Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article documents the ADMX policy setting for managing the integrated privacy screen on supported Surface for Business devices. The privacy screen helps protect sensitive information from visual hacking by limiting side-angle viewing of the device display.
Prerequisites
- Surface Laptop 8th Edition with Integrated Privacy Screen
- Windows 11
Surface Display Privacy Setting
By configuring this policy setting, you can manage the Integrated Privacy Screen feature on supported Surface for Business devices. The privacy screen helps protect sensitive information from visual hacking by limiting side-angle viewing of the device display.
When this policy is enabled, you can specify whether the privacy screen is turned on or off by default and whether end users can change the setting. This policy applies only to eligible Surface for Business devices that have the Integrated Privacy Screen.
Policy settings
| Setting | Description |
|---|---|
| Not Configured / Disabled (initial value) | The privacy screen is off by default. Users can manually enable or disable the feature using the Surface App or the F1 key. |
| Enabled – Off by Default | The privacy screen is disabled by default. Users can turn it on or off using the Surface App or the F1 key. The last user-selected state persists after reboot or wake. |
| Enabled – On by Default | The privacy screen is enabled by default. Users can turn it off or on using the Surface App or the F1 key. The last user-selected state persists after reboot or wake. |
| Enabled – Force On | The privacy screen is always enabled. Users can't disable it. The Surface App toggle is grayed out and the F1 key is non-functional. A notification informs users that the setting is managed by their organization. |
Behavior
- When Enabled (any of 3 settings above): You can specify whether the privacy screen is turned on or off by default and whether end users can change the setting.
- When Disabled or Not Configured: The Integrated Privacy Screen feature remains off by default, but users can manually enable or disable the feature using either the Surface App or the F1 key.
User experience
| Scenario | Surface App | F1 key | Notification |
|---|---|---|---|
| Not configured or user-changeable (Off/On by Default) | Toggle available | Functional | Informs user of current state |
| Force On (locked by IT) | Toggle grayed out | Non-functional | Informs user that the setting is managed by the organization |
The last known state of the privacy screen persists across device reboots and wake cycles unless overridden by IT policy.
Registry details
The following registry value is written when this policy is applied:
Registry path: HKLM\Software\Policies\Surface
| Value name | Type | Data | Description |
|---|---|---|---|
SurfaceIntegratedPrivacyScreenSetting |
REG_DWORD | 0 |
Off by default — users can change |
SurfaceIntegratedPrivacyScreenSetting |
REG_DWORD | 1 |
On by default — users can change |
SurfaceIntegratedPrivacyScreenSetting |
REG_DWORD | 2 |
Force On — users can't change |
When the policy is set to Not Configured or Disabled, this registry value isn't present or is removed.
OMA-URI (for custom MDM profiles)
./Device/Vendor/MSFT/Policy/Config/Surface~Policy~SurfaceCategory~Surface_PrivacyScreen/SurfaceIntegratedPrivacyScreenSetting
Related content
Release notes
Version 1.0
- Initial release