- Protected PDF Rollout: Microsoft will roll out screenshot blocking for qualifying enterprise PDFs in OneDrive and SharePoint web viewers through Edge in August 2026.
- Label Requirement: Protection applies only to files carrying the relevant Microsoft Purview label, which restricts copying in supported applications.
- Open Capture Routes: Chrome, Firefox, Safari, mobile web, phone cameras, unmanaged devices, and unlabeled files remain outside the planned control.
- Administrator Controls: Administrators can disable downloads and steer protected access into managed Edge sessions, but Microsoft’s roadmap timing may change.
Microsoft plans to make Edge block screenshots of protected PDFs opened in OneDrive for Business and SharePoint Online web viewers. Expected in August 2026, the rollout applies to organizations using Microsoft Purview Information Protection, not personal OneDrive accounts.
Purview labels can already restrict editing, printing, and copying in supported desktop applications, while in 2024 Edge policies could prevent document screen captures. Browser viewing has not enforced those restrictions consistently. At general availability, Chrome, Firefox, Safari, and mobile web will not support the restriction; Edge will.
Organizations will need labels, managed devices, and browser policies to keep protected files in the supported route. Microsoft has not scheduled wider browser or mobile support.
For teams exchanging financial records, contracts, legal material, or unreleased product details, the change closes one route for copying sensitive documents. It does not decide who may open a file; existing access policies still do that. Capture protection applies only when the file policy, Microsoft 365 viewer, and Edge session all align, making browser choice part of how administrators enforce document rules.
How the Screenshot Block Works
Microsoft Purview Information Protection lets an organization attach persistent usage restrictions to a labeled file. Microsoft Purview sensitivity-label restrictions remain associated with the file across supported Microsoft 365 locations and applications. For this feature, the label must exclude the Copy, or EXTRACT, permission that allows content to be copied from a document.
Edge then checks three conditions: the PDF has a qualifying label, it is open in the OneDrive or SharePoint web viewer, and the browser session is running in Edge. Missing any condition leaves the operating system’s normal capture behavior available. Existing eligible labels will require no new setting after deployment, while ordinary PDFs, unlabeled files, and labels without the Copy restriction remain outside the control.
The planned control arrives on top of Edge’s Adobe Acrobat PDF engine, the browser’s built-in handler for business users. Inside the supported viewer, Edge can ask the operating system to reject a normal screen-capture request. File access rules continue to govern who can open the document, while the browser adds capture enforcement for that session.
Administrators can disable local downloads, preventing someone from saving a protected PDF and reopening it beyond the web viewer. Conditional Access policies can limit how and where protected files open, while browser-management policies can direct employees into managed Edge sessions. Those controls keep document access and capture behavior on the route where the restriction can operate.
File classification alone is not enough. Device access rules must cover the intended users, download restrictions must keep the document in the web viewer, and browser policy must steer access into Edge. If an unmanaged browsing route remains available, the same protected document can leave the session where capture enforcement applies.
Where Edge-Only Protection Stops
Phone cameras and unmanaged computers remain outside Edge’s control. Edge can reject an operating-system screenshot command, but software cannot stop someone from photographing the display or using an unmanaged device.
Employees and guests receive different protection for the same file when they move among Edge, rival browsers, mobile devices, and unmanaged hardware. A shared PDF opened outside the organization’s browser and device rules remains beyond administrator control. Organizations must bring those sessions under policy or accept that the screenshot block protects only the managed path.
What Administrators Should Verify
Microsoft will use an early deployment group, and later worldwide deployment in August 2026. Administrators can use that first phase to verify that qualifying labels trigger blocking, local downloads remain restricted, and managed access covers employees and guests who handle protected PDFs.
Microsoft cautions that roadmap dates can change before general availability. During Targeted Release in August 2026, administrators can test qualifying labels by checking that Edge rejects operating-system capture requests in the supported viewer.


