BlogScreenshots on your device
How to Take a Screenshot in Windows VDI
Learn how to capture permitted content in Windows VDI, understand black screenshots, and troubleshoot Screen Capture Protection.
First check whether screenshots are permitted. In Azure Virtual Desktop and Windows 365, an administrator can enable Screen Capture Protection. When enabled, screenshots taken on the local device can show black or hidden remote content, and there is no universal shortcut that overrides the policy.
If capture is allowed, use the screenshot function provided by your Windows or remote-desktop client. The exact keys depend on the client and operating system, so confirm the current shortcut in your client documentation or with your VDI administrator.
1. Confirm your organization allows screenshots
Ask your VDI administrator these questions before trying to capture anything:
- Is Screen Capture Protection enabled for this Azure Virtual Desktop session host or Windows 365 Cloud PC?
- Is the policy set to Block screen capture on client or Block screen capture on client and server?
- Is my Windows, macOS, mobile, web, or other client supported for this configuration?
- Is there an approved export, support workflow, or exception for this information?
Microsoft documents Screen Capture Protection for Azure Virtual Desktop VMs and Windows 365 Cloud PCs. On Windows and macOS endpoints, administrators configure the session host or Cloud PC through Intune device configuration policy or Group Policy, and Windows App or the Remote Desktop client enforces the setting. Other platforms have additional requirements, so verify support for the client you use. Microsoft’s support and configuration matrix is the authoritative reference.
2. Use the permitted screenshot method
Capture the entire local display
- Open the approved VDI session and arrange the remote window as required.
- Use your operating system’s supported full-screen capture command or the screenshot utility supplied with your device.
- Save the result locally only where your organization’s policy permits it.
- Check the image for black regions, missing remote content, or a policy notification.
Capture a selected area or window
Use the region or window mode in your operating system’s screenshot utility when your policy allows partial capture. This can reduce accidental exposure of unrelated applications, but it does not bypass Screen Capture Protection. A protected remote window can remain blank even when the rest of the desktop is captured.
Capture from inside the virtual machine
This depends on the configured scope. With Block screen capture on client, the local device is blocked from capturing remote applications, while tools running inside the VM may still work if separately permitted. With Block screen capture on client and server, Microsoft also blocks capture tools and services inside the remote VM or Cloud PC. Do not assume that moving the screenshot utility into the VM will work.
Only test an in-VM capture when your administrator has explicitly approved it. The stronger policy is intended to cover both locations.
3. Understand the two protection scopes
| Policy | What it blocks | Where to verify |
|---|---|---|
| Block screen capture on client | Capture from the local device of applications running remotely | Your local screenshot tool and screen-sharing software |
| Block screen capture on client and server | Local capture plus screenshot tools and services inside the VM or Cloud PC | Both the endpoint and the remote session |
Microsoft says Screen Capture Protection blocks standard operating-system features and APIs, but it is not DRM-level protection. Treat it as one layer in a broader data-protection plan; it does not make information impossible to copy. Watermarking can discourage photographing a display with a physical camera, while restricting clipboard, drive, printer, USB, and other redirection paths reduces digital transfer routes. See Microsoft’s protection guidance.
4. Do not confuse screenshots with clipboard redirection
Clipboard redirection is a separate data path. It controls whether users can copy and paste text, images, and files between the local device and the remote session. An administrator can block transfer in one or both directions or limit which data types are allowed.
RDP redirection policies can also govern webcams, USB devices, printers, drives, and other resources. Settings may be applied with Intune or Group Policy, in an .rdp file, or through Azure Virtual Desktop and Remote Desktop Services broker properties. The most restrictive applicable setting takes precedence. Read Microsoft’s documentation for clipboard direction and data types and RDP peripheral and resource redirection.
5. Troubleshoot a black or blocked screenshot
The screenshot is black, blank, or missing only the VDI window
Cause: Screen Capture Protection may be enabled, or the client may be enforcing a protected session.
Fix: Ask your VDI administrator which policy scope is configured. Do not try to defeat the control. Request an approved export or exception if you need the content for support, documentation, or compliance work.
The administrator changed the policy but capture still fails
Cause: The policy may not have reached the session host, or your existing session still has the old configuration.
Fix: The administrator should apply the policy, restart the relevant session-host computers when required, and verify with a new session. Sign out of existing sessions completely, then sign in again before retesting.
The remote client refuses to connect under protection
Cause: The endpoint or client connection may not meet the configured protection requirements. Microsoft notes that unsupported clients can show an error or fail to connect under protected conditions.
Fix: Record the client name, version, operating system, and connection type. Give those details to IT and ask which supported Windows App, Remote Desktop client, browser, or managed mobile configuration you should use.
Copy and paste works, but screenshots do not
Cause: Clipboard policy and screenshot policy are independent mechanisms.
Fix: Ask IT to check Screen Capture Protection separately from clipboard transfer direction and data-type policies. A permitted clipboard path does not imply permitted screenshots.
An authorized capture is still blocked
Fix: Use your organization’s approved export, ticket, or exception process. Include the session host or Cloud PC, client platform, time of the attempt, and whether the result was black, partially blank, or accompanied by an error.
6. Reliability, privacy, and operational notes
- Policy is authoritative: A local shortcut cannot override an administrator-enforced capture block.
- Session state matters: Policy changes commonly require a new connection; an old session can retain prior behavior.
- Client compatibility matters: Desktop, web, macOS, mobile, and managed-device connections can have different support requirements.
- Minimize exposure: Capture only the required region, close unrelated windows, and store the file in an approved location.
- Redirection is separate: Review clipboard, drive, printer, USB, and peripheral controls when the goal is to prevent data transfer rather than only screenshots.
- No universal shortcut: Do not publish or rely on one key sequence for every VDI product.
7. Or skip the browser setup
If the thing you need to capture is a public web page rather than protected pixels inside your VDI session, ScreenshotNeo provides a one-request website screenshot API. It is not a way around Screen Capture Protection and cannot capture private VDI content that its servers cannot access.
ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
See the ScreenshotNeo API documentation for all options, including full-page capture, CSS selectors, device presets, custom JavaScript and CSS, waits, request blocking, headers, cookies, geolocation, PDFs, caching, signed links, async jobs, bulk capture, and usage reporting.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot failed: ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));
The free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots, and every feature is available on every plan. Create a free ScreenshotNeo account.
FAQ
Can my company block screenshots in VDI?
Yes. Azure Virtual Desktop and Windows 365 provide Screen Capture Protection policies that block local capture, or local and in-VM capture, depending on the selected scope.
Why is only the remote window black?
The client is likely protecting remote content while allowing the local desktop to be captured. Confirm the policy and client support with IT.
Does disabling clipboard allow screenshots?
No. Clipboard redirection and screenshot capture are separate controls.
Is Screen Capture Protection DRM?
No. Microsoft explicitly says it does not provide DRM-level protection. Use defense in depth.
Will a browser screenshot extension bypass VDI protection?
You should not attempt to bypass an administrator control. Browser extensions also vary by client and may be blocked or unsupported.


