A unified data governance solution that helps manage, protect, and discover data across your organization
Hello Nancy,
The behaviour you're seeing is expected with modern Microsoft Purview Information Protection and Microsoft 365 apps.
The black-screen behaviour you previously experienced was associated with older AIP clients and their protection mechanisms. It wasn't a direct capability of the sensitivity label itself.
Microsoft has since moved away from the legacy AIP clients/add-ins towards native sensitivity labelling in Microsoft 365 Apps. With the modern Office experience, if a user is authorised to open and decrypt a protected document or email, the content is rendered normally on their screen. Consequently, Teams can capture that rendered content when the user shares their screen.
Effectively, being authorised to view protected content doesn't automatically mean the content is prevented from being screen-shared.
This is why an authorised presenter can potentially screen-share a "Highly Confidential" document to other meeting participants. It isn't necessarily a tenant configuration problem; it's a consequence of how the modern clients work.
To be thorough, there are two relevant Microsoft controls to consider:
- Teams Premium – Sensitive content detection during screen sharing
Teams Premium can detect certain supported sensitive information types while screen sharing. When sensitive content is detected, Teams can notify the presenter and meeting organiser and prompt the presenter to stop sharing.
This is a real-time screen-sharing control, rather than the old application-window black-out mechanism.
- Purview sensitivity labels for Teams meetings
Sensitivity labels can also be extended to Teams meetings and used to enforce controls such as who can present, who can record, video watermarking, and sensitive-content detection during screen sharing.
For highly sensitive meetings, Microsoft also provides meeting protection options such as restricting who can present and allowing organisers to control what attendees see.
Sensitivity labels protect the content based on the permissions you've defined. They don't automatically make an authorised user's screen invisible to Teams.
If your requirement is "an authorised user can open the document, but must not be able to expose it through screen sharing", I would suggest looking beyond the file's sensitivity label and consider the Teams meeting controls and sensitive-content detection available in your licensing and scenario. This is the suggested modern Microsoft approach rather than relying on the legacy AIP black-screen behaviour.
I hope this clarifies the issue you are experiencing.
Jim