Skip to content

Commit 79bdde2

Browse files
committed
Updated for flow and clarity
1 parent 9631069 commit 79bdde2

File tree

3 files changed

+80
-59
lines changed

3 files changed

+80
-59
lines changed

articles/virtual-desktop/client-device-redirection-intune.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how to configure redirection settings for iOS/iPadOS Windows
44
ms.topic: how-to
55
author: dknappettmsft
66
ms.author: daknappe
7-
ms.date: 11/09/2024
7+
ms.date: 01/15/2025
88
---
99

1010
# Configure client device redirection settings for Windows App and the Remote Desktop app using Microsoft Intune
@@ -147,15 +147,15 @@ Before you can configure redirection settings on a client device using Microsoft
147147

148148
- A client device running one of the following versions of Windows App or the Remote Desktop app:
149149
- For Windows App:
150-
- iOS/iPadOS: 11.0.7 or later.
150+
- iOS/iPadOS: 11.0.8 or later.
151151
- Android: 1.0.145 or later.
152152

153153
- Remote Desktop app:
154154
- Android: 10.0.19.1279 or later.
155155

156156
- The latest version of:
157157
- iOS/iPadOS: Microsoft Authenticator app
158-
- Android: Company Portal app, installed in the same profile as Windows App for personal devices. Both app either in personal profile OR both apps in work profile.
158+
- Android: Company Portal app, installed in the same profile as Windows App for personal devices. Both apps need to either be in a personal profile or in a work profile, not one in each profile.
159159

160160
- There are more Intune prerequisites for configuring app configuration policies, app protection policies, and Conditional Access policies. For more information, see:
161161
- [App configuration policies for Microsoft Intune](/mem/intune/apps/app-configuration-policies-overview).
@@ -224,15 +224,15 @@ To create and apply an app protection policy, follow the steps in [How to create
224224

225225
- For iOS and iPadOS, you can configure the following settings:
226226

227-
- Send org data to other apps. Set to **None** to enable screen capture protection.
228-
- Restrict cut, copy, and paste between other apps
229-
- Third-party keyboards
227+
- **Send org data to other apps**. Set to **None** to enable [screen capture protection](screen-capture-protection.md).
228+
- **Restrict cut, copy, and paste between other apps**
229+
- **Third-party keyboards**
230230

231231
- For Android, you can configure the following settings:
232232

233-
- Restrict cut, copy, and paste between other apps
234-
- Screen capture and Google Assistant
235-
- Approved keyboards
233+
- **Restrict cut, copy, and paste between other apps**
234+
- **Screen capture and Google Assistant**
235+
- **Approved keyboards**
236236

237237
> [!TIP]
238238
> If you disable clipboard redirection in an app configuration policy, you should set **Restrict cut, copy, and paste between other apps** to **Blocked**.

articles/virtual-desktop/compare-remote-desktop-clients.md

Lines changed: 7 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ ms.topic: concept-article
55
zone_pivot_groups: remote-desktop-clients
66
author: dknappettmsft
77
ms.author: daknappe
8-
ms.date: 11/19/2024
8+
ms.date: 01/15/2025
99
---
1010

1111
# Compare Remote Desktop app features across platforms and devices
@@ -641,26 +641,21 @@ The following table shows which security features are available on each platform
641641

642642
| Feature | Windows<br />(MSI) | Windows<br />(AVD Store) | Windows<br />(RD Store) | macOS | iOS/<br />iPadOS | Android/<br />Chrome OS | Web browser |
643643
|--|:-:|:-:|:-:|:-:|:-:|:-:|:-:|
644-
| Screen capture protection ||||| | ||
644+
| Screen capture protection ||||| <sup>&#8197;&#8197;</sup>✅&sup1; | <sup>&#8197;&#8197;</sup>✅&sup1; ||
645645
| Watermarking ||||||||
646646

647+
1. Requires [Microsoft Intune to configure client device redirection settings](/azure/virtual-desktop/client-device-redirection-intune).
648+
647649
::: zone-end
648650

649-
::: zone pivot="windows-365"
651+
::: zone pivot="windows-365,dev-box"
650652

651653
| Feature | Windows<br />(MSI) | macOS | iOS/<br />iPadOS | Android/<br />Chrome OS | Web browser |
652654
|--|:-:|:-:|:-:|:-:|:-:|
653-
| Screen capture protection ||| | ||
655+
| Screen capture protection ||| <sup>&#8197;&#8197;</sup>✅&sup1; | <sup>&#8197;&#8197;</sup>✅&sup1; ||
654656
| Watermarking ||||||
655657

656-
::: zone-end
657-
658-
::: zone pivot="dev-box"
659-
660-
| Feature | Windows<br />(MSI) | macOS | iOS/<br />iPadOS | Android/<br />Chrome OS | Web browser |
661-
|--|:-:|:-:|:-:|:-:|:-:|
662-
| Screen capture protection ||||||
663-
| Watermarking ||||||
658+
1. Requires [Microsoft Intune to configure client device redirection settings](/azure/virtual-desktop/client-device-redirection-intune).
664659

665660
::: zone-end
666661

articles/virtual-desktop/screen-capture-protection.md

Lines changed: 64 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -4,44 +4,69 @@ description: Learn how to enable screen capture protection in Azure Virtual Desk
44
ms.topic: how-to
55
author: dknappettmsft
66
ms.author: daknappe
7-
ms.date: 06/28/2024
7+
ms.date: 01/15/2025
88
---
99

1010
# Enable screen capture protection in Azure Virtual Desktop
1111

12-
Screen capture protection, alongside [watermarking](watermarking.md), helps prevent sensitive information from being captured on client endpoints through a specific set of operating system (OS) features and Application Programming Interfaces (APIs). When you enable screen capture protection, remote content is automatically blocked in screenshots and screen sharing. You can configure screen capture protection using Microsoft Intune or Group Policy on your session hosts.
12+
Screen capture protection, alongside [watermarking](watermarking.md), helps prevent sensitive information from being captured on client endpoints through a specific set of operating system (OS) features and APIs. When you enable screen capture protection, remote content is automatically blocked in screenshots and screen sharing.
1313

14-
There are two supported scenarios for screen capture protection, depending on the version of Windows you're using:
14+
There are two supported scenarios for screen capture protection:
1515

16-
- **Block screen capture on client**: the session host instructs a supported Remote Desktop or Windows App client to enable screen capture protection for a remote session. This option prevents screen capture from the client of applications running in the remote session.
16+
- **Block screen capture on client**: prevents screen capture from the local device of applications running in the remote session.
1717

18-
- **Block screen capture on client and server**: the session host instructs a supported Remote Desktop client to enable screen capture protection for a remote session. This option prevents screen capture from the client of applications running in the remote session, but also prevents tools and services within the session host from capturing the screen.
18+
- **Block screen capture on client and server**: prevents screen capture from the local device of applications running in the remote session, but also prevents tools and services within the session host capturing the screen.
1919

20-
When screen capture protection is enabled, users can't share their Remote Desktop window using local collaboration software, such as Microsoft Teams. With Teams, neither the local Teams app or using [Teams with media optimization](teams-on-avd.md) can share protected content.
20+
When screen capture protection is enabled, users can't share their remote window using local collaboration software, such as Microsoft Teams. With Teams, neither the local Teams app or using [Teams with media optimization](teams-on-avd.md) can share protected content.
2121

2222
> [!TIP]
2323
> - To increase the security of your sensitive information, you should also disable clipboard, drive, and printer redirection. Disabling redirection helps prevent users from copying content from the remote session. To learn about supported redirection values, see [Device redirection](rdp-properties.md#device-redirection).
2424
>
2525
> - To discourage other methods of screen capture, such as taking a photo of a screen with a physical camera, you can enable [watermarking](watermarking.md), where admins can use a QR code to trace the session.
2626
27+
## Determine your configuration
28+
29+
The steps to configure screen capture protection depend on which platforms your users are connecting from:
30+
31+
- For Windows and macOS devices running Windows App or Remote Desktop client, you configure screen capture protection on session hosts using Intune or Group Policy. Windows App and the Remote Desktop client enforces screen capture protection settings from a session host without additional configuration.
32+
33+
- For iOS/iPadOS and Android devices running Windows App, you block screen capture on the local device by [configuring an Intune app protection policy](client-device-redirection-intune.md), part of [mobile application management](/mem/intune/fundamentals/deployment-plan-protect-apps) (MAM). If you also want to block screen capture from within the session host, you also need to configure screen capture protection on session hosts using Intune or Group Policy.
34+
35+
Here's a summary of the configuration steps needed for each platform:
36+
37+
| Platform | Block screen capture on client | Block screen capture on client and server |
38+
|--|--|--|
39+
| Windows | Configure session hosts with Intune or Group Policy | Configure session hosts with Intune or Group Policy |
40+
| macOS | Configure session hosts with Intune or Group Policy | Configure session hosts with Intune or Group Policy |
41+
| iOS/iPadOS | Configure the local device with Intune MAM | Configure the local device with Intune MAM and session hosts with Intune or Group Policy |
42+
| Android | Configure the local device with Intune MAM | Configure the local device with Intune MAM and session hosts with Intune or Group Policy |
43+
2744
## Prerequisites
2845

29-
- Your session hosts must be running one of the following versions of Windows to use screen capture protection:
46+
- For scenarios where you need to configure session hosts, those session hosts must be running a Windows 11, version 22H2 or later, or Windows 10, version 22H2 or later.
3047

31-
- **Block screen capture on client** is available with a [supported version of Windows 10 or Windows 11](prerequisites.md#operating-systems-and-licenses) or a [supported version of Windows App on iOS/iPadOS or Android using Intune MAM](/azure/virtual-desktop/client-device-redirection-intune)
32-
- **Block screen capture on client and server** is available starting with Windows 11, version 22H2.
48+
- Users must connect to Azure Virtual Desktop with Windows App or the Remote Desktop app to use screen capture protection. The following table shows supported scenarios:
3349

34-
- Users must connect to Azure Virtual Desktop with Windows App or the Remote Desktop app to use screen capture protection. The following table shows supported scenarios. If a user tries to connect with a different app or version, the connection is denied and shows an error message with the code `0x1151`.
50+
- Windows App:
51+
52+
| Platform | Minimum version | Desktop session | RemoteApp session |
53+
|--|--|--|--|
54+
| Windows App on Windows | Any | Yes | Yes. Local device OS must be Windows 11, version 22H2 or later. |
55+
| Windows App on macOS | Any | Yes | Yes |
56+
| Windows App on iOS/iPadOS | 11.0.8 | Yes | Yes |
57+
| Windows App on Android (preview)&sup1; | 1.0.145 | Yes | Yes |
3558

36-
| App | Version | Desktop session | RemoteApp session |
37-
|--|--|--|--|
38-
| Windows App on Windows | Any | Yes | Yes. Client device OS must be Windows 11, version 22H2 or later. |
39-
| Remote Desktop client on Windows | 1.2.1672 or later | Yes | Yes. Client device OS must be Windows 11, version 22H2 or later. |
40-
| Azure Virtual Desktop Store app | Any | Yes | Yes. Client device OS must be Windows 11, version 22H2 or later. |
41-
| Windows App on macOS | Any | Yes | Yes |
42-
| Windows App on iOS/iPadOS | 11.0.7 or later | Yes | Yes |
43-
| Windows App (Preview) on Android | 1.0.145 | Yes | Yes |
44-
| Remote Desktop client on macOS | 10.7.0 or later | Yes | Yes |
59+
1. Doesn't include support for Chrome OS.
60+
61+
- Remote Desktop client:
62+
63+
| Platform | Minimum version | Desktop session | RemoteApp session |
64+
|--|--|--|--|
65+
| Windows (desktop client) | 1.2.1672 | Yes | Yes. Local device OS must be Windows 11, version 22H2 or later. |
66+
| Windows (Azure Virtual Desktop Store app) | Any | Yes | Yes. Local device OS must be Windows 11, version 22H2 or later. |
67+
| macOS | 10.7.0 or later | Yes | Yes |
68+
69+
If a user tries to connect with a different app or version, such as Windows App in a web browser, the connection is denied and shows an error message with the code `0x1151`.
4570

4671
- To configure Microsoft Intune, you need:
4772

@@ -55,13 +80,13 @@ When screen capture protection is enabled, users can't share their Remote Deskto
5580

5681
- A security group or organizational unit (OU) containing the devices you want to configure.
5782

58-
## Enable screen capture protection
83+
## Enable screen capture protection on session hosts
5984

60-
Screen capture protection is configured on session hosts and enforced by the client. Select the relevant tab for your scenario.
85+
Select the relevant tab for your scenario.
6186

62-
# [Microsoft Intune (Windows)](#tab/intune)
87+
# [Microsoft Intune](#tab/intune)
6388

64-
To configure screen capture protection using Microsoft Intune:
89+
To configure screen capture protection on session hosts using Microsoft Intune:
6590

6691
1. Sign in to the [Microsoft Intune admin center](https://endpoint.microsoft.com/).
6792

@@ -89,9 +114,9 @@ To configure screen capture protection using Microsoft Intune:
89114

90115
1. Once the policy applies to the computers providing a remote session, restart them for the settings to take effect.
91116

92-
# [Group Policy (Windows)](#tab/group-policy)
117+
# [Group Policy](#tab/group-policy)
93118

94-
To configure screen capture protection using Group Policy:
119+
To configure screen capture protection on session hosts using Group Policy:
95120

96121
1. Follow the steps to make the [Administrative template for Azure Virtual Desktop](administrative-template.md) available in Group Policy.
97122

@@ -111,35 +136,36 @@ To configure screen capture protection using Group Policy:
111136

112137
1. Ensure the policy is applied to the computers providing a remote session, then restart them for the settings to take effect.
113138

114-
# [iOS/iPadOS](#tab/iOS)
139+
---
115140

116-
To configure screen capture protection using Intune App Protection Policies:
141+
## Enable screen capture protection on local devices
117142

118-
1. Follow the steps to create an [App protection policy](/azure/virtual-desktop/client-device-redirection-intune) for your device.
143+
To use screen capture protection on iOS/iPadOS and Android devices running Windows App, you need to configure an Intune app protection policy.
119144

120-
1. On the **Data protection** tab, set **Send org data to other apps** with a value of **None**.
145+
> [!TIP]
146+
> On Windows and macOS, Windows App and the Remote Desktop client enforces screen capture protection settings from a session host without additional configuration.
121147
122-
1. Configure other settings as needed and target the App Protection Policy to users and devices as listed in [App protection policy](/azure/virtual-desktop/client-device-redirection-intune).
148+
To configure an Intune app protection policy to enable screen capture protection on iOS/iPadOS and Android devices:
123149

124-
# [Android](#tab/Android)
150+
1. Follow the steps to [Configure client device redirection settings for Windows App and the Remote Desktop app using Microsoft Intune](client-device-redirection-intune.md). Configuration of screen capture protection is part of an [app protection policy](client-device-redirection-intune.md#create-an-app-protection-policy).
125151

126-
To configure screen capture protection using Intune App Protection Policies:
152+
1. When configuring an app protection policy, on the **Data protection** tab, configure the following setting, depending on the platform:
127153

128-
1. Follow the steps to create an [App protection policy](/azure/virtual-desktop/client-device-redirection-intune) for your device.
154+
1. For iOS/iPadOS, set **Send org data to other apps** to **None**.
129155

130-
1. On the **Data protection** tab, set **Screen capture and Google Assistant** to **Block**.
156+
1. For Android, set **Screen capture and Google Assistant** to **Block**.
131157

132-
1. Configure other settings as needed and target the App Protection Policy to users and devices as listed in [App protection policy](/azure/virtual-desktop/client-device-redirection-intune).
133-
---
158+
1. Configure other settings based on your requirements and target the app protection policy to users and devices.
134159

135160
## Verify screen capture protection
136161

137162
To verify screen capture protection is working:
138163

139-
1. Connect to a remote session with a supported client.
164+
1. Connect to a new remote session with a supported client. Don't reconnect to an existing session. You need to sign out of any existing sessions and sign back in again for the change to take effect.
140165

141-
1. Take a screenshot or share your screen in a Teams call or meeting. The content should be blocked or hidden. Any existing sessions need to sign out and back in again for the change to take effect.
166+
1. From a local device, take a screenshot or share your screen in a Teams call or meeting. The content should be blocked or hidden.
142167

168+
1. If you enabled **Block screen capture on client and server** on your session hosts, try to capture the screen using a tool or service within the session host. The content should be blocked or hidden.
143169

144170
## Related content
145171

0 commit comments

Comments
 (0)