) features when users connect with Microsoft Edge for Business and receive an Intune MAM app protection policy. For configuration steps, see Enable screen capture protection with Intune MAM.

Important

For Android and iOS/iPadOS devices, and for the web client (on Windows), screen capture protection is enforced through Intune mobile application management (MAM). In each case, you configure two things: an Intune MAM app protection policy that applies screen capture protection, and a Conditional Access policy that requires the app protection policy so users can only connect when the policy is applied to the client. The exact app protection policy setting differs by platform — on Android and iOS/iPadOS you block screen capture directly, while on the web you configure Microsoft Edge for Business, where screen capture protection is enforced through the Edge data loss prevention (DLP) features. This is the supported model when admin-configured SCP (for Windows and macOS) is enabled in Intune. For configuration steps, see Enable screen capture protection with Intune MAM.

Platform considerations for screen capture protection on macOS

While fully supported on Windows, there are known limitations on macOS due to the platform's current security architecture:

  • Microsoft Teams compatibility: on macOS, enabling screen capture protection might interfere with screen sharing in Microsoft Teams, potentially causing shared windows to appear blank or not display properly. If Teams-based collaboration is required, screen capture protection might need to be temporarily disabled on the device.

  • Platform-level enforcement: due to macOS restrictions, some native applications might not fully respect screen capture protection enforcement. This is a limitation of the operating system's available APIs, not a defect in screen capture protection itself.

Here are some recommendations for these limitations:

  • For collaboration-heavy macOS workflows, consider configuring screen capture protection settings based on business need and risk level.

  • For highly sensitive content, Windows endpoints are recommended for full enforcement of screen protection features.

  • Watermarking and administrative policies can be used to further discourage misuse on platforms with limited enforcement.

Admin deployment patterns

The following patterns describe common deployment scenarios for screen capture protection:

Pattern 1: Desktop endpoints (Windows and macOS)

If your users connect only from Windows or macOS devices, configure screen capture protection on virtual machines (Azure Virtual Desktop) or Cloud PCs (Windows 365) using an Intune device configuration policy or Group Policy. No MAM configuration is required.

  • Configure virtual machines (Azure Virtual Desktop) or Cloud PCs (Windows 365) with screen capture protection enabled.
  • Windows App and the Remote Desktop client enforce protection automatically.

Pattern 2: Mixed endpoints (Windows/macOS and Android/iOS)

If your users connect from both desktop and mobile devices, use hybrid enforcement. Configure screen capture protection on both the virtual machine or Cloud PC and the Intune MAM app protection policy.

  • Configure virtual machines (Azure Virtual Desktop) or Cloud PCs (Windows 365) with screen capture protection enabled (Intune or Group Policy).
  • Configure an Intune MAM app protection policy to block screen capture on Android and iOS/iPadOS devices.
  • On Android and iOS/iPadOS, Windows App supports hybrid enforcement: if both the admin-configured SCP and the MAM policy block screen capture, the connection is allowed and screen capture is blocked. If the MAM policy doesn't block screen capture, the Android and iOS/iPadOS connection is blocked.

Pattern 3: Web endpoints (browser access)

If your users connect from the web client, enforce screen capture protection through Microsoft Edge for Business. Configure a Conditional Access policy that requires an app protection policy for browser access to your remote resources, together with an Intune MAM app protection policy for Windows that targets Microsoft Edge.

  • Create a Conditional Access policy that targets your remote resources (Windows 365 or Azure Virtual Desktop), applies to the Windows device platform and the Browser client app, and requires an app protection policy.
  • Create an Intune MAM app protection policy for Windows that targets Microsoft Edge and restricts cut, copy, and paste to organizational sources and destinations, which activates screen capture protection across the Edge work profile.
  • For configuration steps, see Enable screen capture protection with Intune MAM.

Prerequisites

Before you can configure screen capture protection, ensure you meet the following prerequisites:

  • For scenarios where you need to configure virtual machines or Cloud PCs, those virtual machines or Cloud PCs must be running a Windows 11, version 22H2 or later, or Windows 10, version 22H2 or later.

  • Users must connect to Azure Virtual Desktop with Windows App or the Remote Desktop app to use screen capture protection. The following table shows supported scenarios:

    • Windows App:

      Platform Minimum version Desktop session RemoteApp session
      Windows App on Windows Any Yes Yes. Local device OS must be Windows 11, version 22H2 or later.
      Windows App on macOS Any Yes Yes
      Windows App on iOS/iPadOS 11.2.4 Yes Yes
      Windows App on Android¹ 11.0.0.94 Yes Yes

      1. Doesn't include support for Chrome OS because Intune MAM isn't supported on Chrome OS.

    • Remote Desktop client:

      Platform Minimum version Desktop session RemoteApp session
      Windows (desktop client) 1.2.1672 Yes Yes. Local device OS must be Windows 11, version 22H2 or later.
      macOS 10.7.0 or later Yes Yes
  • To configure Microsoft Intune, you need:

    • Microsoft Entra ID account that is assigned the Policy and Profile manager built-in RBAC role.

    • A group containing the devices you want to configure.

  • To configure Group Policy, you need:

    • A domain account that is a member of the Domain Admins security group.

    • A security group or organizational unit (OU) containing the devices you want to configure.

Enable screen capture protection on virtual machines and Cloud PCs using an Intune device configuration policy or Group Policy

Select the relevant tab for your scenario.

To configure screen capture protection on virtual machines (Azure Virtual Desktop) or Cloud PCs (Windows 365) using Microsoft Intune:

  1. Sign in to the Microsoft Intune admin center.

  2. Create or edit a configuration profile for Windows 10 and later devices, with the Settings catalog profile type.

  3. In the settings picker, browse to Administrative templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Azure Virtual Desktop.

    A screenshot showing the Azure Virtual Desktop options in the Microsoft Intune portal.

  4. Check the box for Enable screen capture protection, then close the settings picker.

  5. Expand the Administrative templates category, then toggle the switch for Enable screen capture protection to Enabled.

    A screenshot showing the screen capture protection settings in Microsoft Intune.

  6. Toggle the switch for Screen Capture Protection Options (Device) to off for Block screen capture on client, or on for Block screen capture on client and server based on your requirements, then select OK.

  7. Select Next.

  8. Optional: On the Scope tags tab, select a scope tag to filter the profile. For more information about scope tags, see Use role-based access control (RBAC) and scope tags for distributed IT.

  9. On the Assignments tab, select the group containing the computers providing a remote session you want to configure, then select Next.

  10. On the Review + create tab, review the settings, then select Create.

  11. Once the policy applies to the computers providing a remote session, restart them for the settings to take effect.

Enable screen capture protection with Intune MAM

For Android, iOS/iPadOS, and the web client (on Windows), you enforce screen capture protection through Intune mobile application management (MAM). For each of these approaches, the configuration has two parts:

  1. Apply screen capture protection: configure an Intune MAM app protection policy that applies screen capture protection to the client app.
  2. Enforce the app protection policy: configure a Conditional Access policy that requires the app protection policy, so users can only connect when the policy is applied to the client.

Step 1: Apply screen capture protection with an Intune MAM app protection policy

Configure an Intune MAM app protection policy for the platform your users connect from. Follow the steps to Require local client device security compliance with Microsoft Intune and Microsoft Entra Conditional Access, then on the Data protection tab, configure the setting for your platform:

  • iOS/iPadOS (Windows App): set Screen capture to Block.

    A screenshot showing the iOS screen capture protection settings in MAM policy.

  • Android (Windows App): set Screen capture to Block.

    A screenshot showing the Android screen capture protection settings in MAM policy.

  • Web (Microsoft Edge for Business on Windows): target Microsoft Edge in a Windows app protection policy and set Allow cut, copy, and paste for to Org data destinations and org data sources. This activates screen capture protection across the Edge work profile automatically. For more information about the Edge for Business data loss prevention (DLP) features, see Data protection features for Microsoft Edge using Intune App Protection (MAM).

Configure other settings based on your requirements, then assign the app protection policy to your users.

Enforce the app protection policy with Conditional Access

The app protection policy applies screen capture protection, but a Conditional Access policy is what requires that policy to be present before a user can connect. Without it, a user could connect from an unmanaged app or browser that isn't subject to screen capture protection. Create a Conditional Access policy so that connections from Android, iOS/iPadOS, and the web client (on Windows) require a compliant app protection policy.

In the Microsoft Entra admin center, create a policy with the following settings:

Setting Value
Target resources > Resources (formerly cloud apps) Windows 365 for Windows 365, or Azure Virtual Desktop for Azure Virtual Desktop. You can also select all resources, but targeting the specific resource is recommended.
Grant Require app protection policy

Under Conditions, set the device platform and client app for each platform you want to protect:

Platform Device platforms Client apps
Android Android Mobile apps and desktop clients
iOS/iPadOS iOS Mobile apps and desktop clients
Web (Windows) Windows Browser

Assign the policy to the same users as the app protection policy.

Verify screen capture protection

To verify screen capture protection is working:

  1. Connect to a new remote session with a supported client. Don't reconnect to an existing session. You need to sign out of any existing sessions and sign back in again for the change to take effect.

  2. From a local device, take a screenshot or share your screen in a Teams call or meeting. The content is blocked or hidden.

  3. On Windows and macOS devices, if you enabled Block screen capture on client and server on your virtual machines or Cloud PCs, try to capture the screen using a tool or service within the virtual machine or Cloud PC. The content is blocked or hidden.

If you enable screen capture protection on virtual machines or Cloud PCs, you must connect from a supported device. If you don't, you see an error message indicating that screen capture protection is enabled. The error message looks similar to these screenshots:

  • Web browser:

    A screenshot from Windows App in a web browser showing an error message that screen capture is enabled and you need to connect from a supported client.

  • iOS/iPadOS:

    A screenshot from Windows App for iOS/iPadOS showing an error message that screen capture is enabled and you need to connect from a supported client.

Verify and troubleshoot Android or iOS/iPadOS hybrid enforcement

When admin-configured SCP is enabled, Android or iOS/iPadOS connections are only allowed if the MAM app protection policy also blocks screen capture (hybrid enforcement).

To verify Android or iOS/iPadOS hybrid enforcement is working:

  1. Confirm the Intune MAM app protection policy is applied to the user and device. In the Microsoft Intune admin center, check the app protection policy status for the user under Apps > Monitor > App protection status.

  2. On the Android or iOS/iPadOS device, sign out of Windows App and sign back in to pick up the latest policy settings.

  3. Connect to the remote session. If both the admin-configured SCP and the MAM policy block screen capture, the connection succeeds and screen capture is blocked.

If Android or iOS/iPadOS connections are blocked unexpectedly, check the following:

  • Verify the MAM app protection policy is assigned to the user and that Screen capture is set to Block.
  • Restart Windows App on the Android or iOS/iPadOS device or sign out and sign back in.
  • Confirm that the installed version of Windows App for Android or iOS/iPadOS supports hybrid enforcement.
  • Confirm the Android device isn't running ChromeOS or Meta Quest, which don't support Intune MAM.

Tip

If a user is blocked because the MAM policy isn't applied or doesn't block screen capture, recommend the following message to help them understand the issue:

"Your organization requires screen capture protection to be enforced on your device to connect to this remote session. Ensure you're using the Windows App from a managed device with an app protection policy that blocks screen capture. Contact your IT admin for assistance."