Starting by the end of August 2026, Microsoft will close a long-standing gap in its information protection controls: PDF files stored in OneDrive and SharePoint that carry a sensitivity label denying copy permissions will now block screen captures—but only when opened through Microsoft Edge. The rollout, first reported by Windows Latest and confirmed through a Microsoft 365 Message Center advisory, targets enterprise users, not consumers, and marks the first time Purview’s “Do Not Allow Screen Capture” setting is enforced in the web viewer.
What actually changed
Previously, an organization could label a PDF with Microsoft Purview Information Protection to restrict copying, but when that same file was viewed through the OneDrive or SharePoint web viewer in any browser, the screen capture restriction was not applied. Desktop applications respected the policy, but the browser experience left a hole. Microsoft is now updating the web viewer—specifically when rendered in Edge—to honor that restriction.
The change only affects PDFs that have a sensitivity label configured without the Copy (EXTRACT) permission. Standard, unlabeled PDFs are untouched. The restriction engages automatically based on the existing Purview label; administrators do not need to turn on a new switch. However, the enforcement relies entirely on the document’s label and the user’s browser.
Microsoft has not detailed the mechanism, but the end result is that Edge will either block the screenshot shortcut, show a black overlay, or otherwise prevent capture tools like Snipping Tool and Print Screen from grabbing visible content. This is not a guarantee against someone photographing the screen with a phone—no software can stop that—but it raises the barrier against accidental or convenience-driven leaks.
Browser and platform support at launch
| Browser / Platform | Screenshot Block Enforced? |
|---|---|
| Microsoft Edge (Windows, macOS) | Yes |
| Chrome, Firefox, other Chromium browsers | No (unsupported) |
| Mobile web (any browser) | No (unsupported) |
Microsoft’s advisory explicitly states that other browsers and mobile web are not supported at general availability. Users who open the same protected PDF outside Edge may not receive consistent enforcement.
What it means for you
For enterprise IT administrators
The burden shifts to ensuring that sensitive PDFs are accessed through Edge if screenshot protection is required. This isn’t a flip-a-switch moment—it demands a review of existing label configurations, browser management policies, and user workflows.
Because the enforcement is tied to the label, any PDF already tagged with a no-copy permission will suddenly behave differently in Edge. Helpdesk calls are likely: a user opens a PDF they’re authorized to read, tries to take a screenshot for a ticket or report, and finds it blocked. That will look like a malfunction unless you’ve communicated the change and provided alternatives.
Download permissions become critical. If a user can download the PDF and open it locally, the browser-level screenshot block means nothing. Administrators must consider whether to restrict downloads for those documents, or at least understand the residual risk.
For mixed-browser environments, this turns a document-protection decision into a browser-governance problem. You may need Conditional Access policies, Intune configuration, or Group Policy to steer users toward Edge for OneDrive and SharePoint access. BYOD and contractor scenarios add complexity, as unmanaged devices might default to other browsers.
For end users in regulated organizations
If you work in finance, legal, healthcare, or government, you may suddenly find that screenshots of certain PDFs stop working. This is not a bug; it’s the organization’s data protection policy now reaching the browser. You’ll need to learn the approved way to capture information for your job—whether that means requesting a redacted export, using a specific desktop application, or following a defined exception process. Your IT team should provide guidance before the rollout hits.
For consumers and home users
This change does not apply to you. OneDrive Personal and free SharePoint libraries are not part of the Purview ecosystem. Home users will not see screenshot blocking on personal PDFs, and no subscription to Microsoft 365 Family or Personal will trigger this behavior. The feature is strictly for organizations using Microsoft Purview Information Protection.
How we got here
Microsoft Purview Information Protection (formerly Azure Information Protection) has long allowed organizations to apply persistent rights management to documents, including blocking copy, print, and screen capture. These controls worked well in desktop Office apps and, more recently, in desktop PDF viewers that support Rights Management. But the web—the most common way people access OneDrive and SharePoint—remained a weak point.
A PDF restricted from copying in a desktop app could be freely screenshotted just by opening the same file in a browser. This gap frustrated compliance officers and security teams, especially in sectors where a screenshot of a sensitive HR document or financial report could be a serious data loss event.
Microsoft has been positioning Edge as the secure enterprise browser. The built-in viewing of “protected PDFs” on Windows and macOS already relied on Edge, but it didn’t enforce the screen capture restriction until now. The August 2026 update closes that gap, but only for the browser Microsoft controls. It’s a pragmatic first step—deliver the protection where Microsoft can guarantee the behavior, then expand later.
What to do now
With general availability expected by the end of August 2026, administrators should not wait for the rollout to hit production. Use this checklist to prepare:
-
Inventory your sensitivity labels
Identify every Purview label that denies Copy (EXTRACT) permission. Confirm that screen capture blocking is the intended outcome for those documents when viewed online. -
Test in a controlled environment
Open representative labeled PDFs through OneDrive and SharePoint in Edge using test accounts that represent internal employees and external guests. Verify that screenshots are blocked and that the behavior is consistent. Also check what happens when the same file is opened in Chrome or Firefox so you can document the difference for your support team. -
Decide on browser governance
If you need the protection to be reliable, evaluate whether to enforce Edge for accessing sensitive document libraries. Options include:
- Intune app protection policies or Windows settings to set Edge as default.
- Azure AD Conditional Access requiring Microsoft Edge for specific SharePoint sites.
- Group Policy or configuration profiles to restrict browser usage on managed devices. -
Update helpdesk scripts
Add a knowledge base article that describes the new behavior, including screenshots of what a blocked capture looks like. Explain that it is expected when a PDF label prohibits copying, and instruct agents on how to verify the label and guide the user to an approved alternative. -
Review download permissions
For each affected document class, check whether download is allowed. If it is, the screenshot block works only while the file is viewed online—once downloaded, it’s outside your control. Consider adjusting share settings or using the Azure Information Protection unified labeling client to enforce rights even on local copies. -
Communicate with users
Send a targeted notification to teams that regularly work with protected PDFs. Tell them why screenshots may stop working in Edge, what the policy is, and how to request a legitimate extract if needed. Avoid surprise.
Outlook
Microsoft has stated that support for other browsers and mobile platforms will be added later, but no timeline has been committed. This means Edge will be the only compliant viewer for the foreseeable future. Organizations with browser-diverse estates will need to manage the mismatch.
The feature is also a signal that Microsoft views Edge as the cornerstone of its enterprise security story, not just another browser. Future Purview enforcements may similarly debut in Edge first. For admins, that’s a reminder that browser choice isn’t merely a UX preference—it can directly affect data loss prevention posture.
While consumer availability has not been announced, such features sometimes trickle down later. But for now, home users won’t see any change.
The August 2026 rollout is a significant step toward consistent information protection across Microsoft 365, but it also highlights the complexities of browser-dependent security. By requiring Edge, Microsoft is strengthening its enterprise browser story, but for organizations with diverse browser environments, the protection is only as strong as the weakest browser their users open.