Screen Sharing and Capture Data Loss Prevention Policy

The Screen Sharing and Capture Desktop and Laptop Data Loss Prevention (DLP) Policy controls the use of screen sharing and screenshots/print screen inside Venn's Blue Border.

This policy is only enforced on Windows devices. 

As a Company Manager, you can determine whether or not users are able to share, record, or capture their screen while working in Blue Border as part of your Default Policy that applies to all users. You can also create Policy Overrides to change these settings for specific users or groups as needed.

Learn how to manage Default Data Loss Prevention Policies and Overrides.

View and Manage Your Screen Sharing and Capture Data Loss Prevention Policies

To view and manage your Screen Sharing and Capture DLP Policies:

  1. Navigate to the Admin Portal.
    • In your browser, go to https://login.venn.com/ and sign in if prompted. Then, click Open Admin Portal.
    • From the desktop app, click the Open web app icon.png Open web app icon. Then, click Company Admin in the top right.
  2. Click Policy Admin and select DLP Policy in the left menu. 

You will see your default Screen Sharing and Capture policy applied to all users under Default policy.

DLP Policy Admin_Screen sharing and capture.png
  • To view details or make adjustments to the default policy, click Edit icon.pngEdit.
  • You will see any policy exceptions under Policy overrides. Check to see if any of your Policy Overrides include a different Screen Sharing and Capture setting. To view details or make adjustments, click Edit icon.pngEdit next to the Policy Override.
  • You can also add additional Policy Overrides, which allow you to set DLP Policies that supersede the default policy for a single user or a group of users, as needed. For example, if users with a particular role in your organization need to have their screensharing unrestricted, you may want to set up a Policy Override that unrestricts their Screen sharing policy rather than unrestricting it for all users. 

Learn how to manage Default Data Loss Prevention Policies and Overrides.

Enable the Screen Sharing and Capture Policy

As a Company Manager, click the toggle next to Block screen share and capture to enable the Screen sharing and capture policy. Once you click Apply, users will not be able to share, record, or screenshot app windows open in Blue Border.

Screen share and capture Policy Modal.png

If you toggle on Block screen share and capture, you will see additional options:

  • Allow with justification: When selected, users will be able to enable screen sharing and capture if they provide a reason for sharing Blue Border windows. 
  • Enable exceptions for specific apps: When selected, you can enable exceptions to a restricted screen sharing and capture policy for specific apps. This option is typically used to allow employee monitoring or remote support tools to view and record inside Blue Border.

Allow Screen Sharing with Justification

If you block screen sharing and capture, users will not be able to share their windows open in Blue Border on video calls or take any screenshots of windows open in Blue Border. This will prevent them from sharing or capturing their screen even for legitimate business purposes (e.g., presenting in virtual meetings or recording computer behavior for technical troubleshooting support).

In most cases, we recommend checking Allow with justification so that users can share or capture their screen if they provide a business reason.

Learn how this works for end users.

Enable Third-Party Apps to View and Record Inside Blue Border When Screen Sharing and Capture is Blocked

If you block screen sharing and capture, you can enable exceptions to this policy for specific apps. These exceptions are typically used to allow third-party apps such as employee monitoring or remote support tools to view and record inside Blue Border.

To register third-party apps that you would like to enable to capture inside Blue Border:

  1. Navigate to the Admin Portal.
    1. In your browser, go to https://login.venn.com/ and sign in if prompted. Then, click Open Admin Portal.
    2. From the desktop app, click the Open web app icon.png Open web app icon. Then, click Company Admin in the top right.
  2. Click Policy Admin and select DLP Policy in the left menu. 
  3. Open the Screen sharing and capture policy that you would like to apply the exception to.
    • To update your default policy, click Edit icon.pngEdit next to Screen sharing and capture.
    • To update a policy override, click Edit icon.pngEdit next to the override to apply the exception only to that user or group.
    • If you need to create a new policy override that includes this exception, follow these instructions.
  4. Check the box next to Enable exceptions for specific aps.

    This option will only be available if you have enabled the policy. Otherwise, the third-party apps will be able to record inside Blue Border without creating an exception.
  5. Click Add application.

    Screen sharing and capture_Register new app.jpg
  6. Complete the registration fields and click Add.
    • Enter the name of the app.
    • Enter the thumbprint(s) of the app (see identify app thumbprints below for help locating the app thumbprints).
    • Select the appropriate app category.Screen sharing and capture_App registration.jpg
  7. Click Apply.

You can make adjustments to your registered app configurations by clicking  Edit icon.pngEdit next to the app name or remove an app by clicking Delete icon.png Delete.

Identify App Thumbprints

You can identify the Windows executable’s Signer Certificate Thumbprint for the app that you would like to apply this exception to in two ways: 

Find the Thumbprint via GUI

  1. Find the executable in Windows Explorer.
  2. Right-click the file and click Properties.
  3. Go to the Digital Signatures tab, click on the listed signature, then click Details.
    • If there are multiple signatures, you'll see more than one listed. Follow the steps below to identify the thumbprint for each signature.

      Screenshot 2024-04-16 140426.png

  4. In the new window that opens, click View Certificate.

    Screenshot 2024-04-16 140937.png

  5. In the new window that opens, go to the Details tab. Scroll through the list of fields and click Thumbprint.
  6. The value that appears in the field below is the Thumbprint.

    Screenshot 2024-04-16 141132.png

Find the Thumbprint via PowerShell

  1. Open PowerShell.
  2. Run the following command, replacing the path with the actual file location of the executable.

    Get-AuthenticodeSignature -FilePath "C:\Path\To\YourApp.exe"
  3. Look for the SignerCertificate section in the output.

    mceclip3.png

Was this article helpful?