You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/virtual-desktop/client-device-redirection-intune.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Learn how to configure redirection settings for iOS/iPadOS Windows
4
4
ms.topic: how-to
5
5
author: dknappettmsft
6
6
ms.author: daknappe
7
-
ms.date: 11/09/2024
7
+
ms.date: 01/15/2025
8
8
---
9
9
10
10
# Configure client device redirection settings for Windows App and the Remote Desktop app using Microsoft Intune
@@ -147,15 +147,15 @@ Before you can configure redirection settings on a client device using Microsoft
147
147
148
148
- A client device running one of the following versions of Windows App or the Remote Desktop app:
149
149
- For Windows App:
150
-
- iOS/iPadOS: 11.0.7 or later.
150
+
- iOS/iPadOS: 11.0.8 or later.
151
151
- Android: 1.0.145 or later.
152
152
153
153
- Remote Desktop app:
154
154
- Android: 10.0.19.1279 or later.
155
155
156
156
- The latest version of:
157
157
- iOS/iPadOS: Microsoft Authenticator app
158
-
- Android: Company Portal app, installed in the same profile as Windows App for personal devices. Both app either in personal profile OR both apps in work profile.
158
+
- Android: Company Portal app, installed in the same profile as Windows App for personal devices. Both apps need to either be in a personal profile or in a work profile, not one in each profile.
159
159
160
160
- There are more Intune prerequisites for configuring app configuration policies, app protection policies, and Conditional Access policies. For more information, see:
161
161
-[App configuration policies for Microsoft Intune](/mem/intune/apps/app-configuration-policies-overview).
@@ -224,15 +224,15 @@ To create and apply an app protection policy, follow the steps in [How to create
224
224
225
225
- For iOS and iPadOS, you can configure the following settings:
226
226
227
-
- Send org data to other apps. Set to **None** to enable screen capture protection.
228
-
- Restrict cut, copy, and paste between other apps
229
-
- Third-party keyboards
227
+
-**Send org data to other apps**. Set to **None** to enable [screen capture protection](screen-capture-protection.md).
228
+
-**Restrict cut, copy, and paste between other apps**
229
+
-**Third-party keyboards**
230
230
231
231
- For Android, you can configure the following settings:
232
232
233
-
- Restrict cut, copy, and paste between other apps
234
-
- Screen capture and Google Assistant
235
-
- Approved keyboards
233
+
-**Restrict cut, copy, and paste between other apps**
234
+
-**Screen capture and Google Assistant**
235
+
-**Approved keyboards**
236
236
237
237
> [!TIP]
238
238
> If you disable clipboard redirection in an app configuration policy, you should set **Restrict cut, copy, and paste between other apps** to **Blocked**.
Copy file name to clipboardExpand all lines: articles/virtual-desktop/screen-capture-protection.md
+64-38Lines changed: 64 additions & 38 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,44 +4,69 @@ description: Learn how to enable screen capture protection in Azure Virtual Desk
4
4
ms.topic: how-to
5
5
author: dknappettmsft
6
6
ms.author: daknappe
7
-
ms.date: 06/28/2024
7
+
ms.date: 01/15/2025
8
8
---
9
9
10
10
# Enable screen capture protection in Azure Virtual Desktop
11
11
12
-
Screen capture protection, alongside [watermarking](watermarking.md), helps prevent sensitive information from being captured on client endpoints through a specific set of operating system (OS) features and Application Programming Interfaces (APIs). When you enable screen capture protection, remote content is automatically blocked in screenshots and screen sharing. You can configure screen capture protection using Microsoft Intune or Group Policy on your session hosts.
12
+
Screen capture protection, alongside [watermarking](watermarking.md), helps prevent sensitive information from being captured on client endpoints through a specific set of operating system (OS) features and APIs. When you enable screen capture protection, remote content is automatically blocked in screenshots and screen sharing.
13
13
14
-
There are two supported scenarios for screen capture protection, depending on the version of Windows you're using:
14
+
There are two supported scenarios for screen capture protection:
15
15
16
-
-**Block screen capture on client**: the session host instructs a supported Remote Desktop or Windows App client to enable screen capture protection for a remote session. This option prevents screen capture from the client of applications running in the remote session.
16
+
-**Block screen capture on client**: prevents screen capture from the local device of applications running in the remote session.
17
17
18
-
-**Block screen capture on client and server**: the session host instructs a supported Remote Desktop client to enable screen capture protection for a remote session. This option prevents screen capture from the client of applications running in the remote session, but also prevents tools and services within the session host from capturing the screen.
18
+
-**Block screen capture on client and server**: prevents screen capture from the local device of applications running in the remote session, but also prevents tools and services within the session host capturing the screen.
19
19
20
-
When screen capture protection is enabled, users can't share their Remote Desktop window using local collaboration software, such as Microsoft Teams. With Teams, neither the local Teams app or using [Teams with media optimization](teams-on-avd.md) can share protected content.
20
+
When screen capture protection is enabled, users can't share their remote window using local collaboration software, such as Microsoft Teams. With Teams, neither the local Teams app or using [Teams with media optimization](teams-on-avd.md) can share protected content.
21
21
22
22
> [!TIP]
23
23
> - To increase the security of your sensitive information, you should also disable clipboard, drive, and printer redirection. Disabling redirection helps prevent users from copying content from the remote session. To learn about supported redirection values, see [Device redirection](rdp-properties.md#device-redirection).
24
24
>
25
25
> - To discourage other methods of screen capture, such as taking a photo of a screen with a physical camera, you can enable [watermarking](watermarking.md), where admins can use a QR code to trace the session.
26
26
27
+
## Determine your configuration
28
+
29
+
The steps to configure screen capture protection depend on which platforms your users are connecting from:
30
+
31
+
- For Windows and macOS devices running Windows App or Remote Desktop client, you configure screen capture protection on session hosts using Intune or Group Policy. Windows App and the Remote Desktop client enforces screen capture protection settings from a session host without additional configuration.
32
+
33
+
- For iOS/iPadOS and Android devices running Windows App, you block screen capture on the local device by [configuring an Intune app protection policy](client-device-redirection-intune.md), part of [mobile application management](/mem/intune/fundamentals/deployment-plan-protect-apps) (MAM). If you also want to block screen capture from within the session host, you also need to configure screen capture protection on session hosts using Intune or Group Policy.
34
+
35
+
Here's a summary of the configuration steps needed for each platform:
36
+
37
+
| Platform | Block screen capture on client | Block screen capture on client and server |
38
+
|--|--|--|
39
+
| Windows | Configure session hosts with Intune or Group Policy | Configure session hosts with Intune or Group Policy |
40
+
| macOS | Configure session hosts with Intune or Group Policy | Configure session hosts with Intune or Group Policy |
41
+
| iOS/iPadOS | Configure the local device with Intune MAM | Configure the local device with Intune MAM and session hosts with Intune or Group Policy |
42
+
| Android | Configure the local device with Intune MAM | Configure the local device with Intune MAM and session hosts with Intune or Group Policy |
43
+
27
44
## Prerequisites
28
45
29
-
-Your session hostsmust be running one of the following versions of Windows to use screen capture protection:
46
+
-For scenarios where you need to configure session hosts, those session hosts must be running a Windows 11, version 22H2 or later, or Windows 10, version 22H2 or later.
30
47
31
-
-**Block screen capture on client** is available with a [supported version of Windows 10 or Windows 11](prerequisites.md#operating-systems-and-licenses) or a [supported version of Windows App on iOS/iPadOS or Android using Intune MAM](/azure/virtual-desktop/client-device-redirection-intune)
32
-
-**Block screen capture on client and server** is available starting with Windows 11, version 22H2.
48
+
- Users must connect to Azure Virtual Desktop with Windows App or the Remote Desktop app to use screen capture protection. The following table shows supported scenarios:
33
49
34
-
- Users must connect to Azure Virtual Desktop with Windows App or the Remote Desktop app to use screen capture protection. The following table shows supported scenarios. If a user tries to connect with a different app or version, the connection is denied and shows an error message with the code `0x1151`.
| Windows (desktop client) | 1.2.1672 | Yes | Yes. Local device OS must be Windows 11, version 22H2 or later. |
66
+
| Windows (Azure Virtual Desktop Store app) | Any | Yes | Yes. Local device OS must be Windows 11, version 22H2 or later. |
67
+
| macOS | 10.7.0 or later | Yes | Yes |
68
+
69
+
If a user tries to connect with a different app or version, such as Windows App in a web browser, the connection is denied and shows an error message with the code `0x1151`.
45
70
46
71
- To configure Microsoft Intune, you need:
47
72
@@ -55,13 +80,13 @@ When screen capture protection is enabled, users can't share their Remote Deskto
55
80
56
81
- A security group or organizational unit (OU) containing the devices you want to configure.
57
82
58
-
## Enable screen capture protection
83
+
## Enable screen capture protection on session hosts
59
84
60
-
Screen capture protection is configured on session hosts and enforced by the client. Select the relevant tab for your scenario.
85
+
Select the relevant tab for your scenario.
61
86
62
-
# [Microsoft Intune (Windows)](#tab/intune)
87
+
# [Microsoft Intune](#tab/intune)
63
88
64
-
To configure screen capture protection using Microsoft Intune:
89
+
To configure screen capture protection on session hosts using Microsoft Intune:
65
90
66
91
1. Sign in to the [Microsoft Intune admin center](https://endpoint.microsoft.com/).
67
92
@@ -89,9 +114,9 @@ To configure screen capture protection using Microsoft Intune:
89
114
90
115
1. Once the policy applies to the computers providing a remote session, restart them for the settings to take effect.
91
116
92
-
# [Group Policy (Windows)](#tab/group-policy)
117
+
# [Group Policy](#tab/group-policy)
93
118
94
-
To configure screen capture protection using Group Policy:
119
+
To configure screen capture protection on session hosts using Group Policy:
95
120
96
121
1. Follow the steps to make the [Administrative template for Azure Virtual Desktop](administrative-template.md) available in Group Policy.
97
122
@@ -111,35 +136,36 @@ To configure screen capture protection using Group Policy:
111
136
112
137
1. Ensure the policy is applied to the computers providing a remote session, then restart them for the settings to take effect.
113
138
114
-
# [iOS/iPadOS](#tab/iOS)
139
+
---
115
140
116
-
To configure screen capture protection using Intune App Protection Policies:
141
+
## Enable screen capture protection on local devices
117
142
118
-
1. Follow the steps to create an [App protection policy](/azure/virtual-desktop/client-device-redirection-intune) for your device.
143
+
To use screen capture protection on iOS/iPadOS and Android devices running Windows App, you need to configure an Intune app protection policy.
119
144
120
-
1. On the **Data protection** tab, set **Send org data to other apps** with a value of **None**.
145
+
> [!TIP]
146
+
> On Windows and macOS, Windows App and the Remote Desktop client enforces screen capture protection settings from a session host without additional configuration.
121
147
122
-
1. Configure other settings as needed and target the App Protection Policy to users and devices as listed in [App protection policy](/azure/virtual-desktop/client-device-redirection-intune).
148
+
To configure an Intune app protection policy to enable screen capture protection on iOS/iPadOS and Android devices:
123
149
124
-
# [Android](#tab/Android)
150
+
1. Follow the steps to [Configure client device redirection settings for Windows App and the Remote Desktop app using Microsoft Intune](client-device-redirection-intune.md). Configuration of screen capture protection is part of an [app protection policy](client-device-redirection-intune.md#create-an-app-protection-policy).
125
151
126
-
To configure screen capture protection using Intune App Protection Policies:
152
+
1. When configuring an app protection policy, on the **Data protection** tab, configure the following setting, depending on the platform:
127
153
128
-
1.Follow the steps to create an [App protection policy](/azure/virtual-desktop/client-device-redirection-intune) for your device.
154
+
1.For iOS/iPadOS, set **Send org data to other apps** to **None**.
129
155
130
-
1. On the **Data protection** tab, set **Screen capture and Google Assistant** to **Block**.
156
+
1. For Android, set **Screen capture and Google Assistant** to **Block**.
131
157
132
-
1. Configure other settings as needed and target the App Protection Policy to users and devices as listed in [App protection policy](/azure/virtual-desktop/client-device-redirection-intune).
133
-
---
158
+
1. Configure other settings based on your requirements and target the app protection policy to users and devices.
134
159
135
160
## Verify screen capture protection
136
161
137
162
To verify screen capture protection is working:
138
163
139
-
1. Connect to a remote session with a supported client.
164
+
1. Connect to a new remote session with a supported client. Don't reconnect to an existing session. You need to sign out of any existing sessions and sign back in again for the change to take effect.
140
165
141
-
1.Take a screenshot or share your screen in a Teams call or meeting. The content should be blocked or hidden. Any existing sessions need to sign out and back in again for the change to take effect.
166
+
1.From a local device, take a screenshot or share your screen in a Teams call or meeting. The content should be blocked or hidden.
142
167
168
+
1. If you enabled **Block screen capture on client and server** on your session hosts, try to capture the screen using a tool or service within the session host. The content should be blocked or hidden.
0 commit comments