Unexpected screen-sharing behaviour for encrypted Highly Confidential sensitivity-labelled content

Nancy Daniel 20 Reputation points
2026-09-14T10:33:12.3433333+00:00

Hello,

We would like to clarify an unexpected change we have observed in the behaviour of Microsoft Purview sensitivity-labelled and encrypted content when screen sharing in Microsoft Teams.

Background:

In our organisation, we have a sensitivity label called Highly Confidential (Högt Skyddsvärde). The label applies encryption/protection to files and emails, with access restricted to specifically authorised users.

Previously, when a user opened content protected with this label and shared their screen in a Teams meeting, the other meeting participants were unable to see the protected content. Instead, the area containing the protected email or document appeared as a black screen to the participants.

This behaviour was considered an additional protection against exposing highly sensitive content through screen sharing.

Initial observation:

Recently, we noticed that this behaviour appeared to have changed.

During a Teams meeting, when the user shared their screen while displaying an email and files classified as Highly Confidential, another meeting participant was able to see the actual content.

We therefore wanted to determine whether this was an intentional change introduced by Microsoft or whether there could be a configuration, Teams client, Office client, or Information Protection-related reason for the changed behaviour.

Test performed:

We subsequently performed a controlled test using:

  • An email classified as Highly Confidential
  • Documents classified as Highly Confidential
  • Encryption/protection enabled through the sensitivity label
  • Permissions restricted to only the two authorised users participating in the test
  • The authorised user opened the protected content and shared their screen in a Microsoft Teams meeting

A third participant, who was not granted direct access to the protected content, viewed the screen share

The current behaviour in our environment appears to differ from what we previously experienced. Therefore, we would appreciate confirmation of the expected behaviour and whether it represents an intentional Microsoft product change.

Thanks for your support!

Best regards,

Nancy Daniel

Microsoft Security | Microsoft Purview
0 comments No comments

1 answer

Sort by: Newest
  1. Jim 0 Reputation points
    2026-09-14T12:59:54.37+00:00

    Hello Nancy,

    The behaviour you're seeing is expected with modern Microsoft Purview Information Protection and Microsoft 365 apps.

    The black-screen behaviour you previously experienced was associated with older AIP clients and their protection mechanisms. It wasn't a direct capability of the sensitivity label itself.

    Microsoft has since moved away from the legacy AIP clients/add-ins towards native sensitivity labelling in Microsoft 365 Apps. With the modern Office experience, if a user is authorised to open and decrypt a protected document or email, the content is rendered normally on their screen. Consequently, Teams can capture that rendered content when the user shares their screen.

    Effectively, being authorised to view protected content doesn't automatically mean the content is prevented from being screen-shared.

    This is why an authorised presenter can potentially screen-share a "Highly Confidential" document to other meeting participants. It isn't necessarily a tenant configuration problem; it's a consequence of how the modern clients work.

    To be thorough, there are two relevant Microsoft controls to consider:

    1. Teams Premium – Sensitive content detection during screen sharing

    Teams Premium can detect certain supported sensitive information types while screen sharing. When sensitive content is detected, Teams can notify the presenter and meeting organiser and prompt the presenter to stop sharing.

    This is a real-time screen-sharing control, rather than the old application-window black-out mechanism.

    1. Purview sensitivity labels for Teams meetings

    Sensitivity labels can also be extended to Teams meetings and used to enforce controls such as who can present, who can record, video watermarking, and sensitive-content detection during screen sharing.

    For highly sensitive meetings, Microsoft also provides meeting protection options such as restricting who can present and allowing organisers to control what attendees see.

    Sensitivity labels protect the content based on the permissions you've defined. They don't automatically make an authorised user's screen invisible to Teams.

    If your requirement is "an authorised user can open the document, but must not be able to expose it through screen sharing", I would suggest looking beyond the file's sensitivity label and consider the Teams meeting controls and sensitive-content detection available in your licensing and scenario. This is the suggested modern Microsoft approach rather than relying on the legacy AIP black-screen behaviour.

    I hope this clarifies the issue you are experiencing.

    Jim

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.